chore: initialize project workspace and install frontend dependencies
This commit is contained in:
@@ -0,0 +1,2 @@
|
||||
nucleus
|
||||
cmd/nucleus/dist
|
||||
@@ -0,0 +1,80 @@
|
||||
# Nucleus - Vulnerability Scan Orchestrator
|
||||
|
||||
Nucleus is a single, self-contained Go binary that acts as an orchestration manager for scheduled [Nuclei](https://github.com/projectdiscovery/nuclei) vulnerability scans.
|
||||
|
||||
It serves an embedded Vue 3 SPA web dashboard, reads/writes scan states to a local SQLite database, and automatically dispatches beautifully formatted HTML email reports via SMTP when scans discover vulnerabilities.
|
||||
|
||||
## Prerequisites
|
||||
- **Go 1.22+**
|
||||
- **Node.js & npm** (for building the frontend)
|
||||
- **Nuclei**: Ensure the `nuclei` CLI is installed and available in the system `$PATH`.
|
||||
|
||||
## Building the Application
|
||||
|
||||
Nucleus bundles the Vue 3 frontend directly into the Go binary using the `//go:embed` directive.
|
||||
|
||||
### 1. Build the Frontend
|
||||
```bash
|
||||
cd frontend
|
||||
npm install
|
||||
npm run build
|
||||
```
|
||||
*(This places the static assets in the `dist/` directory).*
|
||||
|
||||
### 2. Compile the Go Binary
|
||||
```bash
|
||||
# From the root directory
|
||||
go mod tidy
|
||||
go build -o nucleus ./cmd/nucleus
|
||||
```
|
||||
|
||||
## Running as a Systemd Service
|
||||
|
||||
To keep Nucleus running continuously in the background on your VM, it is recommended to create a systemd service.
|
||||
|
||||
1. Create a service file:
|
||||
```bash
|
||||
sudo nano /etc/systemd/system/nucleus.service
|
||||
```
|
||||
|
||||
2. Add the following configuration (adjust the `User`, `Group`, `WorkingDirectory`, and `ExecStart` paths to match your environment):
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
Description=Nucleus Vulnerability Scan Orchestrator
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=jamie
|
||||
Group=jamie
|
||||
WorkingDirectory=/home/jamie/Git/nucleus
|
||||
ExecStart=/home/jamie/Git/nucleus/nucleus
|
||||
|
||||
# SMTP Configuration
|
||||
Environment="SMTP_HOST=localhost"
|
||||
Environment="SMTP_PORT=25"
|
||||
Environment="SMTP_FROM=nucleus@example.com"
|
||||
Environment="SMTP_TO=admin@example.com"
|
||||
|
||||
# Optional: Add authentication if your SMTP server requires it
|
||||
# Environment="SMTP_USER=username"
|
||||
# Environment="SMTP_PASS=password"
|
||||
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. Enable and start the service:
|
||||
```bash
|
||||
sudo systemctl daemon-reload
|
||||
sudo systemctl enable nucleus
|
||||
sudo systemctl start nucleus
|
||||
sudo systemctl status nucleus
|
||||
```
|
||||
|
||||
## Dashboard
|
||||
By default, the web dashboard will be available on `http://<your-vm-ip>:8080`.
|
||||
@@ -0,0 +1,24 @@
|
||||
# Logs
|
||||
logs
|
||||
*.log
|
||||
npm-debug.log*
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
pnpm-debug.log*
|
||||
lerna-debug.log*
|
||||
|
||||
node_modules
|
||||
dist
|
||||
dist-ssr
|
||||
*.local
|
||||
|
||||
# Editor directories and files
|
||||
.vscode/*
|
||||
!.vscode/extensions.json
|
||||
.idea
|
||||
.DS_Store
|
||||
*.suo
|
||||
*.ntvs*
|
||||
*.njsproj
|
||||
*.sln
|
||||
*.sw?
|
||||
@@ -0,0 +1,13 @@
|
||||
<!doctype html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>Nucleus</title>
|
||||
</head>
|
||||
<body>
|
||||
<div id="app"></div>
|
||||
<script type="module" src="/src/main.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
Generated
+1672
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"name": "frontend",
|
||||
"private": true,
|
||||
"version": "0.0.0",
|
||||
"type": "module",
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
"build": "vite build",
|
||||
"preview": "vite preview"
|
||||
},
|
||||
"dependencies": {
|
||||
"vue": "^3.5.39"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@tailwindcss/vite": "^4.3.3",
|
||||
"@vitejs/plugin-vue": "^6.0.7",
|
||||
"autoprefixer": "^10.5.4",
|
||||
"postcss": "^8.5.19",
|
||||
"tailwindcss": "^4.3.3",
|
||||
"vite": "^8.1.1",
|
||||
"vue-router": "^4.6.4"
|
||||
}
|
||||
}
|
||||
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 9.3 KiB |
@@ -0,0 +1,24 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg">
|
||||
<symbol id="bluesky-icon" viewBox="0 0 16 17">
|
||||
<g clip-path="url(#bluesky-clip)"><path fill="#08060d" d="M7.75 7.735c-.693-1.348-2.58-3.86-4.334-5.097-1.68-1.187-2.32-.981-2.74-.79C.188 2.065.1 2.812.1 3.251s.241 3.602.398 4.13c.52 1.744 2.367 2.333 4.07 2.145-2.495.37-4.71 1.278-1.805 4.512 3.196 3.309 4.38-.71 4.987-2.746.608 2.036 1.307 5.91 4.93 2.746 2.72-2.746.747-4.143-1.747-4.512 1.702.189 3.55-.4 4.07-2.145.156-.528.397-3.691.397-4.13s-.088-1.186-.575-1.406c-.42-.19-1.06-.395-2.741.79-1.755 1.24-3.64 3.752-4.334 5.099"/></g>
|
||||
<defs><clipPath id="bluesky-clip"><path fill="#fff" d="M.1.85h15.3v15.3H.1z"/></clipPath></defs>
|
||||
</symbol>
|
||||
<symbol id="discord-icon" viewBox="0 0 20 19">
|
||||
<path fill="#08060d" d="M16.224 3.768a14.5 14.5 0 0 0-3.67-1.153c-.158.286-.343.67-.47.976a13.5 13.5 0 0 0-4.067 0c-.128-.306-.317-.69-.476-.976A14.4 14.4 0 0 0 3.868 3.77C1.546 7.28.916 10.703 1.231 14.077a14.7 14.7 0 0 0 4.5 2.306q.545-.748.965-1.587a9.5 9.5 0 0 1-1.518-.74q.191-.14.372-.293c2.927 1.369 6.107 1.369 8.999 0q.183.152.372.294-.723.437-1.52.74.418.838.963 1.588a14.6 14.6 0 0 0 4.504-2.308c.37-3.911-.63-7.302-2.644-10.309m-9.13 8.234c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.894 0 1.614.82 1.599 1.82.001 1-.705 1.82-1.6 1.82m5.91 0c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.893 0 1.614.82 1.599 1.82 0 1-.706 1.82-1.6 1.82"/>
