strixoc penetration test flow

Scope declaration to signed findings, via recon + exploit agents under Pydantic validation

strixoc penetration test flow Scope declaration to signed findings, via recon + exploit agents under Pydantic validation declare scope · CLI targets + rules / 声明范围 · 规则与目标 scope acknowledged · recon started / 范围已确认 · 侦察启动 routes · params · auth · deps mapped / 路由 · 参数 · 鉴权 · 依赖 已盘点 dynamic exploit within safety rails / 安全边界内动态利用 raw finding + evidence payload / 原始发现 + 证据载荷 Pydantic validates · structured record returned / Pydantic 校验 · 结构化结果回传 aggregate + dedupe + emit report / 聚合 · 去重 · 生成报告 deliver to CI · ticket · compliance / 下发 CI · 工单 · 合规 Operator / 操作员 · CLI · scope · 范围声明 · Sequence participant Operator / 操作员 CLI · scope · 范围声明 Recon agent / 侦察代理 · attack surface · 攻击面 · Sequence participant Recon agent / 侦察代理 attack surface · 攻击面 Exploit agent / 利用代理 · dynamic · safety rails · 动态受控 · Sequence participant Exploit agent / 利用代理 dynamic · safety rails · 动态受控 Validator / 校验器 · Pydantic 2.11 · structured · Sequence participant Validator / 校验器 Pydantic 2.11 · structured Reports / 报告目标 · CI · ticket · compliance · Sequence participant Reports / 报告目标 CI · ticket · compliance Legend request return security

Ingest · 接入

  • • Operator declares scope via CLI · targets, rules, allowlist
  • • 操作员通过 CLI 声明测试目标、规则与允许名单
  • • Recon agent reads scope and starts mapping the target
  • • 侦察代理读取范围并开始绘制目标拓扑

Analyze · 分析

  • • Attack surface: routes, params, auth flows, dependencies
  • • 攻击面包含路由、参数、鉴权流程与依赖组件
  • • Exploit agent runs dynamic tests inside the safety rails
  • • 利用代理在安全边界内执行动态真实利用

Act · 处置

  • • Pydantic validates every finding before logging
  • • Pydantic 对每条发现做结构化校验后再入库
  • • Findings pipeline aggregates + dedupes; report ships to CI, ticket, compliance
  • • 聚合管线去重后生成报告,下发 CI、工单与合规系统