
secator - ペンテスターのスイスアーミーナイフ
<h1 align="center">
<img src="https://assets.kitploit.com/production/public/readmes/6300/dc9ae605fb3dd81cb606836bd853e391122c4acde19b8554c2db00fcaa28a6e5.png" width="400">
</h1>
<h4 align="center">ペネトレーションテスターのスイスアーミーナイフ。</h4>
<p align="center">
<!-- <a href="https://goreportcard.com/report/github.com/freelabz/secator"><img src="https://goreportcard.com/badge/github.com/freelabz/secator"></a> -->
<img src="https://img.shields.io/badge/python-3.6-blue.svg">
<a href="https://github.com/freelabz/secator/releases"><img src="https://img.shields.io/github/release/freelabz/secator"></a>
<a href="https://github.com/freelabz/secator/blob/main/LICENSE"><img src="https://img.shields.io/badge/License-BSL%201.1-brightgreen.svg"></a>
<a href="https://pypi.org/project/secator/"><img src="https://img.shields.io/pypi/dm/secator"></a>
<a href="https://twitter.com/freelabz"><img src="https://img.shields.io/twitter/follow/freelabz.svg?logo=twitter"></a>
<a href="https://youtube.com/@FreeLabz"><img src="https://img.shields.io/youtube/channel/subscribers/UCu-F6SpU0h2NP18zBBP04cw?style=social&label=Subscribe%20@FreeLabz"></a>
<a href="https://discord.gg/nyHjC2aTrq"><img src="https://img.shields.io/discord/695645237418131507.svg?logo=discord"></a>
</p>
<p align="center">
<a href="#features">機能</a> •
<a href="#supported-commands">サポートされているコマンド</a> •
<a href="#install-secator">インストール</a> •
<a href="#usage">使い方</a> •
<a href="https://docs.freelabz.com">ドキュメント</a> •
<a href="https://discord.gg/nyHjC2aTrq">Discordで参加しよう!</a>
</p>
`secator`は、セキュリティ評価に使用されるタスクおよびワークフローランナーです。数十の有名なセキュリティツールをサポートしており、ペネトレーションテスターやセキュリティ研究者の生産性向上を目的として設計されています。
# 機能

* **厳選されたコマンド一覧**
* **統一された入力オプション**
* **統一された出力スキーマ**
* **CLIとライブラリとしての使用**
* **Celeryによる分散オプション**
* **シンプルなタスクから複雑なワークフローまで**
* **カスタマイズ可能**
## サポートされているツール
`secator`は以下のツールを統合しています:
<!-- START_TOOLS_TABLE -->
| 名前 | 説明 | カテゴリ |
|-----------------------------------------------------------------|----------------------------------------------------------------------------------|-------------------|
| [arjun](https://github.com/s0md3v/Arjun) | HTTPパラメータ発見スイート。 | `url/fuzz/params` |
| arp | システムのARPキャッシュを表示します。 | `ip/recon` |
| [arpscan](https://github.com/royhills/arp-scan) | ARPを使用して、CIDR範囲内の生存ホストをスキャンします。 | `ip/recon` |
| [bbot](https://github.com/blacklanternsecurity/bbot) | 多目的スキャナー。 | `vuln/scan` |
| [bup](https://github.com/laluka/bypass-url-parser) | 40Xバイパッサー。 | `url/bypass` |
| [cariddi](https://github.com/edoardottt/cariddi) | エンドポイント、シークレット、APIキー、拡張子、トークンなどをクロールします。 | `url/crawl` |
| [dalfox](https://github.com/hahwul/dalfox) | 強力なオープンソースXSSスキャンツール。 | `url/fuzz` |
| [dirsearch](https://github.com/maurosoria/dirsearch) | 高度なWebパスブルートフォーサー。 | `url/fuzz` |
| [dnsx](https://github.com/projectdiscovery/dnsx) | dnsxは、様々なretryablednsライブラリを実行するために設計された、高速で多目的なDNSツールキットです。 | `dns/fuzz` |
| [feroxbuster](https://github.com/epi052/feroxbuster) | Rustで書かれた、シンプルで高速、再帰的なコンテンツ発見ツール。 | `url/fuzz` |