|
||||
</symbol>
|
||||
<symbol id="documentation-icon" viewBox="0 0 21 20">
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="m15.5 13.333 1.533 1.322c.645.555.967.833.967 1.178s-.322.623-.967 1.179L15.5 18.333m-3.333-5-1.534 1.322c-.644.555-.966.833-.966 1.178s.322.623.966 1.179l1.534 1.321"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M17.167 10.836v-4.32c0-1.41 0-2.117-.224-2.68-.359-.906-1.118-1.621-2.08-1.96-.599-.21-1.349-.21-2.848-.21-2.623 0-3.935 0-4.983.369-1.684.591-3.013 1.842-3.641 3.428C3 6.449 3 7.684 3 10.154v2.122c0 2.558 0 3.838.706 4.726q.306.383.713.671c.76.536 1.79.64 3.581.66"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M3 10a2.78 2.78 0 0 1 2.778-2.778c.555 0 1.209.097 1.748-.047.48-.129.854-.503.982-.982.145-.54.048-1.194.048-1.749a2.78 2.78 0 0 1 2.777-2.777"/>
|
||||
</symbol>
|
||||
<symbol id="github-icon" viewBox="0 0 19 19">
|
||||
<path fill="#08060d" fill-rule="evenodd" d="M9.356 1.85C5.05 1.85 1.57 5.356 1.57 9.694a7.84 7.84 0 0 0 5.324 7.44c.387.079.528-.168.528-.376 0-.182-.013-.805-.013-1.454-2.165.467-2.616-.935-2.616-.935-.349-.91-.864-1.143-.864-1.143-.71-.48.051-.48.051-.48.787.051 1.2.805 1.2.805.695 1.194 1.817.857 2.268.649.064-.507.27-.857.49-1.052-1.728-.182-3.545-.857-3.545-3.87 0-.857.31-1.558.8-2.104-.078-.195-.349-1 .077-2.078 0 0 .657-.208 2.14.805a7.5 7.5 0 0 1 1.946-.26c.657 0 1.328.092 1.946.26 1.483-1.013 2.14-.805 2.14-.805.426 1.078.155 1.883.078 2.078.502.546.799 1.247.799 2.104 0 3.013-1.818 3.675-3.558 3.87.284.247.528.714.528 1.454 0 1.052-.012 1.896-.012 2.156 0 .208.142.455.528.377a7.84 7.84 0 0 0 5.324-7.441c.013-4.338-3.48-7.844-7.773-7.844" clip-rule="evenodd"/>
|
||||
</symbol>
|
||||
<symbol id="social-icon" viewBox="0 0 20 20">
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M12.5 6.667a4.167 4.167 0 1 0-8.334 0 4.167 4.167 0 0 0 8.334 0"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M2.5 16.667a5.833 5.833 0 0 1 8.75-5.053m3.837.474.513 1.035c.07.144.257.282.414.309l.93.155c.596.1.736.536.307.965l-.723.73a.64.64 0 0 0-.152.531l.207.903c.164.715-.213.991-.84.618l-.872-.52a.63.63 0 0 0-.577 0l-.872.52c-.624.373-1.003.094-.84-.618l.207-.903a.64.64 0 0 0-.152-.532l-.723-.729c-.426-.43-.289-.864.306-.964l.93-.156a.64.64 0 0 0 .412-.31l.513-1.034c.28-.562.735-.562 1.012 0"/>
|
||||
</symbol>
|
||||
<symbol id="x-icon" viewBox="0 0 19 19">
|
||||
<path fill="#08060d" fill-rule="evenodd" d="M1.893 1.98c.052.072 1.245 1.769 2.653 3.77l2.892 4.114c.183.261.333.48.333.486s-.068.089-.152.183l-.522.593-.765.867-3.597 4.087c-.375.426-.734.834-.798.905a1 1 0 0 0-.118.148c0 .01.236.017.664.017h.663l.729-.83c.4-.457.796-.906.879-.999a692 692 0 0 0 1.794-2.038c.034-.037.301-.34.594-.675l.551-.624.345-.392a7 7 0 0 1 .34-.374c.006 0 .93 1.306 2.052 2.903l2.084 2.965.045.063h2.275c1.87 0 2.273-.003 2.266-.021-.008-.02-1.098-1.572-3.894-5.547-2.013-2.862-2.28-3.246-2.273-3.266.008-.019.282-.332 2.085-2.38l2-2.274 1.567-1.782c.022-.028-.016-.03-.65-.03h-.674l-.3.342a871 871 0 0 1-1.782 2.025c-.067.075-.405.458-.75.852a100 100 0 0 1-.803.91c-.148.172-.299.344-.99 1.127-.304.343-.32.358-.345.327-.015-.019-.904-1.282-1.976-2.808L6.365 1.85H1.8zm1.782.91 8.078 11.294c.772 1.08 1.413 1.973 1.425 1.984.016.017.241.02 1.05.017l1.03-.004-2.694-3.766L7.796 5.75 5.722 2.852l-1.039-.004-1.039-.004z" clip-rule="evenodd"/>
|
||||
</symbol>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 4.9 KiB |
@@ -0,0 +1,22 @@
|
||||
<template>
|
||||
<div class="min-h-screen bg-bg text-body flex flex-col font-sans">
|
||||
<header class="bg-surface border-b border-border-subtle shadow-sm relative z-10">
|
||||
<div class="max-w-7xl mx-auto px-4 sm:px-6 lg:px-8 h-16 flex items-center justify-between">
|
||||
<div class="flex items-center space-x-3">
|
||||
<div class="w-8 h-8 rounded-full bg-accent flex items-center justify-center font-bold text-bg shadow-lg border border-accent/80">N</div>
|
||||
<h1 class="text-xl font-bold text-heading">Nucleus</h1>
|
||||
</div>
|
||||
<nav class="flex space-x-4">
|
||||
<router-link to="/" class="px-3 py-2 rounded-md text-sm font-medium transition-colors hover:bg-border-subtle hover:text-heading" active-class="bg-bg text-accent shadow-inner">Targets</router-link>
|
||||
<router-link to="/scans" class="px-3 py-2 rounded-md text-sm font-medium transition-colors hover:bg-border-subtle hover:text-heading" active-class="bg-bg text-accent shadow-inner">Scans History</router-link>
|
||||
</nav>
|
||||
</div>
|
||||
</header>
|
||||
|
||||
<main class="flex-1 w-full max-w-7xl mx-auto px-4 sm:px-6 lg:px-8 py-8 relative">
|
||||
<!-- Glow effect -->
|
||||
<div class="absolute top-0 left-1/2 -translate-x-1/2 w-full max-w-3xl h-64 bg-accent/10 blur-[120px] pointer-events-none"></div>
|
||||
<router-view class="relative z-10"></router-view>
|
||||
</main>
|
||||
</div>
|
||||
</template>
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 13 KiB |
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 8.5 KiB |
@@ -0,0 +1 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" class="iconify iconify--logos" width="37.07" height="36" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 198"><path fill="#41B883" d="M204.8 0H256L128 220.8L0 0h97.92L128 51.2L157.44 0h47.36Z"></path><path fill="#41B883" d="m0 0l128 220.8L256 0h-51.2L128 132.48L50.56 0H0Z"></path><path fill="#35495E" d="M50.56 0L128 133.12L204.8 0h-47.36L128 51.2L97.92 0H50.56Z"></path></svg>
|
||||
|
After Width: | Height: | Size: 496 B |
@@ -0,0 +1,90 @@
|
||||
<template>
|
||||
<div class="space-y-6">
|
||||
