Git Product home page Git Product logo

qrxnz / artemis Goto Github PK

View Code? Open in Web Editor NEW

This project forked from cert-polska/artemis

0.0 0.0 0.0 3.46 MB

A modular vulnerability scanner with automatic report generation capabilities.

Home Page: https://cert.pl/en/posts/2024/01/artemis-security-scanner/

License: BSD 3-Clause "New" or "Revised" License

Shell 1.89% Python 89.06% PHP 0.25% CSS 0.01% Hack 0.18% HTML 0.04% Mako 0.06% Dockerfile 0.27% Jinja 8.25%

artemis's Introduction

logo

Artemis is a modular vulnerability scanner. It's the tool that powers CERT PL scanning activities by checking various aspects of website security and building easy-to-read messages ready to be sent to the scanned organizations.

Note

We run free on-line training sessions on how to setup and use Artemis. If you are a national or governmental CSIRT, you can sign up here.

If you want to use additional modules that weren't included here due to non-BSD-compatible licenses, browse to the Artemis-modules-extra repository.

If you want to modify/develop Artemis, read Development first.

Artemis is experimental software, under active development - use at your own risk.

To chat about Artemis, join the Discord server:

Features

For an up-to-date list of features, please refer to the documentation. The most important one is the possibility to easily export reports such as:

The following addresses contain version control system data:

Making a code repository public may allow an attacker to learn the inner workings of a system, and if it contains passwords or API keys - also gain unauthorized access. Such data shouldn't be publicly available.

The following addresses contain old Joomla versions:

If a site is no longer used, we recommend shutting it down to eliminate the risk of exploitation of known vulnerabilities in older Joomla versions. Otherwise, we recommend regular Joomla core and plugin updates.

The possibility to automatically prepare such reports enabled us to notify entities in our constituency about hundreds of thousands of vulnerabilities.

Screenshots

Artemis - scan

Development

To start a locally modified version of Artemis, run:

 ./scripts/start_dev

This script automatically copies the example environment file (env.example) to .env if it doesn't exist. You can then configure the settings in the .env file according to your needs. This includes customizing the user-agent by setting the CUSTOM_USER_AGENT variable, as well as other relevant parameters. For a complete list of configuration variables and their descriptions, please refer to the Configuration section in the documentation.

The Artemis image is then built locally (from the code you are developing) not downloaded from Docker Hub. For web, you will also be able to see the results of code modifications on the page without reloading the entire container.

Tests

To run the tests, use:

./scripts/test

Code formatting

Artemis uses pre-commit to run linters and format the code. pre-commit is executed on CI to verify that the code is formatted properly.

To run it locally, use:

pre-commit run --all-files

To set up pre-commit so that it runs before each commit, use:

pre-commit install

Building the docs

To build the documentation, use:

cd docs
python3 -m venv venv
. venv/bin/activate
pip install -r requirements.txt
make html

How do I write my own module?

Please refer to the documentation.

Contributing

Contributions are welcome! We will appreciate both ideas for new Artemis modules (added as GitHub issues) as well as pull requests with new modules or code improvements.

However obvious it may seem we kindly remind you that by contributing to Artemis you agree that the BSD 3-Clause License shall apply to your input automatically, without the need for any additional declarations to be made.

Contributors

Huge thanks to the following people that contributed to Artemis development, especially the KN Cyber science club of Warsaw University of Technology that initiated the project!

kazet
kazet

πŸ’» πŸ“– πŸ€” πŸš‡ πŸ‘€ πŸ“’
Adam KliΕ›
Adam KliΕ›

πŸ’¬ πŸ’» πŸ€” πŸ‘€ πŸ“’
anna1492
anna1492

πŸ› πŸ’»
MichaΕ‚ M.
MichaΕ‚ M.

πŸ’» πŸ€”
cyberamt
cyberamt

πŸ’» πŸ€”
martclau
martclau

πŸ’» πŸ€”
szymsid
szymsid

πŸ’» πŸ‘€
bulek
bulek

πŸ’» πŸ‘€
Michel Le Bihan
Michel Le Bihan

πŸ’»
Grzegorz Eliszewski
Grzegorz Eliszewski

πŸ’» πŸ€” πŸ“¦
kshitij kapoor
kshitij kapoor

πŸ’» πŸ€”
Delfin
Delfin

πŸ’»
Bornunique911
Bornunique911

πŸ’»
Ridham Bhagat
Ridham Bhagat

πŸ’»
Mateusz Borkowski
Mateusz Borkowski

πŸ’» πŸ€”
jxdv
jxdv

πŸ’»
kvothe
kvothe

πŸ’» πŸ€”

artemis's People

Contributors

kazet avatar dependabot[bot] avatar bonusplay avatar matie26 avatar kshitijk4poor avatar anna1492 avatar michalkrzem avatar eloole avatar es1o avatar jxdv avatar bornunique911 avatar delfinsr avatar rasenrhino avatar cyberamt avatar martclau avatar szymsid avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.