| [ffuf](https://github.com/ffuf/ffuf) | Goで書かれた高速なWebファザー。 | `url/fuzz` |
| [fping](https://github.com/schweikert/fping) | ネットワークホストにICMPエコープローブを送信します。pingと似ていますが、はるかに優れています。 | `ip/recon` |
| [gau](https://github.com/lc/gau) | AlienVaultのOpen Threat Exchange、Wayback Machine、Common Crawl、URLScanから既知のURLを取得します。 | `pattern/scan` |
| [getasn](https://github.com/Vulnpire/getasn) | IPアドレスからASN情報を取得します。 | `ip/probe` |
| [gf](https://github.com/tomnomnom/gf) | grepのラッパーで、特定のものをgrepするのに役立ちます。 | `pattern/scan` |
| [gitleaks](https://github.com/gitleaks/gitleaks) | gitリポジトリ、ファイル、標準入力からパスワード、APIキー、トークンなどのシークレットを検出するツールです。 | `secret/scan` |
| [gospider](https://github.com/jaeles-project/gospider) | Goで書かれた高速なWebスパイダー。 | `url/crawl` |
| [grype](https://github.com/anchore/grype) | コンテナイメージとファイルシステム用の脆弱性スキャナー。 | `vuln/scan` |
| [h8mail](https://github.com/khast3x/h8mail) | 電子メール情報とパスワード検索ツール。 | `user/recon/email` |
| [httpx](https://github.com/projectdiscovery/httpx) | 高速で多目的なHTTPツールキット。 | `url/probe` |
| [jswhois](https://github.com/jschauma/jswhois) | JSON形式のWHOIS | `domain/info` |
| [katana](https://github.com/projectdiscovery/katana) | 次世代のクローリングおよびスパイダリングフレームワーク。 | `url/crawl` |
| [maigret](https://github.com/soxoj/maigret) | ユーザー名から人物に関する資料を収集します。 | `user/recon/username` |
| [mapcidr](https://github.com/projectdiscovery/mapcidr) | 指定されたサブネット/CIDR範囲に対して複数の操作を実行するユーティリティプログラム。 | `ip/recon` |
| [msfconsole](https://docs.rapid7.com/metasploit/msf-overview/) | Metasploit Frameworkにアクセスして操作するためのCLI。 | `exploit/attack` |
| [naabu](https://github.com/projectdiscovery/naabu) | Goで書かれたポートスキャンツール。 | `port/scan` |
| [nmap](https://github.com/nmap/nmap) | ネットワークマッパーは、ネットワーク探索とセキュリティ監査のためのフリーでオープンソースのユーティリティです。 | `port/scan` |
| [nuclei](https://github.com/projectdiscovery/nuclei) | シンプルなYAMLベースのDSLに基づく、高速でカスタマイズ可能な脆弱性スキャナー。 | `vuln/scan` |
| [search_vulns](https://github.com/ra1nb0rn/search_vulns) | 製品名またはCPEによってソフトウェアの既知の脆弱性を検索します。 | `vuln/recon` |
| [searchsploit](https://gitlab.com/exploit-database/exploitdb) | ExploitDBに基づくエクスプロイト検索ツール。 | `exploit/recon` |
| [sshaudit](https://github.com/jtesta/ssh-audit) | SSHサーバーおよびクライアントのセキュリティ監査(バナー、鍵交換、暗号化、MAC、圧縮など)。 | `ssh/audit/security` |
| [subfinder](https://github.com/projectdiscovery/subfinder) | 高速なパッシブサブドメイン列挙ツール。 | `dns/recon` |
| [testssl](https://github.com/testssl/testssl.sh) | SSL/TLSセキュリティスキャナー。暗号、プロトコル、暗号上の欠陥を含む。 | `dns/recon/tls` |
| [trivy](https://github.com/aquasecurity/trivy) | 包括的で多用途なセキュリティスキャナー。 | `vuln/scan` |
| [trufflehog](https://github.com/trufflesecurity/trufflehog) | TruffleHogを使用してgitリポジトリやファイルシステム内のシークレットを見つけるツール。 | `secret/scan` |
| [urlfinder](https://github.com/projectdiscovery/urlfinder) | テキスト内のURLを見つけます。 | `pattern/scan` |
| [wafw00f](https://github.com/EnableSecurity/wafw00f) | Webアプリケーションファイアウォールフィンガープリンティングツール。 | `waf/scan` |
| [whois](https://github.com/mboot-github/WhoisDomain) | whoisツールは、ドメイン名とIPアドレスに関する登録情報を取得します。 | |