<div class="flex items-center space-x-4 mb-6">
|
||||
<router-link to="/scans" class="text-body hover:text-heading transition-colors flex items-center">
|
||||
<svg class="w-5 h-5 mr-1" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M10 19l-7-7m0 0l7-7m-7 7h18"></path></svg>
|
||||
Back
|
||||
</router-link>
|
||||
<h2 class="text-2xl font-bold text-heading">Scan Findings Inspector</h2>
|
||||
</div>
|
||||
|
||||
<div class="bg-surface rounded-xl overflow-hidden shadow-lg border border-border-subtle">
|
||||
<div class="px-6 py-4 border-b border-border-subtle flex justify-between items-center">
|
||||
<h3 class="text-lg font-medium text-heading">All Findings ({{ findings.length }})</h3>
|
||||
<button @click="loadFindings" class="text-body hover:text-heading transition-colors">Refresh</button>
|
||||
</div>
|
||||
|
||||
<div class="overflow-x-auto">
|
||||
<table class="w-full text-left text-sm">
|
||||
<thead class="bg-bg/50 text-body">
|
||||
<tr>
|
||||
<th class="px-6 py-3 font-medium">Severity</th>
|
||||
<th class="px-6 py-3 font-medium">Name & Template</th>
|
||||
<th class="px-6 py-3 font-medium">Host</th>
|
||||
<th class="px-6 py-3 font-medium">Matched At</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody class="divide-y divide-border-subtle">
|
||||
<tr v-for="finding in findings" :key="finding.id" class="hover:bg-border-subtle/30 transition-colors">
|
||||
<td class="px-6 py-4">
|
||||
<span :class="severityClass(finding.severity)" class="px-2.5 py-1 rounded-md text-xs font-bold uppercase tracking-wider border">
|
||||
{{ finding.severity }}
|
||||
</span>
|
||||
</td>
|
||||
<td class="px-6 py-4">
|
||||
<div class="text-heading font-medium">{{ finding.name }}</div>
|
||||
<div class="text-body font-mono text-xs mt-1">{{ finding.template_id }}</div>
|
||||
<div v-if="finding.description" class="text-body text-xs mt-2 max-w-md truncate" :title="finding.description">
|
||||
{{ finding.description }}
|
||||
</div>
|
||||
</td>
|
||||
<td class="px-6 py-4 text-body font-mono text-xs">{{ finding.host }}</td>
|
||||
<td class="px-6 py-4 text-body text-xs break-all max-w-xs">{{ finding.matched_at }}</td>
|
||||
</tr>
|
||||
<tr v-if="findings.length === 0">
|
||||
<td colspan="4" class="px-6 py-12 text-center">
|
||||
<div class="inline-flex items-center justify-center w-16 h-16 rounded-full bg-bg mb-4 border border-border-subtle">
|
||||
<svg class="w-8 h-8 text-accent" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M9 12l2 2 4-4m6 2a9 9 0 11-18 0 9 9 0 0118 0z"></path></svg>
|
||||
</div>
|
||||
<h3 class="text-lg font-medium text-heading mb-1">No Findings</h3>
|
||||
<p class="text-body">This scan completed cleanly without any detected vulnerabilities.</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script setup>
|
||||
import { ref, onMounted } from 'vue'
|
||||
|
||||
const props = defineProps({
|
||||
id: { type: String, required: true }
|
||||
})
|
||||
|
||||
const findings = ref([])
|
||||
|
||||
const loadFindings = async () => {
|
||||
try {
|
||||
const res = await fetch(`/api/scans/${props.id}/findings`)
|
||||
findings.value = await res.json() || []
|
||||
} catch (e) {
|
||||
console.error(e)
|
||||
}
|
||||
}
|
||||
|
||||
const severityClass = (sev) => {
|
||||
const map = {
|
||||
critical: 'bg-red-500/20 text-red-400 border-red-500/50',
|
||||
high: 'bg-orange-500/20 text-orange-400 border-orange-500/50',
|
||||
medium: 'bg-yellow-500/20 text-yellow-400 border-yellow-500/50',
|
||||
low: 'bg-blue-500/20 text-blue-400 border-blue-500/50',
|
||||
info: 'bg-border-subtle/50 text-body border-border-subtle'
|
||||
}
|
||||
return map[sev] || map.info
|
||||
}
|
||||
|
||||
onMounted(loadFindings)
|
||||
</script>
|
||||
@@ -0,0 +1,95 @@
|
||||
<script setup>
|
||||
import { ref } from 'vue'
|
||||
import viteLogo from '../assets/vite.svg'
|
||||
import heroImg from '../assets/hero.png'
|
||||
import vueLogo from '../assets/vue.svg'
|
||||
|
||||
const count = ref(0)
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="center">
|
||||
<div class="hero">
|
||||
<img :src="heroImg" class="base" width="170" height="179" alt="" />
|
||||
<img :src="vueLogo" class="framework" alt="Vue logo" />
|
||||
<img :src="viteLogo" class="vite" alt="Vite logo" />
|
||||
</div>
|
||||
<div>
|
||||
<h1>Get started</h1>
|
||||
<p>Edit <code>src/App.vue</code> and save to test <code>HMR</code></p>
|
||||
</div>
|
||||
<button type="button" class="counter" @click="count++">
|
||||
Count is {{ count }}
|
||||
</button>
|
||||
</section>
|
||||
|
||||
<div class="ticks"></div>
|
||||
|
||||
<section id="next-steps">
|
||||
<div id="docs">
|
||||
<svg class="icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#documentation-icon"></use>
|
||||
</svg>
|
||||
<h2>Documentation</h2>
|
||||
<p>Your questions, answered</p>
|
||||
<ul>
|
||||
<li>
|
||||
<a href="https://vite.dev/" target="_blank">
|
||||
<img class="logo" :src="viteLogo" alt="" />
|
||||
Explore Vite
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://vuejs.org/" target="_blank">
|
||||
<img class="button-icon" :src="vueLogo" alt="" />
|
||||
Learn more
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
<div id="social">
|
||||
<svg class="icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#social-icon"></use>
|
||||
</svg>
|
||||
<h2>Connect with us</h2>
|
||||
<p>Join the Vite community</p>
|
||||
<ul>
|
||||
<li>
|
||||
<a href="https://github.com/vitejs/vite" target="_blank">
|
||||
<svg class="button-icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#github-icon"></use>
|
||||
</svg>
|
||||
GitHub
