Skip to content

Commit 88a6d80

Browse files
committed
refactor: modularize workflow execution and implement phase completion tracking in database
1 parent c999921 commit 88a6d80

44 files changed

Lines changed: 1012 additions & 5129 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

cmd/autoar/main.go

Lines changed: 2 additions & 3810 deletions
Large diffs are not rendered by default.

go.mod

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@ require (
2020
github.com/hashicorp/go-retryablehttp v0.7.5
2121
github.com/jackc/pgx/v5 v5.7.6
2222
github.com/joeguo/tldextract v0.0.0-20220507100122-d83daa6adef8
23+
github.com/joho/godotenv v1.5.1
2324
github.com/juju/persistent-cookiejar v1.0.0
2425
github.com/majd/ipatool/v2 v2.2.0
2526
github.com/projectdiscovery/dnsx v1.2.2
@@ -30,6 +31,7 @@ require (
3031
github.com/projectdiscovery/tlsx v1.2.2
3132
github.com/sa7mon/s3scanner v0.0.0-20251106040855-9e26bc46e8ee
3233
github.com/sirupsen/logrus v1.9.3
34+
github.com/spf13/cobra v1.10.2
3335
github.com/sw33tLie/bbscope v0.0.0-20251113222800-c453973e83dd
3436
golang.org/x/net v0.47.0
3537
golang.org/x/time v0.14.0
@@ -150,11 +152,11 @@ require (
150152
github.com/hbakhtiyor/strsim v0.0.0-20190107154042-4d2bbb273edf // indirect
151153
github.com/hdm/jarm-go v0.0.7 // indirect
152154
github.com/iangcarroll/cookiemonster v1.6.0 // indirect
155+
github.com/inconshreveable/mousetrap v1.1.0 // indirect
153156
github.com/jackc/pgpassfile v1.0.0 // indirect
154157
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
155158
github.com/jackc/puddle/v2 v2.2.2 // indirect
156159
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
157-
github.com/joho/godotenv v1.5.1 // indirect
158160
github.com/json-iterator/go v1.1.12 // indirect
159161
github.com/juju/go4 v0.0.0-20160222163258-40d72ab9641a // indirect
160162
github.com/kataras/jwt v0.1.10 // indirect