| [wpprobe](https://github.com/Chocapikk/wpprobe) | 高速なWordPressプラグイン列挙ツール。 | `vuln/scan/wordpress` |
| [wpscan](https://github.com/wpscanteam/wpscan) | WordPressセキュリティスキャナー。 | `vuln/scan/wordpress` |
| [x8](https://github.com/Sh1Yo/x8) | Rustで書かれた隠しパラメータ発見スイート。 | `url/fuzz/params` |
| [xurlfind3r](https://github.com/hueristiq/xurlfind3r) | 指定されたドメインのURLを、シンプルかつパッシブで効率的な方法で発見します | `url/recon` |
<!-- END_TOOLS_TABLE -->
新しいツールの追加リクエストは、Issueを開いてお気軽にどうぞ。ただし、事前にそのツールが私たちの選択基準に準拠しているか確認してください。準拠していなくても、`secator`に統合したい場合は、プラグインすることができます([開発者ガイド](https://docs.freelabz.com/for-developers/writing-custom-tasks)を参照)。
## secatorのインストール
<details>
<summary>Bash</summary>
```sh
bash -c "$(curl -fsSL https://raw.githubusercontent.com/freelabz/secator/main/scripts/install_universal.sh)"
```
***注意:** オプションフラグ `--version`、`--templates`、`--addons`、`--tools` をサポートしています。詳細はスクリプトを `--help` 付きで実行してください。*
</details>
<details>
<summary>Pipx</summary>
```sh
pipx install secator
```
***注意:** [pipx](https://pipx.pypa.io/stable/installation/) がインストールされていることを確認してください。*
</details>
<details>
<summary>Pip</summary>
```sh
pip install secator
```
</details>
<details>
<summary>Docker</summary>
```sh
docker run -it --rm --net=host -v ~/.secator:/root/.secator freelabz/secator --help
```
ボリュームマウント -v は、すべてのsecatorレポートをホストマシンに保存するために必要であり、--net=host はホストネットワークへの完全なアクセスを許可するために推奨されます。
このコマンドをエイリアスにすると、より簡単に実行できます:
```sh
alias secator="docker run -it --rm --net=host -v ~/.secator:/root/.secator freelabz/secator"
```
これで、ベアメタルにインストールされているかのようにsecatorを実行できます:
```
secator --help
```
</details>
<details>
<summary>Docker Compose</summary>
```sh
git clone https://github.com/freelabz/secator
cd secator
docker-compose up -d
docker-compose exec secator-client secator --help
```
</details>
***注意:*** Docker または Docker Compose のインストール方法を選択した場合、次のセクションはスキップして[使い方](#usage)に直接進んでください。
## 使い方
```sh
secator --help
```
### 使用例
`secator`で何ができるかについての完全なチートシートを入手するには、以下の出力をお読みください:
```sh
secator cheatsheet
```
ファジングタスクを実行する (`ffuf`):
```sh
secator x ffuf http://testphp.vulnweb.com/FUZZ
```
URLクロールワークフローを実行する:
```sh
secator w url_crawl http://testphp.vulnweb.com
```
ホストスキャンを実行する:
```sh
secator s host mydomain.com
```
使用できるすべてのタスク/ワークフロー/スキャンを一覧表示するには:
```sh
secator x --help
secator w --help
secator s --help
```
システムにインストールされている言語やツール(およびそのバージョン)を確認するには:
```sh
secator health
```
### クエリ
`secator` では、`secator query`(または `secator q`)コマンドを使用して、以前のすべてのレポートをクエリし、クエリを再利用できます。
`secator q <arg>` は、引数を3つのステップで解決します:
1. **保存済みクエリ名** — `<arg>` が保存済みクエリと一致する場合、その式が使用されます。
2. **フィルター式** — `<arg>` がフィルターのように見える場合(`==`、`<`、`~=`、`&&`、…を含む)、そのまま渡されます。
3. **自然言語** — それ以外の場合は、AIチャットに送信されます(`secator x ai --mode chat`)。
```sh
# 生の式を直接実行
secator q "vulnerability.tags ~= 'kev' && vulnerability.confidence == 'high'" # KEV(既知の悪用された脆弱性)+ 高信頼度の脆弱性
secator q "vulnerability.severity == 'critical' && vulnerability.tags ~= 'exploitable' && vulnerability.confidence == 'high'" # 致命的 + 悪用可能 + 高信頼度の脆弱性
secator q "vulnerability.severity_nb < 2 && vulnerability.confidence == 'high'" # 重要度が高より高い + 高信頼度の脆弱性