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://chat.vite.dev/" target="_blank">
|
||||
<svg class="button-icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#discord-icon"></use>
|
||||
</svg>
|
||||
Discord
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://x.com/vite_js" target="_blank">
|
||||
<svg class="button-icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#x-icon"></use>
|
||||
</svg>
|
||||
X.com
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://bsky.app/profile/vite.dev" target="_blank">
|
||||
<svg class="button-icon" role="presentation" aria-hidden="true">
|
||||
<use href="/icons.svg#bluesky-icon"></use>
|
||||
</svg>
|
||||
Bluesky
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<div class="ticks"></div>
|
||||
<section id="spacer"></section>
|
||||
</template>
|
||||
@@ -0,0 +1,109 @@
|
||||
<template>
|
||||
<div class="bg-surface rounded-xl overflow-hidden shadow-lg border border-border-subtle">
|
||||
<div class="px-6 py-4 border-b border-border-subtle flex justify-between items-center">
|
||||
<h2 class="text-xl font-semibold text-heading">Scans History</h2>
|
||||
<button @click="loadScans" class="text-body hover:text-heading transition-colors">
|
||||
<svg class="w-5 h-5" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M4 4v5h.582m15.356 2A8.001 8.001 0 004.582 9m0 0H9m11 11v-5h-.581m0 0a8.003 8.003 0 01-15.357-2m15.357 2H15"></path></svg>
|
||||
</button>
|
||||
</div>
|
||||
<div class="overflow-x-auto">
|
||||
<table class="w-full text-left text-sm">
|
||||
<thead class="bg-bg/50 text-body">
|
||||
<tr>
|
||||
<th class="px-6 py-3 font-medium">Target</th>
|
||||
<th class="px-6 py-3 font-medium">Status</th>
|
||||
<th class="px-6 py-3 font-medium">Started At</th>
|
||||
<th class="px-6 py-3 font-medium">Duration</th>
|
||||
<th class="px-6 py-3 font-medium">Findings</th>
|
||||
<th class="px-6 py-3 font-medium text-right">Actions</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody class="divide-y divide-border-subtle">
|
||||
<tr v-for="scan in scans" :key="scan.id" class="hover:bg-border-subtle/30 transition-colors">
|
||||
<td class="px-6 py-4 text-heading font-medium">{{ scan.target_name }}</td>
|
||||
<td class="px-6 py-4">
|
||||
<span v-if="scan.status === 'running'" class="inline-flex items-center px-2.5 py-0.5 rounded-full text-xs font-medium bg-blue-900/50 text-blue-400 border border-blue-800">
|
||||
<svg class="animate-spin -ml-0.5 mr-1.5 h-3 w-3 text-blue-400" fill="none" viewBox="0 0 24 24">
|
||||
<circle class="opacity-25" cx="12" cy="12" r="10" stroke="currentColor" stroke-width="4"></circle>
|
||||
<path class="opacity-75" fill="currentColor" d="M4 12a8 8 0 018-8V0C5.373 0 0 5.373 0 12h4zm2 5.291A7.962 7.962 0 014 12H0c0 3.042 1.135 5.824 3 7.938l3-2.647z"></path>
|
||||
</svg>
|
||||
Running
|
||||
</span>
|
||||
<span v-else-if="scan.status === 'completed'" class="inline-flex items-center px-2.5 py-0.5 rounded-full text-xs font-medium bg-green-900/50 text-green-400 border border-green-800">
|
||||
<svg class="mr-1.5 h-3 w-3" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M5 13l4 4L19 7"></path></svg>
|
||||
Completed
|
||||
</span>
|
||||
<span v-else class="inline-flex items-center px-2.5 py-0.5 rounded-full text-xs font-medium bg-red-900/50 text-red-400 border border-red-800">
|
||||
Failed
|
||||
</span>
|
||||
</td>
|
||||
<td class="px-6 py-4 text-body">
|
||||
{{ new Date(scan.started_at).toLocaleString() }}
|
||||
</td>
|
||||
<td class="px-6 py-4 text-body">
|
||||
{{ getDuration(scan.started_at, scan.completed_at) }}
|
||||
</td>
|
||||
<td class="px-6 py-4">
|
||||
<div class="flex space-x-2">
|
||||
<span v-if="getSeverityCount(scan, 'critical') > 0" class="px-2 py-0.5 rounded text-xs font-bold bg-red-500/20 text-red-400 border border-red-500/50" title="Critical">{{ getSeverityCount(scan, 'critical') }}</span>
|
||||
<span v-if="getSeverityCount(scan, 'high') > 0" class="px-2 py-0.5 rounded text-xs font-bold bg-orange-500/20 text-orange-400 border border-orange-500/50" title="High">{{ getSeverityCount(scan, 'high') }}</span>
|
||||
<span v-if="getSeverityCount(scan, 'medium') > 0" class="px-2 py-0.5 rounded text-xs font-bold bg-yellow-500/20 text-yellow-400 border border-yellow-500/50" title="Medium">{{ getSeverityCount(scan, 'medium') }}</span>
|
||||
<span v-if="getSeverityCount(scan, 'low') > 0" class="px-2 py-0.5 rounded text-xs font-bold bg-blue-500/20 text-blue-400 border border-blue-500/50" title="Low">{{ getSeverityCount(scan, 'low') }}</span>
|
||||
<span v-if="getSeverityCount(scan, 'info') > 0" class="px-2 py-0.5 rounded text-xs font-bold bg-border-subtle/50 text-body border border-border-subtle" title="Info">{{ getSeverityCount(scan, 'info') }}</span>
|
||||
<span v-if="totalFindings(scan) === 0" class="text-body text-xs">None</span>
|
||||
</div>
|
||||
</td>
|
||||
<td class="px-6 py-4 text-right">
|
||||
<router-link :to="`/scans/${scan.id}`" class="text-accent hover:text-accent/80 font-medium transition-colors">View Details</router-link>
|
||||
</td>
|
||||
</tr>
|
||||
<tr v-if="scans.length === 0">
|
||||
<td colspan="6" class="px-6 py-8 text-center text-body">No scans recorded yet.</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script setup>
|
||||
import { ref, onMounted, onUnmounted } from 'vue'
|
||||
|
||||
const scans = ref([])
|
||||
let interval = null
|
||||
|
||||
const loadScans = async () => {
|
||||
try {
|
||||
const res = await fetch('/api/scans')
|
||||
scans.value = await res.json() || []
|
||||
} catch (e) {
|
||||
console.error(e)
|
||||
}
|
||||
}
|
||||
|
||||
const getDuration = (start, end) => {
|
||||
if (!end) return '...'
