-
-
Notifications
You must be signed in to change notification settings - Fork 44
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Add functionality to automate exploitation of Pwn Requests, Injection, TOCTOU including payload delivery and secondary operations (such as making a feature branch, attempting to approve and merge a PR and more).
I call this feature "semi-auto" because the user will need to define the steps needed to exploit the vulnerability, Gato-X will just automate the process and monitor the target repository, handle exfiltration of secrets, and monitor the steps of the exploit as the attack progresses.
The attack steps will be defined within an "Attack template" YAMl file, and Gato-X will include a set of example pwn templates.
fproulx-boostsecurity
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request