diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a0d0522..ba54a88 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -48,7 +48,3 @@ jobs: env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GPG_FINGERPRINT: ${{ secrets.GPG_FINGERPRINT }} - COSIGN_KEY: ${{ secrets.COSIGN_KEY }} - COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} - COSIGN_CERT_PATH: "." - COSIGN_SIG_PATH: "." diff --git a/.gitignore b/.gitignore index 8197f6b..993419e 100644 --- a/.gitignore +++ b/.gitignore @@ -40,10 +40,12 @@ profile.out # Output /output/ /reports/ -*.html -*.html *.sarif +# HTML reports (but not docs/) +/reports/*.html +/*.html + # Env .env .env.local diff --git a/.goreleaser.yaml b/.goreleaser.yaml index f2f5761..d73055b 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -25,20 +25,19 @@ builds: archives: - id: nice_scan - format: tar.gz + formats: [tar.gz] format_overrides: - goos: windows - format: zip + formats: [zip] name_template: "{{.ProjectName}}_{{.Version}}_{{.Os}}_{{.Arch}}" files: - README.md - - LICENSE checksum: name_template: "{{.ProjectName}}_{{.Version}}_checksums.txt" algorithm: sha256 -# ── GPG sign the checksums file ── +# ── Signing (GPG + cosign/Sigstore) ── signs: - id: checksum_sign cmd: gpg @@ -53,18 +52,15 @@ signs: artifacts: checksum signature: "${artifact}.sig" -# ── cosign — Sigstore signing for SLSA provenance ── -# Requires: COSIGN_KEY and COSIGN_PASSWORD env vars -# https://docs.sigstore.dev/cosign/overview/ -cosigns: - id: cosign_blob - artifacts: checksum + cmd: cosign + signature: "${artifact}.sigstore.json" args: - sign-blob - - "--output-certificate={{.Env.COSIGN_CERT_PATH}}/{{.ProjectName}}_{{.Version}}_checksums.pem" - - "--output-signature={{.Env.COSIGN_SIG_PATH}}/{{.ProjectName}}_{{.Version}}_checksums.sig" + - "--bundle=${signature}" - "${artifact}" - certificate: "${artifact}.pem" + - "--yes" + artifacts: checksum output: true # ── SBOM with syft (software bill of materials) ── @@ -100,10 +96,9 @@ release: # 3. Verify GPG signature gpg --verify nice_scan_{{.Version}}_checksums.txt.sig - # 4. Verify Sigstore (cosign) + # 4. Verify Sigstore (cosign — keyless OIDC) cosign verify-blob \ - --certificate nice_scan_{{.Version}}_checksums.pem \ - --signature nice_scan_{{.Version}}_checksums.sig \ + --bundle nice_scan_{{.Version}}_checksums.sigstore.json \ nice_scan_{{.Version}}_checksums.txt ``` @@ -112,8 +107,7 @@ release: |------|-------------| | `nice_scan_{{.Version}}_checksums.txt` | SHA256 checksums for all binaries | | `nice_scan_{{.Version}}_checksums.txt.sig` | GPG signature of checksums | - | `nice_scan_{{.Version}}_checksums.pem` | Sigstore certificate | - | `nice_scan_{{.Version}}_checksums.sig` | Sigstore signature | + | `nice_scan_{{.Version}}_checksums.sigstore.json` | Cosign Sigstore bundle (keyless) | | `nice_scan_{{.Version}}_sbom.spdx.json` | SPDX SBOM (dependencies) | ## 🚀 Quick Start diff --git a/cmd/nice_scan/attack_report.html b/cmd/nice_scan/attack_report.html new file mode 100644 index 0000000..f5cafdc --- /dev/null +++ b/cmd/nice_scan/attack_report.html @@ -0,0 +1,200 @@ + + +
+ + +Multiple attack chains detected; Secrets → Cloud Compromise
+Autonomous security reconnaissance engine with decision chaining — SQLi → users, LFI → files, CMD → shells, S3 → buckets, Upload → RCE
+ +Not just another scanner — an autonomous security agent that chains attacks, extracts real data, and generates professional reports.
+Forward-chaining AI scans for vulnerabilities and automatically spawns exploit modules — SQLi dumps user tables, LFI reads server files, CMD injection opens shells.
+10 chain patterns — CORS+XSS, JWT→Admin, Secrets→Cloud, Upload→RCE. Each finding automatically triggers deeper exploitation across interconnected vectors.
+Goes beyond detection — extracts SQL databases, LFI files, S3 bucket contents, deploys web shells, and dumps everything to reports/ organized by target.
Professional dark-theme reports with risk scoring, findings timeline, capabilities graph, extracted data summary, and credential inventory. Shareable with -R report.html.
All releases signed with GPG + Sigstore/cosign. SHA256 checksums verified. Supply-chain security with SLSA provenance and SPDX SBOM included every release.
+Passive recon, crawl, fuzz, JWT forge, login brute, XSS, SQLi, GraphQL, S3 enum, LFI, CMD injection, upload, OOB server, port scan — all with auto-spawning chains.
+Four ways to install, all with cryptographic verification.
+Windows package manager
+Windows native package manager
+Cross-platform source build
+Download from GitHub Releases
+scoop bucket add nice-scan https://github.com/NICE-DEV226/nice-Scan
+scoop install nice-scan/nice_scan
+ One command. Autonomous attack chaining. Real data extraction.
+Full autonomous attack against any target — detects vulnerabilities and automatically exploits them.
+nice_scan hack example.com -R report.html
+
+ Persistent REPL reconnaissance shell with command history, session context, and live results.
+nice_scan shell
+
+ Real-time TUI dashboard with progress bars, findings stream, and live severity updates.
+nice_scan scan example.com -i
+
+ Set a timeout to control engagement duration — ideal for bug bounties and CTFs.
+nice_scan hack target.com --timeout 30s -R report.html
+
+ Dark-theme, risk-scored, evidence-backed — ready for client delivery or team collaboration.
+Every release is cryptographically signed. Every install script verifies before extraction.
+Checksum files signed with NICE-DEV226's GPG key. Verify with:
+gpg --verify checksums.txt.sig checksums.txt
+ Keyless signing via GitHub OIDC. SLSA provenance with cosign bundles.
+cosign verify-blob --bundle checksums.sigstore.json checksums.txt
+ Software Bill of Materials for every release — full dependency transparency.
+syft scan nice_scan --from-release NICE-DEV226/nice-Scan:v0.1.0
+ Build integrity verified through Sigstore. Non-falsifiable provenance attestations.
+gh attestation verify nice_scan_0.1.0_linux_amd64.tar.gz \
+ --repo NICE-DEV226/nice-Scan
+ Download the latest release and verify for yourself.
+ + + Latest Release + +