|
||||
const ms = new Date(end) - new Date(start)
|
||||
const sec = Math.floor(ms / 1000)
|
||||
if (sec < 60) return `${sec}s`
|
||||
return `${Math.floor(sec / 60)}m ${sec % 60}s`
|
||||
}
|
||||
|
||||
const getSeverityCount = (scan, sev) => {
|
||||
return scan.finding_counts?.[sev] || 0
|
||||
}
|
||||
|
||||
const totalFindings = (scan) => {
|
||||
if (!scan.finding_counts) return 0
|
||||
return Object.values(scan.finding_counts).reduce((a, b) => a + b, 0)
|
||||
}
|
||||
|
||||
onMounted(() => {
|
||||
loadScans()
|
||||
interval = setInterval(loadScans, 5000)
|
||||
})
|
||||
|
||||
onUnmounted(() => {
|
||||
if (interval) clearInterval(interval)
|
||||
})
|
||||
</script>
|
||||
@@ -0,0 +1,112 @@
|
||||
<template>
|
||||
<div class="space-y-6">
|
||||
<div class="bg-surface rounded-xl p-6 shadow-lg border border-border-subtle backdrop-blur-sm">
|
||||
<h2 class="text-xl font-semibold mb-4 text-heading">Add New Target</h2>
|
||||
<form @submit.prevent="addTarget" class="grid grid-cols-1 md:grid-cols-4 gap-4 items-end">
|
||||
<div>
|
||||
<label class="block text-sm font-medium text-body mb-1">Name</label>
|
||||
<input v-model="form.name" type="text" required class="w-full bg-bg border border-border-subtle rounded-lg px-4 py-2 text-heading focus:ring-2 focus:ring-accent focus:border-transparent outline-none transition-all" placeholder="Prod App">
|
||||
</div>
|
||||
<div>
|
||||
<label class="block text-sm font-medium text-body mb-1">Address / Subnet</label>
|
||||
<input v-model="form.address" type="text" required class="w-full bg-bg border border-border-subtle rounded-lg px-4 py-2 text-heading focus:ring-2 focus:ring-accent focus:border-transparent outline-none transition-all" placeholder="10.0.0.1/24 or example.com">
|
||||
</div>
|
||||
<div>
|
||||
<label class="block text-sm font-medium text-body mb-1">Schedule</label>
|
||||
<select v-model="form.schedule" class="w-full bg-bg border border-border-subtle rounded-lg px-4 py-2 text-heading focus:ring-2 focus:ring-accent focus:border-transparent outline-none transition-all">
|
||||
<option value="manual">Manual Only</option>
|
||||
<option value="@midnight">Daily at Midnight</option>
|
||||
<option value="@hourly">Hourly</option>
|
||||
<option value="0 0 * * 0">Weekly on Sunday</option>
|
||||
</select>
|
||||
</div>
|
||||
<div>
|
||||
<button type="submit" class="w-full bg-accent hover:bg-accent/80 text-bg font-bold py-2 px-4 rounded-lg shadow-md hover:shadow-lg transition-all transform hover:-translate-y-0.5">
|
||||
Add Target
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<div class="bg-surface rounded-xl overflow-hidden shadow-lg border border-border-subtle">
|
||||
<div class="px-6 py-4 border-b border-border-subtle flex justify-between items-center">
|
||||
<h2 class="text-xl font-semibold text-heading">Configured Targets</h2>
|
||||
<button @click="loadTargets" class="text-body hover:text-heading transition-colors">
|
||||
<svg class="w-5 h-5" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M4 4v5h.582m15.356 2A8.001 8.001 0 004.582 9m0 0H9m11 11v-5h-.581m0 0a8.003 8.003 0 01-15.357-2m15.357 2H15"></path></svg>
|
||||
</button>
|
||||
</div>
|
||||
<div class="overflow-x-auto">
|
||||
<table class="w-full text-left text-sm">
|
||||
<thead class="bg-bg/50 text-body">
|
||||
<tr>
|
||||
<th class="px-6 py-3 font-medium">Name</th>
|
||||
<th class="px-6 py-3 font-medium">Address</th>
|
||||
<th class="px-6 py-3 font-medium">Schedule</th>
|
||||
<th class="px-6 py-3 font-medium">Last Scan</th>
|
||||
<th class="px-6 py-3 font-medium text-right">Actions</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody class="divide-y divide-border-subtle">
|
||||
<tr v-for="target in targets" :key="target.id" class="hover:bg-border-subtle/30 transition-colors">
|
||||
<td class="px-6 py-4 text-heading font-medium">{{ target.name }}</td>
|
||||
<td class="px-6 py-4 text-body font-mono text-xs">{{ target.address }}</td>
|
||||
<td class="px-6 py-4 text-body">
|
||||
<span class="px-2 py-1 bg-bg rounded text-xs border border-border-subtle">{{ target.schedule }}</span>
|
||||
</td>
|
||||
<td class="px-6 py-4 text-body">
|
||||
{{ target.last_scan_at ? new Date(target.last_scan_at).toLocaleString() : 'Never' }}
|
||||
</td>
|
||||
<td class="px-6 py-4 text-right space-x-3">
|
||||
<button @click="runScan(target.id)" class="text-accent hover:text-accent/80 font-medium transition-colors">Run Now</button>
|
||||
<button @click="deleteTarget(target.id)" class="text-red-400 hover:text-red-300 font-medium transition-colors">Delete</button>
|
||||
</td>
|
||||
</tr>
|
||||
<tr v-if="targets.length === 0">
|
||||
<td colspan="5" class="px-6 py-8 text-center text-body">No targets configured. Add one above.</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script setup>
|
||||
import { ref, onMounted } from 'vue'
|
||||
|
||||
const targets = ref([])
|
||||
const form = ref({ name: '', address: '', schedule: 'manual' })
|
||||
|
||||
const loadTargets = async () => {
|
||||
try {
|
||||
const res = await fetch('/api/targets')
|
||||
targets.value = await res.json() || []
|
||||
} catch (e) {
|
||||
console.error(e)
|
||||
}
|
||||
}
|
||||
|
||||
const addTarget = async () => {
|
||||
await fetch('/api/targets', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify(form.value)
|
||||
})
|
||||
form.value = { name: '', address: '', schedule: 'manual' }
|
||||
loadTargets()
|
||||
}
|
||||
|
||||
const deleteTarget = async (id) => {
|
||||
if (!confirm('Delete target?')) return
|
||||
await fetch(`/api/targets/${id}`, { method: 'DELETE' })
|
||||
loadTargets()
|
||||
}
|
||||
|
||||
const runScan = async (id) => {
|
||||
await fetch(`/api/targets/${id}/scan`, { method: 'POST' })
|
||||
alert('Scan triggered successfully. Check Scans History.')
