mirror of
https://github.com/j3ssie/osmedeus.git
synced 2026-08-22 07:32:27 +02:00
161 lines
4.3 KiB
YAML
161 lines
4.3 KiB
YAML
name: test-docker-flow
|
|
kind: flow
|
|
description: Flow orchestrating multiple Docker-based security scanning modules
|
|
tags: test,flow,docker
|
|
|
|
params:
|
|
- name: target
|
|
required: true
|
|
- name: Output
|
|
default: /tmp/osm-docker-flow
|
|
- name: mode
|
|
default: "full"
|
|
- name: threads
|
|
default: "10"
|
|
- name: skip_vuln_scan
|
|
default: "false"
|
|
|
|
modules:
|
|
# Module 1: Initial reconnaissance
|
|
- name: recon-module
|
|
path: modules/test-docker-recon
|
|
params:
|
|
target: "{{target}}"
|
|
output_dir: "{{Output}}/recon"
|
|
threads: "{{threads}}"
|
|
on_success:
|
|
- action: log
|
|
message: "Reconnaissance completed for {{target}}"
|
|
- action: export
|
|
key: recon_complete
|
|
value: "true"
|
|
on_error:
|
|
- action: log
|
|
message: "Reconnaissance failed for {{target}}"
|
|
- action: abort
|
|
|
|
# Module 2: Subdomain enumeration (depends on recon)
|
|
- name: subdomain-module
|
|
path: modules/test-docker-subdomain
|
|
depends_on:
|
|
- recon-module
|
|
params:
|
|
target: "{{target}}"
|
|
output_dir: "{{Output}}/subdomains"
|
|
wordlist: "/usr/share/wordlists/subdomains.txt"
|
|
condition: "mode == 'full' || mode == 'subdomain'"
|
|
on_success:
|
|
- action: export
|
|
key: subdomains_file
|
|
value: "{{Output}}/subdomains/all.txt"
|
|
|
|
# Module 3: Port scanning (parallel with subdomain)
|
|
- name: portscan-module
|
|
path: modules/test-docker-portscan
|
|
depends_on:
|
|
- recon-module
|
|
params:
|
|
target: "{{target}}"
|
|
output_dir: "{{Output}}/ports"
|
|
port_range: "1-10000"
|
|
rate: "1000"
|
|
condition: "mode == 'full' || mode == 'portscan'"
|
|
|
|
# Module 4: HTTP probing (depends on subdomain results)
|
|
- name: httpx-module
|
|
path: modules/test-docker-httpx
|
|
depends_on:
|
|
- subdomain-module
|
|
params:
|
|
input: "{{subdomains_file}}"
|
|
output_dir: "{{Output}}/http"
|
|
threads: "{{threads}}"
|
|
on_success:
|
|
- action: export
|
|
key: alive_hosts
|
|
value: "{{Output}}/http/alive.txt"
|
|
- action: export
|
|
key: httpx_json
|
|
value: "{{Output}}/http/httpx.json"
|
|
decision:
|
|
switch: "{{alive_count}}"
|
|
cases:
|
|
"0":
|
|
goto: report-module
|
|
|
|
# Module 5: Technology detection (depends on HTTP probe)
|
|
- name: tech-detect-module
|
|
path: modules/test-docker-techdetect
|
|
depends_on:
|
|
- httpx-module
|
|
params:
|
|
input: "{{alive_hosts}}"
|
|
output_dir: "{{Output}}/tech"
|
|
|
|
# Module 6: Screenshot capture (parallel with tech detection)
|
|
- name: screenshot-module
|
|
path: modules/test-docker-screenshot
|
|
depends_on:
|
|
- httpx-module
|
|
params:
|
|
input: "{{alive_hosts}}"
|
|
output_dir: "{{Output}}/screenshots"
|
|
threads: "5"
|
|
|
|
# Module 7: Vulnerability scanning (conditional)
|
|
- name: vulnscan-module
|
|
path: modules/test-docker-scanning
|
|
depends_on:
|
|
- httpx-module
|
|
- tech-detect-module
|
|
params:
|
|
target: "{{target}}"
|
|
Output: "{{Output}}/vulns"
|
|
severity: "critical,high,medium"
|
|
threads: "{{threads}}"
|
|
condition: "skip_vuln_scan != 'true'"
|
|
on_error:
|
|
- action: log
|
|
message: "Vulnerability scan encountered errors but continuing"
|
|
- action: continue
|
|
|
|
# Module 8: Directory bruteforcing (optional - depends on mode)
|
|
- name: dirbrute-module
|
|
path: modules/test-docker-dirbrute
|
|
depends_on:
|
|
- httpx-module
|
|
params:
|
|
input: "{{alive_hosts}}"
|
|
output_dir: "{{Output}}/dirs"
|
|
wordlist: "/usr/share/wordlists/common.txt"
|
|
threads: "20"
|
|
condition: "mode == 'full'"
|
|
|
|
# Module 9: JavaScript analysis (depends on dir results)
|
|
- name: js-analysis-module
|
|
path: modules/test-docker-jsanalysis
|
|
depends_on:
|
|
- dirbrute-module
|
|
params:
|
|
input: "{{Output}}/dirs/js-files.txt"
|
|
output_dir: "{{Output}}/js"
|
|
condition: "mode == 'full'"
|
|
|
|
# Module 10: Final report generation
|
|
- name: report-module
|
|
path: modules/test-docker-report
|
|
depends_on:
|
|
- screenshot-module
|
|
- vulnscan-module
|
|
- tech-detect-module
|
|
params:
|
|
target: "{{target}}"
|
|
input_dir: "{{Output}}"
|
|
output_dir: "{{Output}}/reports"
|
|
format: "html,json,markdown"
|
|
on_success:
|
|
- action: log
|
|
message: "Flow completed successfully for {{target}}"
|
|
- action: notify
|
|
message: "Security assessment complete: {{target}}"
|