Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Improve cascading scans docs by rewording and including a overview di…
…agram

Put the diagram onto the website static directory and used a absolute link to it to ensure that it works whereever this is displayed.
It might be opened on either github, our website, artifacthub or dockerhub so the image can't be included using a relative link as we can only get the readme set there.

Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
  • Loading branch information
J12934 committed Jan 10, 2025
commit 000a07c5414fa2fe8341d26489ccf58b1446c856
4 changes: 4 additions & 0 deletions documentation/static/img/cascades.drawio.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
11 changes: 9 additions & 2 deletions hooks/cascading-scans/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,15 @@ usecase: "Cascading Scans based declarative Rules."

{{- define "extra.chartAboutSection" -}}
## What is "Cascading Scans" Hook about?
The Cascading Scans Hook can be used to orchestrate security scanners based on defined rule sets.
The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`. When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan. To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

The Cascading Scans Hook can be used to start additional scans based on the results of other scans.
This allows you to create powerful setups to automatically discover targets, and then trigger more specialized scans for the type of target that was discovered.

![Diagram of CascadingScans showing one amass scans for example.com finding two subdomains. These then trigger a port scan each. An identified ssh port then gets a SSH Scan and a Ncrack scan triggered. A https port gets a sslyze and a nuclei scan triggered.](https://www.securecodebox.io/static/img/cascades.drawio.svg)

The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`.
When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan.
To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

This Hook is based on the ADR https://www.securecodebox.io/docs/architecture/architecture_decisions/adr_0003/

Expand Down
11 changes: 9 additions & 2 deletions hooks/cascading-scans/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,15 @@ Otherwise your changes will be reverted/overwritten automatically due to the bui
</p>

## What is "Cascading Scans" Hook about?
The Cascading Scans Hook can be used to orchestrate security scanners based on defined rule sets.
The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`. When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan. To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

The Cascading Scans Hook can be used to start additional scans based on the results of other scans.
This allows you to create powerful setups to automatically discover targets, and then trigger more specialized scans for the type of target that was discovered.

![Diagram of CascadingScans showing one amass scans for example.com finding two subdomains. These then trigger a port scan each. An identified ssh port then gets a SSH Scan and a Ncrack scan triggered. A https port gets a sslyze and a nuclei scan triggered.](https://www.securecodebox.io/static/img/cascades.drawio.svg)

The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`.
When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan.
To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

This Hook is based on the ADR https://www.securecodebox.io/docs/architecture/architecture_decisions/adr_0003/

Expand Down
11 changes: 9 additions & 2 deletions hooks/cascading-scans/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,15 @@ The secureCodeBox project is running on [Kubernetes](https://kubernetes.io/). To
You can find resources to help you get started on our [documentation website](https://www.securecodebox.io) including instruction on how to [install the secureCodeBox project](https://www.securecodebox.io/docs/getting-started/installation) and guides to help you [run your first scans](https://www.securecodebox.io/docs/getting-started/first-scans) with it.

## What is "Cascading Scans" Hook about?
The Cascading Scans Hook can be used to orchestrate security scanners based on defined rule sets.
The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`. When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan. To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

The Cascading Scans Hook can be used to start additional scans based on the results of other scans.
This allows you to create powerful setups to automatically discover targets, and then trigger more specialized scans for the type of target that was discovered.

![Diagram of CascadingScans showing one amass scans for example.com finding two subdomains. These then trigger a port scan each. An identified ssh port then gets a SSH Scan and a Ncrack scan triggered. A https port gets a sslyze and a nuclei scan triggered.](https://www.securecodebox.io/static/img/cascades.drawio.svg)

The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`.
When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan.
To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

This Hook is based on the ADR https://www.securecodebox.io/docs/architecture/architecture_decisions/adr_0003/

Expand Down
11 changes: 9 additions & 2 deletions hooks/cascading-scans/docs/README.DockerHub-Hook.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,15 @@ docker pull securecodebox/hook-cascading-scans
```

## What is "Cascading Scans" Hook about?
The Cascading Scans Hook can be used to orchestrate security scanners based on defined rule sets.
The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`. When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan. To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

The Cascading Scans Hook can be used to start additional scans based on the results of other scans.
This allows you to create powerful setups to automatically discover targets, and then trigger more specialized scans for the type of target that was discovered.

![Diagram of CascadingScans showing one amass scans for example.com finding two subdomains. These then trigger a port scan each. An identified ssh port then gets a SSH Scan and a Ncrack scan triggered. A https port gets a sslyze and a nuclei scan triggered.](https://www.securecodebox.io/static/img/cascades.drawio.svg)

The so called `CascadingRules` consist of a `matches` section which contains one or multiple rules which are compared against `findings`.
When a `finding` matches a `rule` the `scanSpec` section will then be used to create a new scan.
To customize the scan to match the finding, the [mustache](https://github.com/janl/mustache.js) templating language can be used to reference fields of the finding.

This Hook is based on the ADR https://www.securecodebox.io/docs/architecture/architecture_decisions/adr_0003/

Expand Down