|
||||
loadTargets()
|
||||
}
|
||||
|
||||
onMounted(loadTargets)
|
||||
</script>
|
||||
@@ -0,0 +1,8 @@
|
||||
import { createApp } from 'vue'
|
||||
import './style.css'
|
||||
import App from './App.vue'
|
||||
import { router } from './router'
|
||||
|
||||
const app = createApp(App)
|
||||
app.use(router)
|
||||
app.mount('#app')
|
||||
@@ -0,0 +1,15 @@
|
||||
import { createRouter, createWebHistory } from 'vue-router'
|
||||
import TargetManager from './components/TargetManager.vue'
|
||||
import ScansHistory from './components/ScansHistory.vue'
|
||||
import FindingsInspector from './components/FindingsInspector.vue'
|
||||
|
||||
const routes = [
|
||||
{ path: '/', component: TargetManager },
|
||||
{ path: '/scans', component: ScansHistory },
|
||||
{ path: '/scans/:id', component: FindingsInspector, props: true }
|
||||
]
|
||||
|
||||
export const router = createRouter({
|
||||
history: createWebHistory(),
|
||||
routes
|
||||
})
|
||||
@@ -0,0 +1,16 @@
|
||||
@import "tailwindcss";
|
||||
|
||||
@theme {
|
||||
--color-bg: #0d1117;
|
||||
--color-surface: #161b22;
|
||||
--color-accent: #1ebe8a;
|
||||
--color-heading: #e6edf3;
|
||||
--color-body: #8b949e;
|
||||
--color-border-subtle: #30363d;
|
||||
}
|
||||
|
||||
body {
|
||||
margin: 0;
|
||||
background-color: var(--color-bg);
|
||||
color: var(--color-body);
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
import { defineConfig } from 'vite'
|
||||
import vue from '@vitejs/plugin-vue'
|
||||
import tailwindcss from '@tailwindcss/vite'
|
||||
|
||||
// https://vite.dev/config/
|
||||
export default defineConfig({
|
||||
plugins: [
|
||||
vue(),
|
||||
tailwindcss(),
|
||||
],
|
||||
build: {
|
||||
outDir: '../cmd/nucleus/dist',
|
||||
emptyOutDir: true,
|
||||
}
|
||||
})
|
||||
@@ -0,0 +1,8 @@
|
||||
module nucleus
|
||||
|
||||
go 1.26.4
|
||||
|
||||
require (
|
||||
github.com/mattn/go-sqlite3 v1.14.48
|
||||
github.com/robfig/cron/v3 v3.0.1
|
||||
)
|
||||
@@ -0,0 +1,4 @@
|
||||
github.com/mattn/go-sqlite3 v1.14.48 h1:7XHIgl0a8HwOaiK4E47ozLkST78rR9+OtNGx27D/TFs=
|
||||
github.com/mattn/go-sqlite3 v1.14.48/go.mod h1:6JTjA44L93a0QCyJef5YvlPoKXntQPjzWv5gtm9sB6w=
|
||||
github.com/robfig/cron/v3 v3.0.1 h1:WdRxkvbJztn8LMz/QEvLN5sBU+xKpSqwwUO1Pjr4qDs=
|
||||
github.com/robfig/cron/v3 v3.0.1/go.mod h1:eQICP3HwyT7UooqI/z+Ov+PtYAWygg1TEWWzGIFLtro=
|
||||
@@ -0,0 +1,165 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"strconv"
|
||||
|
||||
"nucleus/internal/db"
|
||||
"nucleus/internal/models"
|
||||
"nucleus/internal/runner"
|
||||
"nucleus/internal/scheduler"
|
||||
)
|
||||
|
||||
func RegisterRoutes(mux *http.ServeMux) {
|
||||
mux.HandleFunc("GET /api/targets", getTargets)
|
||||
mux.HandleFunc("POST /api/targets", createTarget)
|
||||
mux.HandleFunc("DELETE /api/targets/{id}", deleteTarget)
|
||||
mux.HandleFunc("POST /api/targets/{id}/scan", triggerScan)
|
||||
mux.HandleFunc("GET /api/scans", getScans)
|
||||
mux.HandleFunc("GET /api/scans/{id}/findings", getFindings)
|
||||
}
|
||||
|
||||
func getTargets(w http.ResponseWriter, r *http.Request) {
|
||||
rows, err := db.DB.Query("SELECT id, name, address, schedule, last_scan_at, created_at FROM targets ORDER BY created_at DESC")
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
defer rows.Close()
|
||||
|
||||
var targets []models.Target
|
||||
for rows.Next() {
|
||||
var t models.Target
|
||||
rows.Scan(&t.ID, &t.Name, &t.Address, &t.Schedule, &t.LastScanAt, &t.CreatedAt)
|
||||
targets = append(targets, t)
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(targets)
|
||||
}
|
||||
|
||||
func createTarget(w http.ResponseWriter, r *http.Request) {
|
||||
var t models.Target
|
||||
if err := json.NewDecoder(r.Body).Decode(&t); err != nil {
|
||||
http.Error(w, err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
res, err := db.DB.Exec("INSERT INTO targets (name, address, schedule) VALUES (?, ?, ?)", t.Name, t.Address, t.Schedule)
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
id, _ := res.LastInsertId()
|
||||
t.ID = int(id)
|
||||
|
||||
scheduler.ReloadScheduler()
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(t)
|
||||
}
|
||||
|
||||
func deleteTarget(w http.ResponseWriter, r *http.Request) {
|
||||
idStr := r.PathValue("id")
|
||||
id, err := strconv.Atoi(idStr)
|
||||
if err != nil {
|
||||
http.Error(w, "invalid id", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
_, err = db.DB.Exec("DELETE FROM targets WHERE id = ?", id)
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
|
||||
scheduler.ReloadScheduler()
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
}
|
||||
|
||||
func triggerScan(w http.ResponseWriter, r *http.Request) {
|
||||
idStr := r.PathValue("id")
|
||||
id, err := strconv.Atoi(idStr)
|
||||
if err != nil {
|
||||
http.Error(w, "invalid id", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
// Run async
|
||||
go runner.RunScan(id, true)
|
||||
|
||||
w.WriteHeader(http.StatusAccepted)
|
||||
w.Write([]byte(`{"message": "scan triggered"}`))
|
||||
}
|
||||
|
||||
func getScans(w http.ResponseWriter, r *http.Request) {
|
||||
rows, err := db.DB.Query(`
|
||||
SELECT s.id, s.target_id, t.name, s.status, s.started_at, s.completed_at
|
||||
FROM scans s
|
||||
JOIN targets t ON s.target_id = t.id
|
||||
ORDER BY s.started_at DESC
|
||||
LIMIT 100
|
||||
`)
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
defer rows.Close()
|
||||
|
||||
var scans []models.Scan
|
||||
for rows.Next() {
|
||||
var s models.Scan
|
||||
rows.Scan(&s.ID, &s.TargetID, &s.TargetName, &s.Status, &s.StartedAt, &s.CompletedAt)
|
||||
|
||||
// Query findings counts by severity
|
||||
counts := make(map[string]int)
|
||||
fRows, err := db.DB.Query("SELECT severity, COUNT(*) FROM findings WHERE scan_id = ? GROUP BY severity", s.ID)
|
||||
if err == nil {
|
||||
for fRows.Next() {
|
||||
var sev string
|
||||
var count int
|
||||
fRows.Scan(&sev, &count)
|
||||
counts[sev] = count
|
||||
}
|
||||
fRows.Close()
|
||||
}
|
||||
s.FindingCounts = counts
|
||||
|
||||
scans = append(scans, s)
