
비동기적 열거 및 취약점 스캐너입니다. 모든 호스트에서 모든 도구를 실행합니다.
celerystalk는 비동기 작업(aka tasks)을 통해 네트워크 스캐닝/정보 수집 과정을 자동화하면서도, 실행할 도구를 완전히 제어할 수 있도록 도와줍니다.

대화형 데모: 버그 바운티 모드 (HackerOne)
대화형 데모: 취약점 평가/침투 테스트 모드 (은퇴한 HackTheBox.eu 머신)
| 단계 | 명령어 | 사용된 도구 예시 |
|---|---|---|
| DNS 정찰/정보 수집 | ./celerystalk subdomains -d domain1,domain2 | Amass, sublist3r |
| 범위 정의, nmap/nessus 가져오기 | ./celerystalk import [scan_data,scope_files,etc.] | celerystalk |
| 포트 스캐닝 | ./celerystalk nmap | nmap |
| 디렉터리 및 파일 열거, 취약점 식별 | ./celerystalk scan | Gobuster, Nikto, Photon, sqlmap, wpscan, hydra, medusa, wappalyzer, whatweb 등 |
| 스크린샷 | ./celerystalk sceenshots | Aquatone |
| 분석 | ./celerystalk report | celerystalk |
celerystalk는 다음과 같은 특징이 있습니다:
celerystalk는 root로 설치하고 실행해야 합니다.``` git clone https://github.com/sethsec/celerystalk.git cd celerystalk/setup ./install.sh cd .. ./celerystalk -h
## Dockerhub에서 docker container 사용하기```
docker pull sethsec/celerystalk:latest
docker run -p 27007:27007 -ti celerystalk
docker build -t celerystalk https://github.com/sethsec/celerystalk.git docker run -p 27007:27007 -ti celerystalk
## Using celerystalk - The basics
### [URL Mode] - How to scan a a URL (or multiple URLs in a file)
#### Launch all enabled tools against a URL or many URLs in a file without having to import scope, nmap, etc.```
# ./celerystalk scan -u url or filename # Run all enabled commands against specified url(s)
# ./celerystalk query watch (then Ctrl+c) # Wait for scans to finish
# ./celerystalk screenshots # Take screenshots
# ./celerystalk report # Generate report
#### 또는, 범위 내 호스트 목록을 가져와 celerystalk가 nmap을 실행하도록 합니다```
# ./celerystalk import -S scope.txt # Import IP/CIDR/Ranges and mark as in scope
# ./celerystalk nmap # Nmap all in-scope hosts (reads options from config.ini)
## 고급 사용법: 버그 바운티 모드 대 취약점 평가 모드
작업 공간 생성 시 모드를 정의합니다. 기본 작업 공간은 VAPT 모드이지만, 수동으로 생성된 작업 공간에 대해서는 두 가지 옵션이 있습니다.
* 범위 내 IP 주소/범위/CIDR로 시작하는 경우 취약점 평가 및 침투 테스트(VAPT) 모드를 사용하세요.
* 범위 내 도메인으로 시작하는 경우 버그 바운티(BB) 모드를 사용하세요.
### [버그 바운티 모드]
* BB 모드에서는 celerystalk로 발견되거나 수동으로 가져온 모든 서브도메인이 범위 내로 표시됩니다.
#### 서브도메인 찾기, 범위 외 호스트 정의, 나머지 모두 스캔```
# ./celerystalk workspace create -o /dir -m bb # Create default workspace and set output dir
# ./celerystalk subdomains -d company.com,dom.net # Find subdomains and determine if in scope
# ./celerystalk import -S scope.txt (optional) # Import IP/CIDR/Ranges and mark as in scope
# ./celerystalk import -O out_scope.txt (optional) # Define HOSTS/IPs that are out of scope
# ./celerystalk nmap (optional) # Nmap all in-scope hosts (reads options from config.ini)
# ./celerystalk import -f client.xml (optional) # If you would rather import an nmap file you already ran
# ./celerystalk scan [--noIP] # Run all enabled commands against all in scope hosts
# ./celerystalk query watch (then Ctrl+c) # Wait for scans to finish
# ./celerystalk screenshots # Take screenshots
# ./celerystalk report # Generate report
참고: 하위 도메인 명령을 먼저 실행한 후 범위를 정의하거나, 범위를 정의한 후 하위 도메인을 가져올 수 있습니다.
**참고:** 서브도메인 명령을 먼저 실행한 후 범위를 정의하거나, 범위를 정의한 후 서브도메인을 가져올 수 있습니다.
#### 범위 내에 있고 celerystalk가 nmap을 실행하고 결과를 파싱하도록 하는 호스트 목록 가져오기```
# ./celerystalk workspace create -o /dir -m vapt # Create default workspace and set output dir
# ./celerystalk import -S client-inscope-list.txt # Import IP/CIDR/Ranges and mark as in scope
# ./celerystalk import -O out_scope.txt (optional) # Define HOSTS/IPs that are out of scope
# ./celerystalk nmap # Nmap all in-scope hosts (reads options from config.ini)
# ./celerystalk query watch (then Ctrl+c) # Watch nmap scans as they move from pending > running > complete
# ./celerystalk subdomains -d client.com,client.net # Find subdomains and determine if in scope
# ./celerystalk scan # Run all enabled commands
# ./celerystalk query watch (then Ctrl+c) # Watch scans as they move from pending > running > complete
# ./celerystalk screenshots # Take screenshots
# ./celerystalk report # Generate report
참고: 서브도메인 명령을 먼저 실행한 후 범위를 정의하거나, 범위를 정의한 후 서브도메인을 가져올 수 있습니다.
자세한 내용은 Wiki의 Configuration 페이지를 참조하세요.
다른 작업을 수행하기 전에 워크스페이스를 생성해야 합니다.
| 옵션 | 설명 |
|---|---|
| 옵션 없음 | 현재 워크스페이스 출력 |
| create | 새 워크스페이스 생성 |
| -w | 새 워크스페이스 이름 정의 |
| -o | 워크스페이스에 할당된 출력 디렉터리 정의 |
| -m | 모드 [vapt \ bb] |
| Create default workspace ./celerystalk workspace create -o /assessments/client -m bb | |
| Create named workspace ./celerystalk workspace create -o /assessments/client -w client -m vapt | |
| Switch to another workspace ./celerystalk workspace client |
#### import
이 명령은 포트와 호스트 데이터를 celerystalk으로 가져오고, 범위 내와 범위 밖을 정의할 수 있게 합니다.