自定义扫描
您可以使用 Ostorlab CLI 在平台上运行带有自定义检查列表的扫描(Scan)。自定义检查列表以自定义代理设置的形式体现。
如果您有私有代理,或者想要使用带有特定参数的开源代理之一,这将非常有用。
一个例子是运行“Nuclei”代理,并使用不属于默认模板的预定义模板列表。
以下是运行自定义扫描所需的步骤:
Ostorlab - Ostorlab Cli
Ostorlab CLI 负责对用户进行身份验证并在平台上运行扫描:
- 首先,install ostorlab;
pip install ostorlab
ostorlab auth login
准备 Agent 组定义:
要运行的代理及其各自的参数列表是通过代理组定义(Agent group definition)文件传递的。
示例:
kind: AgentGroup
description: This is a custom agent group to run nuclei with custom templates.
name: custom_agent_group
agents:
- key: agent/ostorlab/nuclei
args:
- name: use_default_templates
type: boolean
description: use nuclei's default templates to scan.
value: false
- name: template_urls
type: array
description: List of template urls to run. These will be fetched by the agent and passed to Nuclei.
value:
- https://raw.githubusercontent.com/Ostorlab/known_exploited_vulnerbilities_detectors/main/nuclei/CVE-2021-35464.yaml
- https://raw.githubusercontent.com/Ostorlab/known_exploited_vulnerbilities_detectors/main/nuclei/CVE-2021-27561.yaml
agent_def.yaml)保存到一个文件中,我们将使用它来运行扫描。
运行扫描:
oxo scan --runtime=cloud run -g PATH_AGENT_GROUP_DEFINITION COMMAND [ARGS]
例如,要使用在 /tmp/agent_def.yaml 中定义的代理组扫描 url https://my_domain.com
oxo scan --runtime=cloud run -g /tmp/agent_def.yaml link --url https://my_domain.com --method GET