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(scans)
|
||||
}
|
||||
|
||||
func getFindings(w http.ResponseWriter, r *http.Request) {
|
||||
idStr := r.PathValue("id")
|
||||
id, err := strconv.Atoi(idStr)
|
||||
if err != nil {
|
||||
http.Error(w, "invalid id", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
rows, err := db.DB.Query("SELECT id, scan_id, template_id, name, severity, host, matched_at, description, detected_at FROM findings WHERE scan_id = ? ORDER BY detected_at DESC", id)
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
defer rows.Close()
|
||||
|
||||
var findings []models.Finding
|
||||
for rows.Next() {
|
||||
var f models.Finding
|
||||
rows.Scan(&f.ID, &f.ScanID, &f.TemplateID, &f.Name, &f.Severity, &f.Host, &f.MatchedAt, &f.Description, &f.DetectedAt)
|
||||
findings = append(findings, f)
|
||||
}
|
||||
|
||||
if findings == nil {
|
||||
findings = []models.Finding{} // return empty array instead of null
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(findings)
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
package db
|
||||
|
||||
import (
|
||||
"database/sql"
|
||||
"log"
|
||||
|
||||
_ "github.com/mattn/go-sqlite3"
|
||||
)
|
||||
|
||||
var DB *sql.DB
|
||||
|
||||
func InitDB(filepath string) {
|
||||
var err error
|
||||
DB, err = sql.Open("sqlite3", filepath)
|
||||
if err != nil {
|
||||
log.Fatal("Failed to open database:", err)
|
||||
}
|
||||
|
||||
if err = DB.Ping(); err != nil {
|
||||
log.Fatal("Failed to ping database:", err)
|
||||
}
|
||||
|
||||
_, err = DB.Exec(Schema)
|
||||
if err != nil {
|
||||
log.Fatal("Failed to create schema:", err)
|
||||
}
|
||||
|
||||
// Enable foreign keys
|
||||
_, err = DB.Exec("PRAGMA foreign_keys = ON;")
|
||||
if err != nil {
|
||||
log.Println("Warning: Failed to enable foreign keys:", err)
|
||||
}
|
||||
|
||||
log.Println("Database initialized successfully at", filepath)
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
package db
|
||||
|
||||
const Schema = `
|
||||
CREATE TABLE IF NOT EXISTS targets (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
name TEXT NOT NULL,
|
||||
address TEXT NOT NULL,
|
||||
schedule TEXT NOT NULL,
|
||||
last_scan_at DATETIME,
|
||||
created_at DATETIME DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS scans (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
target_id INTEGER NOT NULL,
|
||||
status TEXT NOT NULL,
|
||||
started_at DATETIME,
|
||||
completed_at DATETIME,
|
||||
FOREIGN KEY(target_id) REFERENCES targets(id) ON DELETE CASCADE
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS findings (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
scan_id INTEGER NOT NULL,
|
||||
template_id TEXT NOT NULL,
|
||||
name TEXT,
|
||||
severity TEXT,
|
||||
host TEXT,
|
||||
matched_at TEXT,
|
||||
description TEXT,
|
||||
detected_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
FOREIGN KEY(scan_id) REFERENCES scans(id) ON DELETE CASCADE
|
||||
);
|
||||
`
|
||||
@@ -0,0 +1,76 @@
|
||||
package mailer
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"fmt"
|
||||
"log"
|
||||
"net/smtp"
|
||||
"os"
|
||||
|
||||
"nucleus/internal/models"
|
||||
)
|
||||
|
||||
func SendReport(target models.Target, findings []models.Finding) {
|
||||
host := os.Getenv("SMTP_HOST")
|
||||
port := os.Getenv("SMTP_PORT")
|
||||
if host == "" || port == "" {
|
||||
log.Println("SMTP_HOST or SMTP_PORT not set, skipping email report.")
|
||||
return
|
||||
}
|
||||
|
||||
user := os.Getenv("SMTP_USER")
|
||||
pass := os.Getenv("SMTP_PASS")
|
||||
from := os.Getenv("SMTP_FROM")
|
||||
to := os.Getenv("SMTP_TO")
|
||||
|
||||
if from == "" || to == "" {
|
||||
log.Println("SMTP_FROM or SMTP_TO not set, skipping email report.")
|
||||
return
|
||||
}
|
||||
|
||||
var auth smtp.Auth
|
||||
if user != "" && pass != "" {
|
||||
auth = smtp.PlainAuth("", user, pass, host)
|
||||
}
|
||||
|
||||
subject := fmt.Sprintf("Nucleus Scan Report: %s", target.Name)
|
||||
|
||||
var body bytes.Buffer
|
||||
body.WriteString(fmt.Sprintf("To: %s\r\n", to))
|
||||
body.WriteString(fmt.Sprintf("From: %s\r\n", from))
|
||||
body.WriteString(fmt.Sprintf("Subject: %s\r\n", subject))
|
||||
body.WriteString("Content-Type: text/html; charset=UTF-8\r\n\r\n")
|
||||
|
||||
body.WriteString("<html><body style='font-family: sans-serif;'>")
|
||||
body.WriteString(fmt.Sprintf("<h2>Scan Report for %s (%s)</h2>", target.Name, target.Address))
|
||||
body.WriteString("<p>The scheduled Nuclei scan has completed.</p>")
|
||||
|
||||
if len(findings) == 0 {
|
||||
body.WriteString("<p>No findings were detected.</p>")
|
||||
} else {
|
||||
body.WriteString("<table border='1' cellpadding='5' style='border-collapse: collapse; width: 100%;'>")
|
||||
body.WriteString("<tr style='background-color: #f2f2f2; text-align: left;'><th>Severity</th><th>Name</th><th>Host</th><th>Template</th></tr>")
|
||||
for _, f := range findings {
|
||||
color := "#ffffff"
|
||||
switch f.Severity {
|
||||
case "critical": color = "#ffcccc"
|
||||
case "high": color = "#ffe6cc"
|
||||
case "medium": color = "#ffffcc"
|
||||
case "low": color = "#e6f2ff"
|
||||
case "info": color = "#f2f2f2"
|
||||
}
|
||||
body.WriteString(fmt.Sprintf("<tr style='background-color: %s;'><td><strong>%s</strong></td><td>%s</td><td>%s</td><td>%s</td></tr>", color, f.Severity, f.Name, f.Host, f.TemplateID))
|
||||
}
|
||||
body.WriteString("</table>")
|
||||
}
|
||||
|
||||
body.WriteString("</body></html>")
|
||||
|
||||
addr := fmt.Sprintf("%s:%s", host, port)
|
||||
err := smtp.SendMail(addr, auth, from, []string{to}, body.Bytes())
|
||||
if err != nil {
|
||||
log.Printf("Failed to send email report: %v", err)
|
||||
} else {
|
||||
log.Println("Successfully sent email report for target", target.Name)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
package models
|
||||
|
||||
import "time"
|
||||
|
||||
type Target struct {
|
||||
ID int `json:"id"`
|
||||
Name string `json:"name"`
|
||||
Address string `json:"address"`
|
||||
Schedule string `json:"schedule"`
