Skip to content

Add Semi-Automated Pwn Request Automation #83

@AdnaneKhan

Description

@AdnaneKhan

Add functionality to automate exploitation of Pwn Requests, Injection, TOCTOU including payload delivery and secondary operations (such as making a feature branch, attempting to approve and merge a PR and more).

I call this feature "semi-auto" because the user will need to define the steps needed to exploit the vulnerability, Gato-X will just automate the process and monitor the target repository, handle exfiltration of secrets, and monitor the steps of the exploit as the attack progresses.

The attack steps will be defined within an "Attack template" YAMl file, and Gato-X will include a set of example pwn templates.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions