
Ein asynchroner Enumeration- und Schwachstellenscanner. Führe alle Tools auf allen Hosts aus.
celerystalk hilft Ihnen, Ihren Netzwerk-Scan/-Enumeration-Prozess mit asynchronen Jobs (auch Aufgaben genannt) zu automatisieren, während Sie die volle Kontrolle darüber behalten, welche Tools Sie ausführen möchten.

Interaktive Demo: Bug Bounty Modus (HackerOne)
Interaktive Demo: Schwachstellenanalyse / PenTest Modus (Ausgemusterte HackTheBox.eu Maschinen)
| Phase | Befehl | Beispiele verwendeter Tools |
|---|---|---|
| DNS-Recon/Enumeration | ./celerystalk subdomains -d domain1,domain2 | Amass, sublist3r |
| Scope definieren, Nmap/Nessus importieren | ./celerystalk import [scan_data,scope_files,etc.] | celerystalk |
| Port-Scanning | ./celerystalk nmap | nmap |
| Verzeichnis- und Datei-Enumeration, Schwachstellenidentifikation | ./celerystalk scan | Gobuster, Nikto, Photon, sqlmap, wpscan, hydra, medusa, wappalyzer, whatweb usw. |
| Screenshots | ./celerystalk screenshots | Aquatone |
| Analyse | ./celerystalk report | celerystalk |
celerystalk ist:
Sie müssen celerystalk als root installieren und ausführen.``` git clone https://github.com/sethsec/celerystalk.git cd celerystalk/setup ./install.sh cd .. ./celerystalk -h
## Docker-Container von Dockerhub verwenden```
docker pull sethsec/celerystalk:latest
docker run -p 27007:27007 -ti celerystalk
docker build -t celerystalk https://github.com/sethsec/celerystalk.git docker run -p 27007:27007 -ti celerystalk
## Verwendung von celerystalk - Die Grundlagen
### [URL-Modus] - Wie man eine URL (oder mehrere URLs in einer Datei) scannt
#### Starte alle aktivierten Tools gegen eine URL oder viele URLs in einer Datei, ohne Scope, nmap, etc. importieren zu müssen.```
# ./celerystalk scan -u url or filename # Run all enabled commands against specified url(s)
# ./celerystalk query watch (then Ctrl+c) # Wait for scans to finish
# ./celerystalk screenshots # Take screenshots
# ./celerystalk report # Generate report
#### Oder importieren Sie eine Liste der Hosts, die im Scope sind, und lassen Sie celerystalk nmap für Sie ausführen```
# ./celerystalk import -S scope.txt # Import IP/CIDR/Ranges and mark as in scope
# ./celerystalk nmap # Nmap all in-scope hosts (reads options from config.ini)
## Advanced Usage: Bug Bounty Mode vs Vulnerability Assessment Mode
You define the mode at workspace instantiation. The default workspace is VAPT mode, but you have two options for manually
created workspaces.
* If you are starting with in scope IP addresses/ranges/CIDRs, use Vulnerability Assessment and PenTest (VAPT) mode.
* If you are starting with in scope domains, use Bug Bounty (BB) mode.
### [Bug Bounty Mode]
* In BB mode, all subdomains found with celerystalk or manually imported are marked in scope.
#### Find subdomains, define out of scope hosts, scan everything else```
# ./celerystalk workspace create -o /dir -m bb # Create default workspace and set output dir
# ./celerystalk subdomains -d company.com,dom.net # Find subdomains and determine if in scope
# ./celerystalk import -S scope.txt (optional) # Import IP/CIDR/Ranges and mark as in scope
# ./celerystalk import -O out_scope.txt (optional) # Define HOSTS/IPs that are out of scope
# ./celerystalk nmap (optional) # Nmap all in-scope hosts (reads options from config.ini)
# ./celerystalk import -f client.xml (optional) # If you would rather import an nmap file you already ran
# ./celerystalk scan [--noIP] # Run all enabled commands against all in scope hosts
# ./celerystalk query watch (then Ctrl+c) # Wait for scans to finish
# ./celerystalk screenshots # Take screenshots
# ./celerystalk report # Generate report
Hinweis: Sie können zuerst den Subdomain-Befehl ausführen und dann den Scope definieren, oder Sie können den Scope definieren und Subdomains importieren.
**Hinweis:** Sie können zuerst den subdomains-Befehl ausführen und dann den Scope definieren, oder Sie können den Scope definieren und Subdomains importieren.