|
||||
LastScanAt *time.Time `json:"last_scan_at"`
|
||||
CreatedAt time.Time `json:"created_at"`
|
||||
}
|
||||
|
||||
type Scan struct {
|
||||
ID int `json:"id"`
|
||||
TargetID int `json:"target_id"`
|
||||
TargetName string `json:"target_name"` // For UI
|
||||
Status string `json:"status"` // "running", "completed", "failed"
|
||||
StartedAt time.Time `json:"started_at"`
|
||||
CompletedAt *time.Time `json:"completed_at"`
|
||||
FindingCounts map[string]int `json:"finding_counts,omitempty"` // aggregated by severity
|
||||
}
|
||||
|
||||
type Finding struct {
|
||||
ID int `json:"id"`
|
||||
ScanID int `json:"scan_id"`
|
||||
TemplateID string `json:"template_id"`
|
||||
Name string `json:"name"`
|
||||
Severity string `json:"severity"`
|
||||
Host string `json:"host"`
|
||||
MatchedAt string `json:"matched_at"`
|
||||
Description string `json:"description"`
|
||||
DetectedAt time.Time `json:"detected_at"`
|
||||
}
|
||||
|
||||
// Nuclei JSONL Output Structure (Partial for what we need)
|
||||
type NucleiFinding struct {
|
||||
TemplateID string `json:"template-id"`
|
||||
Info struct {
|
||||
Name string `json:"name"`
|
||||
Severity string `json:"severity"`
|
||||
Description string `json:"description"`
|
||||
} `json:"info"`
|
||||
Host string `json:"host"`
|
||||
MatchedAt string `json:"matched-at"`
|
||||
Timestamp string `json:"timestamp"`
|
||||
}
|
||||
@@ -0,0 +1,100 @@
|
||||
package runner
|
||||
|
||||
import (
|
||||
"bufio"
|
||||
"encoding/json"
|
||||
"log"
|
||||
"os/exec"
|
||||
"time"
|
||||
|
||||
"nucleus/internal/db"
|
||||
"nucleus/internal/mailer"
|
||||
"nucleus/internal/models"
|
||||
)
|
||||
|
||||
func RunScan(targetID int, isManual bool) {
|
||||
// 1. Get Target
|
||||
row := db.DB.QueryRow("SELECT id, name, address, schedule FROM targets WHERE id = ?", targetID)
|
||||
var t models.Target
|
||||
err := row.Scan(&t.ID, &t.Name, &t.Address, &t.Schedule)
|
||||
if err != nil {
|
||||
log.Println("Failed to find target for scan:", err)
|
||||
return
|
||||
}
|
||||
|
||||
// 2. Create Scan Record
|
||||
res, err := db.DB.Exec("INSERT INTO scans (target_id, status, started_at) VALUES (?, 'running', ?)", t.ID, time.Now())
|
||||
if err != nil {
|
||||
log.Println("Failed to create scan record:", err)
|
||||
return
|
||||
}
|
||||
scanID, _ := res.LastInsertId()
|
||||
|
||||
// 3. Update target last_scan_at
|
||||
db.DB.Exec("UPDATE targets SET last_scan_at = ? WHERE id = ?", time.Now(), t.ID)
|
||||
|
||||
// 4. Run Nuclei
|
||||
cmd := exec.Command("nuclei", "-target", t.Address, "-jsonl", "-silent")
|
||||
|
||||
stdout, err := cmd.StdoutPipe()
|
||||
if err != nil {
|
||||
log.Println("Failed to get stdout pipe:", err)
|
||||
db.DB.Exec("UPDATE scans SET status = 'failed', completed_at = ? WHERE id = ?", time.Now(), scanID)
|
||||
return
|
||||
}
|
||||
|
||||
if err := cmd.Start(); err != nil {
|
||||
log.Println("Failed to start nuclei:", err)
|
||||
db.DB.Exec("UPDATE scans SET status = 'failed', completed_at = ? WHERE id = ?", time.Now(), scanID)
|
||||
return
|
||||
}
|
||||
|
||||
var findings []models.Finding
|
||||
hasMediumOrHigher := false
|
||||
|
||||
scanner := bufio.NewScanner(stdout)
|
||||
for scanner.Scan() {
|
||||
line := scanner.Bytes()
|
||||
var nf models.NucleiFinding
|
||||
if err := json.Unmarshal(line, &nf); err == nil {
|
||||
// Insert finding
|
||||
res, err := db.DB.Exec(`
|
||||
INSERT INTO findings (scan_id, template_id, name, severity, host, matched_at, description)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?)
|
||||
`, scanID, nf.TemplateID, nf.Info.Name, nf.Info.Severity, nf.Host, nf.MatchedAt, nf.Info.Description)
|
||||
|
||||
if err == nil {
|
||||
fid, _ := res.LastInsertId()
|
||||
f := models.Finding{
|
||||
ID: int(fid),
|
||||
ScanID: int(scanID),
|
||||
TemplateID: nf.TemplateID,
|
||||
Name: nf.Info.Name,
|
||||
Severity: nf.Info.Severity,
|
||||
Host: nf.Host,
|
||||
MatchedAt: nf.MatchedAt,
|
||||
Description: nf.Info.Description,
|
||||
}
|
||||
findings = append(findings, f)
|
||||
|
||||
if f.Severity == "critical" || f.Severity == "high" || f.Severity == "medium" {
|
||||
hasMediumOrHigher = true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
err = cmd.Wait()
|
||||
status := "completed"
|
||||
if err != nil {
|
||||
log.Println("Nuclei finished with error:", err)
|
||||
status = "failed"
|
||||
}
|
||||
|
||||
db.DB.Exec("UPDATE scans SET status = ?, completed_at = ? WHERE id = ?", status, time.Now(), scanID)
|
||||
|
||||
// Send Email Report if manual or has medium+ severity
|
||||
if isManual || hasMediumOrHigher {
|
||||
mailer.SendReport(t, findings)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,53 @@
|
||||
package scheduler
|
||||
|
||||
import (
|
||||
"log"
|
||||
|
||||
"github.com/robfig/cron/v3"
|
||||
|
||||
"nucleus/internal/db"
|
||||
"nucleus/internal/models"
|
||||
"nucleus/internal/runner"
|
||||
)
|
||||
|
||||
var c *cron.Cron
|
||||
|
||||
func InitScheduler() {
|
||||
c = cron.New()
|
||||
|
||||
// Load all targets
|
||||
rows, err := db.DB.Query("SELECT id, name, address, schedule FROM targets")
|
||||
if err != nil {
|
||||
log.Fatal("Failed to load targets for scheduler:", err)
|
||||
}
|
||||
defer rows.Close()
|
||||
|
||||
for rows.Next() {
|
||||
var t models.Target
|
||||
if err := rows.Scan(&t.ID, &t.Name, &t.Address, &t.Schedule); err != nil {
|
||||
continue
|
||||
}
|
||||
|
||||
if t.Schedule != "" && t.Schedule != "manual" {
|
||||
AddJob(t)
|
||||
}
|
||||
}
|
||||
|
||||
c.Start()
|
||||
log.Println("Scheduler started successfully")
|
||||
}
|
||||
|
||||
func AddJob(t models.Target) {
|
||||
_, err := c.AddFunc(t.Schedule, func() {
|
||||
log.Printf("Triggering scheduled scan for target %s (%s)", t.Name, t.Address)
|
||||
runner.RunScan(t.ID, false)
|
||||
})
|
||||
if err != nil {
|
||||
log.Printf("Failed to schedule target %s: %v", t.Name, err)
|
||||
}
|
||||
}
|
||||
|
||||
func ReloadScheduler() {
|
||||
c.Stop()
|
||||
InitScheduler()
|
||||
}
|
||||
Reference in New Issue
Block a user