カスタムスキャン
Ostorlab CLIを使用して、プラットフォーム上でカスタムチェックリストを使用したスキャン(Scan)を実行できます。カスタムチェックリストは、カスタムエージェント設定の形式で表されます。
これは、プライベートエージェントを使用している場合、またはオープンソースのエージェントのいずれかを特定の引数とともに使用したい場合に役立ちます。
例として、デフォルトの一部ではない事前定義されたテンプレートリストを使用して「Nuclei」エージェントを実行することが挙げられます。
カスタムスキャンを実行するために必要な手順は次のとおりです。
Ostorlab - Ostorlab Cli
Ostorlab CLIは、ユーザーを認証し、プラットフォーム上でスキャンを実行する役割を担います。
- まず、install ostorlabを実行します。
pip install ostorlab
ostorlab auth login
Agentグループ定義の準備:
実行するエージェントとそれぞれの引数のリストは、エージェントグループ定義(Agent group definition)ファイルを介して渡されます。
例:
kind: AgentGroup
description: This is a custom agent group to run nuclei with custom templates.
name: custom_agent_group
agents:
- key: agent/ostorlab/nuclei
args:
- name: use_default_templates
type: boolean
description: use nuclei's default templates to scan.
value: false
- name: template_urls
type: array
description: List of template urls to run. These will be fetched by the agent and passed to Nuclei.
value:
- https://raw.githubusercontent.com/Ostorlab/known_exploited_vulnerbilities_detectors/main/nuclei/CVE-2021-35464.yaml
- https://raw.githubusercontent.com/Ostorlab/known_exploited_vulnerbilities_detectors/main/nuclei/CVE-2021-27561.yaml
agent_def.yaml)を、スキャンの実行に使用するファイルに保存します。
スキャンの実行:
oxo scan --runtime=cloud run -g PATH_AGENT_GROUP_DEFINITION COMMAND [ARGS]
たとえば、/tmp/agent_def.yamlで定義されたエージェントグループを使用してURL https://my_domain.com をスキャンする場合
oxo scan --runtime=cloud run -g /tmp/agent_def.yaml link --url https://my_domain.com --method GET