secator q "exploit.cves ~= 'CVE-2021-44521'" # 脆弱性 CVE-2021-44521 に対して見つかったエクスプロイト
secator q "port" -f "{host} {port} {service_name}" | cut -d " " -f2 | sort | uniq -c | sort -nr | head -n 15 # トップ15ポート
secator q "port" -f "{host} {port} {service_name}" | cut -d " " -f3,4,5,6 | awk 'NF > 0' | sort | uniq -c | sort -nr | head -n 15 # トップ15サービス
secator q "technology" -f "{product}/{version}" | sort | uniq -c | sort -nr | head -n 15 # トップ15テクノロジー
secator q "port.state == 'open'" -rf scans/23,tasks/10 # スキャン23とタスク10の結果のみ
# クエリを保存して実行
secator c set queries.critical_vulns "vulnerability.severity_nb < 2" # クエリを保存
secator c get queries # 保存済みクエリを一覧表示
secator q critical_vulns -f "{vulnerability.matched_at}" -ws secator.cloud # ワークスペースで保存済みクエリを実行 + ターゲットを抽出
# 自然言語で質問する(AIチャットタスクを実行)
secator q "Analyze my workspace data"
```
`secator q` は `secator r show` と同じオプションを受け入れます(`-o/--output`、
`-d/--time-delta`、`-f/--format`、`-w/-ws/--workspace`、`--driver`、`--dedupe`)、
さらに `-rf/--report-filter` でクエリを特定のランナーパスにスコープできます(
`r show` の `REPORT_QUERY` 引数に相当します)。AIチャットパスでは、ワークスペースとプロンプトのみが使用されます。
### シェル補完
`secator` は bash、zsh、fish のシェル補完をサポートしています。これにより、以下の自動補完が提供されます:
- タスク名(例:`nmap`、`httpx`、`nuclei`)
- ワークフロー名(例:`url_crawl`、`subdomain_recon`)
- スキャン名(例:`host`、`domain`、`network`)
- CLIオプション(例:`--profiles`、`--workspace`、`--driver`、`--output`)
シェル補完をインストールするには:
**Bash:**
```sh
secator util completion --shell bash --install
source ~/.bashrc
```
**Zsh:**
```sh
secator util completion --shell zsh --install
source ~/.zshrc
```
**Fish:**
```sh
secator util completion --shell fish --install
```
インストール後、タブ補完を使用できます:
```sh
secator x n<TAB> # nmap、naabu、nuclei などに補完されます
secator w url_<TAB> # url_crawl、url_fuzz、url_dirsearch などに補完されます
secator x nmap --profiles ag<TAB> # aggressive に補完されます
```
## ツールのインストール
`secator` は、ツールを初めて使用するときに自動的にインストールします。
この動作を防ぐには、`secator config set security.autoinstall_commands false` または `SECATOR_SECURITY_AUTOINSTALL_COMMANDS=0` を使用して `security.autoinstall_commands` を `false` に設定します。
すべてのツールをインストールするには、次のコマンドを実行できます:
```sh
secator install tools
```
## アドオンのインストール
`secator` ではアドオンが利用可能です。詳細は[ドキュメント](https://docs.freelabz.com/getting-started/installation#installing-addons-optional)をご確認ください。
例えば、`mongodb` アドオンを使用すると、ランナーの結果をMongoDBに送信できます。
## さらに詳しく
`secator` をより深く知るには、以下をご確認ください:
* 完全な[ドキュメント](https://docs.freelabz.com)
* 入門用[チュートリアルビデオ](https://youtu.be/-JmUTNWQDTQ?si=qpAClDWMXo2zwUK7)
* [Mediumの記事](https://medium.com/p/09333f3d3682)
* ソーシャルメディアでフォロー: Twitterで [@freelabz](https://twitter.com/freelabz)、YouTubeで [@FreeLabz](https://youtube.com/@FreeLabz)
## 統計情報
<a href="https://star-history.com/#freelabz/secator&Date">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=freelabz/secator&type=Date&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=freelabz/secator&type=Date" />
<img alt="Star History Chart" src="https://api.star-history.com/svg?repos=freelabz/secator&type=Date" />
</picture>
</a>