go.sum

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -227,6 +227,7 @@ github.com/corona10/goimagehash v1.1.0/go.mod h1:VkvE0mLn84L4aF8vCb6mafVajEb6QYM
227227
github.com/corpix/uarand v0.2.0 h1:U98xXwud/AVuCpkpgfPF7J5TQgr7R5tqT8VZP5KWbzE=
228228
github.com/corpix/uarand v0.2.0/go.mod h1:/3Z1QIqWkDIhf6XWn/08/uMHoQ8JUoTIKc2iPchBOmM=
229229
github.com/cpuguy83/go-md2man/v2 v2.0.0/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
230+
github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g=
230231
github.com/creack/pty v1.1.7/go.mod h1:lj5s0c3V2DBrqTV7llrYr5NG6My20zk30Fl46Y7DoTY=
231232
github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E=
232233
github.com/creack/pty v1.1.13/go.mod h1:MOBLtS5ELjhRRrroQr9kyvTxUAFNvYEK993ew/Vr4O4=
@@ -507,6 +508,8 @@ github.com/ianlancetaylor/demangle v0.0.0-20200824232613-28f6c0f3b639/go.mod h1:
507508
github.com/imdario/mergo v0.3.9 h1:UauaLniWCFHWd+Jp9oCEkTBj8VO/9DKg3PV3VCNMDIg=
508509
github.com/imdario/mergo v0.3.9/go.mod h1:2EnlNZ0deacrJVfApfmtdGgDfMuh/nq6Ok1EcJh5FfA=
509510
github.com/inconshreveable/mousetrap v1.0.0/go.mod h1:PxqpIevigyE2G7u3NXJIT2ANytuPF1OarO4DADm73n8=
511+
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
512+
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
510513
github.com/jackc/pgpassfile v1.0.0 h1:/6Hmqy13Ss2zCq62VdNG8tM1wchn8zjSGOBJ6icpsIM=
511514
github.com/jackc/pgpassfile v1.0.0/go.mod h1:CEx0iS5ambNFdcRtxPj5JhEz+xB6uRky5eyVu/W2HEg=
512515
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 h1:iCEnooe7UlwOQYpKFhBabPMi4aNAfoODPEFNiAnClxo=
@@ -790,6 +793,7 @@ github.com/rs/xid v1.6.0/go.mod h1:7XoLgs4eV+QndskICGsho+ADou8ySMSjJKDIan90Nz0=
790793
github.com/rs/zerolog v1.28.0 h1:MirSo27VyNi7RJYP3078AA1+Cyzd2GB66qy3aUHvsWY=
791794
github.com/rs/zerolog v1.28.0/go.mod h1:NILgTygv/Uej1ra5XxGf82ZFSLk58MFGAUS2o6usyD0=
792795
github.com/russross/blackfriday/v2 v2.0.1/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
796+
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
793797
github.com/rwcarlsen/goexif v0.0.0-20190401172101-9e8deecbddbd/go.mod h1:hPqNNc0+uJM6H+SuU8sEs5K5IQeKccPqeSjfgcKGgPk=
794798
github.com/ryanuber/columnize v0.0.0-20160712163229-9b3edd62028f/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
795799
github.com/sa7mon/s3scanner v0.0.0-20251106040855-9e26bc46e8ee h1:kwVuHvu+GCXGpuVwiE5MFI3rVRQibg90YF2BiB+lZmg=
@@ -840,10 +844,13 @@ github.com/spf13/cast v1.10.0 h1:h2x0u2shc1QuLHfxi+cTJvs30+ZAHOGRic8uyGTDWxY=
840844
github.com/spf13/cast v1.10.0/go.mod h1:jNfB8QC9IA6ZuY2ZjDp0KtFO2LZZlg4S/7bzP6qqeHo=
841845
github.com/spf13/cobra v1.1.1/go.mod h1:WnodtKOvamDL/PwE2M4iKs8aMDBZ5Q5klgD3qfVJQMI=
842846
github.com/spf13/cobra v1.2.1/go.mod h1:ExllRjgxM/piMAM+3tAZvg8fsklGAf3tPfi+i8t68Nk=
847+
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
848+
github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4=
843849
github.com/spf13/jwalterweatherman v1.0.0/go.mod h1:cQK4TGJAtQXfYWX+Ddv3mKDzgVb68N+wFjFa4jdeBTo=
844850
github.com/spf13/jwalterweatherman v1.1.0/go.mod h1:aNWZUN0dPAAO/Ljvb5BEdw96iTZ0EXowPYD95IqWIGo=
845851
github.com/spf13/pflag v1.0.3/go.mod h1:DYY7MBk1bdzusC3SYhjObp+wFpr4gzcvqqNjLnInEg4=
846852
github.com/spf13/pflag v1.0.5/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
853+
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
847854
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
848855
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
849856
github.com/spf13/viper v1.7.0/go.mod h1:8WkrPz2fc9jxqZNCJI/76HCieCp4Q8HaLFoCha5qpdg=

internal/cmd/domain.go

Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
package cmd
2+
3+
import (
4+
"fmt"
5+
"os"
6+
7+
"github.com/spf13/cobra"
8+
"github.com/h0tak88r/AutoAR/internal/modules/domain"
9+
"github.com/h0tak88r/AutoAR/internal/modules/db"
10+
)
11+
12+
var domainCmd = &cobra.Command{
13+
Use: "domain",
14+
Short: "Domain-related operations",
15+
}
16+
17+
var domainRunCmd = &cobra.Command{
18+
Use: "run",
19+
Short: "Run a full scan on a domain",
20+
RunE: func(cmd *cobra.Command, args []string) error {
21+
domainName, _ := cmd.Flags().GetString("domain")
22+
skipFFuf, _ := cmd.Flags().GetBool("skip-ffuf")
23+
24+
if domainName == "" {
25+
return fmt.Errorf("domain (-d) is required")
26+
}
27+
28+
// Handle scan ID and DB integration (logic ported from main.go)
29+
scanID := os.Getenv("AUTOAR_CURRENT_SCAN_ID")
30+
if scanID == "" {
31+
scanID = fmt.Sprintf("domain_run-%d", os.Getpid())
32+
_ = db.Init()
33+
_ = db.InitSchema()
34+
_ = db.CreateScan(&db.ScanRecord{
35+
ScanID: scanID,
36+
ScanType: "domain_run",
37+
Target: domainName,
38+
Status: "running",
39+
})
40+
os.Setenv("AUTOAR_CURRENT_SCAN_ID", scanID)
41+
defer func() {
42+
_ = db.UpdateScanStatus(scanID, "completed")
43+
os.Unsetenv("AUTOAR_CURRENT_SCAN_ID")
44+
}()
45+
}
46+
47+
_, err := domain.RunDomain(domain.ScanOptions{
48+
Domain: domainName,
49+
SkipFFuf: skipFFuf,
50+
})
51+
52+
if err != nil {
53+
_ = db.UpdateScanStatus(scanID, "failed")
54+
}
55+
return err
56+
},
57+
}
58+
59+
func init() {
60+
rootCmd.AddCommand(domainCmd)
61+
domainCmd.AddCommand(domainRunCmd)
62+
63+
domainRunCmd.Flags().StringP("domain", "d", "", "Target domain to scan")
64+
domainRunCmd.Flags().Bool("skip-ffuf", false, "Skip FFuf fuzzing phase")
65+
domainRunCmd.MarkFlagRequired("domain")
66+
}

internal/cmd/lite.go

Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
package cmd
2+
3+
import (
4+
"fmt"
5+
"os"
6+
7+
"github.com/spf13/cobra"
8+
"github.com/h0tak88r/AutoAR/internal/modules/lite"
9+
"github.com/h0tak88r/AutoAR/internal/modules/db"
10+
)
11+
12+
var liteCmd = &cobra.Command{
13+
Use: "lite",
14+
Short: "Lite-related operations",
15+
}
16+
17+
var liteRunCmd = &cobra.Command{
18+
Use: "run",
19+
Short: "Run a lighter workflow on a domain",
20+
RunE: func(cmd *cobra.Command, args []string) error {
21+
domainName, _ := cmd.Flags().GetString("domain")
22+
skipJS, _ := cmd.Flags().GetBool("skip-js")
23+
24+
if domainName == "" {
25+
return fmt.Errorf("domain (-d) is required")
26+
}
27+
28+
scanID := os.Getenv("AUTOAR_CURRENT_SCAN_ID")
29+
if scanID == "" {
30+
scanID = fmt.Sprintf("lite-%d", os.Getpid())
31+
_ = db.Init()
32+
_ = db.InitSchema()
33+
_ = db.CreateScan(&db.ScanRecord{
34+
ScanID: scanID,
35+
ScanType: "lite",
36+
Target: domainName,
37+
Status: "running",
38+
})
39+
os.Setenv("AUTOAR_CURRENT_SCAN_ID", scanID)
40+
defer func() {
41+
_ = db.UpdateScanStatus(scanID, "completed")
42+
os.Unsetenv("AUTOAR_CURRENT_SCAN_ID")
43+
}()
44+
}
45+
46+
opts := lite.Options{
47+
Domain: domainName,
48+
SkipJS: skipJS,
49+
}
50+
51+
_, err := lite.RunLite(opts)
52+
if err != nil {
53+
_ = db.UpdateScanStatus(scanID, "failed")
54+
}
55+
return err
56+
},
57+
}
58+
59+
func init() {
60+
rootCmd.AddCommand(liteCmd)
61+
liteCmd.AddCommand(liteRunCmd)
62+
63+
liteRunCmd.Flags().StringP("domain", "d", "", "Target domain to scan")
64+
liteRunCmd.Flags().Bool("skip-js", false, "Skip JavaScript analysis phase")
65+
liteRunCmd.MarkFlagRequired("domain")
66+
}

internal/cmd/misc.go

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
package cmd
2+
3+
import (
4+
"github.com/spf13/cobra"
5+
"github.com/h0tak88r/AutoAR/internal/modules/backup"
6+
"github.com/h0tak88r/AutoAR/internal/modules/s3"
7+
"github.com/h0tak88r/AutoAR/internal/modules/jwt"
8+
"github.com/h0tak88r/AutoAR/internal/modules/zerodays"
9+
)
10+
11+
var (
12+
backupCmd = &cobra.Command{
13+
Use: "backup",
14+
Short: "Scan for backup files",
15+
RunE: func(cmd *cobra.Command, args []string) error {
16+
domain, _ := cmd.Flags().GetString("domain")
17+
_, err := backup.Run(backup.Options{Domain: domain, Method: "all", Threads: 50})
18+
return err
19+
},
20+
}
21+
22+
s3Cmd = &cobra.Command{
23+
Use: "s3",
24+
Short: "S3 bucket enumeration and scanning",
25+
}
26+
27+
s3ScanCmd = &cobra.Command{
28+
Use: "scan",
29+
Short: "Scan a specific bucket",
30+
RunE: func(cmd *cobra.Command, args []string) error {
31+
bucket, _ := cmd.Flags().GetString("bucket")
32+
return s3.Run(s3.Options{Action: "scan", Bucket: bucket})
33+
},
34+
}
35+
36+
jwtCmd = &cobra.Command{
37+
Use: "jwt",
38+
Short: "JWT token security analysis",
39+
RunE: func(cmd *cobra.Command, args []string) error {
40+
token, _ := cmd.Flags().GetString("token")
41+
_, err := jwt.RunScan([]string{token})
42+
return err
43+
},
44+
}
45+
46+
zerodaysCmd = &cobra.Command{
47+
Use: "zerodays",
48+
Short: "Scan for recent Zero-Day vulnerabilities",
49+
RunE: func(cmd *cobra.Command, args []string) error {
50+
domain, _ := cmd.Flags().GetString("domain")
51+
_, err := zerodays.Run(zerodays.Options{Domain: domain})
52+
return err
53+
},
54+
}
55+
)
56+
57+
func init() {
58+
rootCmd.AddCommand(backupCmd)
59+
rootCmd.AddCommand(s3Cmd)
60+
s3Cmd.AddCommand(s3ScanCmd)
61+
rootCmd.AddCommand(jwtCmd)
62+
rootCmd.AddCommand(zerodaysCmd)
63+
64+
backupCmd.Flags().StringP("domain", "d", "", "Target domain")
65+
s3ScanCmd.Flags().StringP("bucket", "b", "", "Bucket name")
66+
jwtCmd.Flags().StringP("token", "t", "", "JWT token")
67+
zerodaysCmd.Flags().StringP("domain", "d", "", "Target domain")
68+
}

internal/cmd/recon.go

Lines changed: 92 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,92 @@
1+
package cmd
2+
3+
import (
4+
"github.com/spf13/cobra"
5+
"github.com/h0tak88r/AutoAR/internal/modules/subdomains"
6+
"github.com/h0tak88r/AutoAR/internal/modules/livehosts"
7+
"github.com/h0tak88r/AutoAR/internal/modules/cnames"
8+
"github.com/h0tak88r/AutoAR/internal/modules/tech"
9+
"github.com/h0tak88r/AutoAR/internal/modules/ports"
10+
"github.com/h0tak88r/AutoAR/internal/modules/urls"
11+
)
12+
13+
var (
14+
subdomainsCmd = &cobra.Command{
15+
Use: "subdomains",
16+
Short: "Enumerate subdomains",
17+
RunE: func(cmd *cobra.Command, args []string) error {
18+
domain, _ := cmd.Flags().GetString("domain")
19+
_, err := subdomains.EnumerateSubdomains(domain, 100)
20+
return err
21+
},
22+
}
23+
24+
livehostsCmd = &cobra.Command{
25+
Use: "livehosts",
26+
Short: "Filter live hosts",
27+
RunE: func(cmd *cobra.Command, args []string) error {
28+
domain, _ := cmd.Flags().GetString("domain")
29+
_, err := livehosts.FilterLiveHosts(domain, 100, true)
30+
return err
31+
},
32+
}
33+
34+
cnamesCmd = &cobra.Command{
35+
Use: "cnames",
36+
Short: "Collect CNAME records",
37+
RunE: func(cmd *cobra.Command, args []string) error {
38+
domain, _ := cmd.Flags().GetString("domain")
39+
_, err := cnames.CollectCNAMEs(domain)
40+
return err
41+
},
42+
}
43+
44+
techCmd = &cobra.Command{
45+
Use: "tech",
46+
Short: "Detect technologies",
47+
RunE: func(cmd *cobra.Command, args []string) error {
48+
domain, _ := cmd.Flags().GetString("domain")
49+
_, err := tech.DetectTech(domain, 100)
50+
return err
51+
},
52+
}
53+
54+
portsCmd = &cobra.Command{
55+
Use: "ports",
56+
Short: "Scan for open ports",
57+
RunE: func(cmd *cobra.Command, args []string) error {
58+
domain, _ := cmd.Flags().GetString("domain")
59+
_, err := ports.ScanPorts(domain, 100)
60+
return err
61+
},
62+
}
63+
64+
urlsCmd = &cobra.Command{
65+
Use: "urls",
66+
Short: "Collect URLs and JS files",
67+
RunE: func(cmd *cobra.Command, args []string) error {
68+
domain, _ := cmd.Flags().GetString("domain")
69+
_, err := urls.CollectURLs(domain, 100, false)
70+
return err
71+
},
72+
}
73+
)
74+
75+
func init() {
76+
reconCmd := &cobra.Command{
77+
Use: "recon",
78+
Short: "Reconnaissance operations",
79+
}
80+
rootCmd.AddCommand(reconCmd)
81+
82+
subcmds := []*cobra.Command{subdomainsCmd, livehostsCmd, cnamesCmd, techCmd, portsCmd, urlsCmd}
83+
for _, sc := range subcmds {
84+
sc.Flags().StringP("domain", "d", "", "Target domain")
85+
sc.MarkFlagRequired("domain")
86+
reconCmd.AddCommand(sc)
87+
}
88+
89+
// Also support the original flat structure for compatibility
90+
// (e.g., autoar subdomains get -d domain)
91+
// For now let's just use the 'recon' grouping for new modularity
92+
}

0 commit comments

Comments
 (0)