Skip to content

Feature/shell scroll - #2

Merged
NICE-DEV226 merged 7 commits into
mainfrom
feature/shell-scroll
May 29, 2026
Merged

NICE-DEV226 merged 7 commits into
mainfrom
feature/shell-scroll

Conversation

@NICE-DEV226

Copy link
Copy Markdown
Owner

Description

Type of Change

  • feat: new feature
  • fix: bug fix
  • refactor: code restructuring
  • perf: performance improvement
  • docs: documentation
  • test: testing
  • ci: CI/CD changes

Architecture Impact

Performance Impact

Testing

  • Unit tests added/updated
  • Integration tests pass
  • Race detection clean
  • Benchmarks considered

Checklist

  • Code follows project conventions
  • No sensitive data exposed
  • Error handling is robust
  • Panic recovery in place
  • Context propagation correct
  • Dependencies are minimal

…ucture

Decision Engine (internal/hacker/):
- Action interface with forward-chaining (Actions → spawned sub-actions)
- Planner v2: dynamic priority queue, AddAction() for spawns
- Chain Executor: 10 attack chain patterns (CORS+XSS, JWT→Admin, Secrets→Cloud...)
- SessionManager: persistent cookies/tokens/JWT across actions
- ReportDir: extracted data saved to reports/{target}/
- 14 actions: passive recon, crawl, fuzz, portscan, JWT forge, login brute,
  XSS, SQLi, GraphQL, S3 enum, LFI, CMD inj, upload, OOB server
- 6 exploit modules: SQLi data extract, LFI file read, CMD shell,
  post-login crawl, S3 bucket dump, web shell deploy
- HTML attack report with risk scoring + dark theme

UX/UI:
- First-run: nice_scan shows quick-start examples (hack, scan, --help)
- --version flag added
- Hack output: elapsed time per step, aligned severity labels,
  compact KB summary, consistent icons
- Better error messages for missing args
- SilenceErrors + SilenceUsage for clean output

Installation & Trust:
- Module path fixed: github.com/NICE-DEV226/nice-Scan
- Makefile with build/run/test/hack/release targets
- scripts/install.ps1: SHA256 verification, transparent output,
  no silent exec, fallback to source build
- scripts/install.sh: SHA256 + GPG verification, cosign support
- .goreleaser.yaml: GPG signing, cosign/SLSA, SPDX SBOM
- SECURITY.md: full trust policy, verification steps, vuln reporting
- CONTRIBUTING.md: dev workflow, conventions, signed commits
- README: 4 install methods, trust section, verification guide

Action spawning:
- SQLi → SQLiDataExtractAction
- LFI → LFIReadAction
- CMD inject → CMDShellAction
- Upload → WebShellAction
- Login → PostLoginCrawlAction
- S3 → S3DumpAction
@NICE-DEV226
NICE-DEV226 merged commit 7e78549 into main May 29, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant