منصوبے کے بارے میں
CERT-X-GEN روایتی سیکیورٹی اسکینرز کی محدودیتوں کو دور کرنے کے لیے بنایا گیا ہے، جو تمام detection logic کو محدود YAML DSLs میں مجبور کرتے ہیں جو multi-step protocol conversations، binary protocol parsing، conditional branching، performance-critical operations، یا native library access کو آسانی سے سپورٹ نہیں کر سکتے۔ بنیادی runtime ایک language-agnostic execution layer ہے جو 12 زبانوں میں detection templates لکھنے کی سہولت دیتا ہے: Python، Go، Rust، C، C++، Java، JavaScript، Ruby، Perl، PHP، Shell، اور YAML۔ اس میں compiled زبانوں کے لیے compilation caching، rate limiting کے ساتھ parallel template execution، اور ایک سادہ template contract شامل ہے جہاں templates environment variables سے target connection details پڑھتے ہیں، custom detection logic چلاتے ہیں، اور structured JSON findings واپس کرتے ہیں۔ یہ ٹول دو بنیادی workflows فراہم کرتا ہے: 1. cxg scan کمانڈ کے ذریعے Template scanning: یہ polyglot detection templates کو targets کے خلاف چلاتا ہے جو single hosts، files میں target lists، CIDR ranges، URLs، یا local CLI binaries کے طور پر متعین ہوتے ہیں۔ یہ glob-based template selection، custom port ranges، اور متعدد output formats (JSON، CSV، SARIF، HTML، Markdown) کو سپورٹ کرتا ہے جو pipeline integration کے لیے بہتر بنائے گئے ہیں۔ 2. cxg pentest کمانڈ کے ذریعے AI-driven whitebox pentesting: یہ source code analysis findings سے فائدہ اٹھا کر security hypotheses کی درجہ بندی کرتا ہے، configurable AI providers (Claude، Codex، Gemini، Anthropic، OpenAI، یا custom bridge endpoints) استعمال کرتا ہے تاکہ JavaScript probe templates تیار کیے جا سکیں، اور web applications یا Electron desktop apps کے خلاف authenticated Chromium contexts میں probes چلاتا ہے۔ اس میں authenticated testing کے لیے built-in session management، ایک CI mode جو expired sessions پر سخت ناکامی دیتا ہے تاکہ unauthenticated probing سے بچا جا سکے، اور structured reports شامل ہیں جو findings کو اصل source code exposure claims سے جوڑتے ہیں۔ اضافی CLI صلاحیتوں میں cxg build شامل ہے جو scan verdicts کی توثیق کے لیے sanitizers کے ساتھ instrumented targets کو compile کرتا ہے، cxg template جو الگ Git-hosted official template library کو manage کرتا ہے، cxg search جو full-text اور regex template lookup فراہم کرتا ہے، cxg ai جو AI-powered template generation دیتا ہے، cxg mcp جو AI agent integration کے لیے Model Context Protocol server کے طور پر چلتا ہے، cxg sandbox جو per-language dependency environments کو manage کرتا ہے، cxg config جو configuration generation اور validation کے لیے ہے، cxg update جو self-updating کرتا ہے، اور cxg version جو version checks کرتا ہے۔ منصوبہ بند cxg server REST API ابھی تک نافذ نہیں کیا گیا۔ Installation کے اختیارات میں Cargo (crates.io)، Homebrew، ایک quick curl install script، pre-built Docker images، Linux، macOS، اور Windows کے لیے static binaries، اور source builds شامل ہیں۔ صارفین کو templates چلاتے وقت احتیاط برتنے کا مشورہ دیا جاتا ہے، کیونکہ templates invoking user کے مکمل network اور filesystem access کے ساتھ child processes کے طور پر چلتے ہیں، اور کوئی built-in sandboxing یا resource limiting موجود نہیں ہے۔ یہ پروجیکٹ Apache 2.0 کے تحت licensed ہے، اور official documentation docs.bugb.io/cxg/ پر hosted ہے۔
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.