Title: Configure Hooks to run per scan · Issue #728 · secureCodeBox/secureCodeBox · GitHub
Open Graph Title: Configure Hooks to run per scan · Issue #728 · secureCodeBox/secureCodeBox
X Title: Configure Hooks to run per scan · Issue #728 · secureCodeBox/secureCodeBox
Description: ➹ New Feature implementation request It would be extremely helpful if you can decide on a per-scan basis which hooks to run. Example use case Installed hooks: Cascading Scans, DefectDojo persistence provider Started scan: apiVersion: "ex...
Open Graph Description: ➹ New Feature implementation request It would be extremely helpful if you can decide on a per-scan basis which hooks to run. Example use case Installed hooks: Cascading Scans, DefectDojo persistenc...
X Description: ➹ New Feature implementation request It would be extremely helpful if you can decide on a per-scan basis which hooks to run. Example use case Installed hooks: Cascading Scans, DefectDojo persistenc...
Opengraph URL: https://github.com/secureCodeBox/secureCodeBox/issues/728
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Configure Hooks to run per scan","articleBody":"## ➹ New Feature implementation request\r\n\r\nIt would be extremely helpful if you can decide on a per-scan basis which hooks to run.\r\n\r\n### Example use case\r\n\r\nInstalled hooks: Cascading Scans, DefectDojo persistence provider\r\n\r\nStarted scan:\r\n\r\n```yaml\r\napiVersion: \"execution.securecodebox.io/v1\"\r\nkind: Scan\r\nmetadata:\r\n name: \"nmap-open-ports\"\r\nspec:\r\n scanType: \"nmap\"\r\n parameters:\r\n - \"-p-\"\r\n # Against Host\r\n - \"example.com\"\r\n```\r\n\r\nThe initial scan would create this finding:\r\n\r\n```json\r\n {\r\n \"name\":\"Open Port: 443 (http)\",\r\n \"category\":\"Open Port\",\r\n \"attributes\":{\r\n \"port\":443,\r\n \"state\":\"open\",\r\n \"service\":\"http\",\r\n \"serviceProduct\":\"nginx\",\r\n \"serviceVersion\":null,\r\n \"tunnel\":\"ssl\"\r\n },\r\n },\r\n```\r\n\r\nCascading Rule:\r\n\r\n```yaml\r\napiVersion: \"cascading.securecodebox.io/v1\"\r\nkind: CascadingRule\r\nmetadata:\r\n name: \"nmap-service-detection\"\r\nspec:\r\n matches:\r\n anyOf:\r\n - category: \"Open Port\"\r\n attributes:\r\n state: open\r\n scanSpec:\r\n scanType: \"nmap\"\r\n parameters:\r\n - \"-p{{attributes.port}}\"\r\n - \"-sV\"\r\n - \"--service-all\"\r\n # Against Host\r\n - \"{{$.hostOrIP}}\"\r\n```\r\n\r\nWhen triggered, the Cascading Scan would create the following finding with **more service information**:\r\n\r\n```json\r\n {\r\n \"name\":\"Open Port: 443 (http)\",\r\n \"category\":\"Open Port\",\r\n \"attributes\":{\r\n \"port\":443,\r\n \"state\":\"open\",\r\n \"service\":\"http\",\r\n \"serviceProduct\":\"nginx\",\r\n \"serviceVersion\":\"1.20.1\",\r\n \"tunnel\":\"ssl\"\r\n },\r\n },\r\n```\r\n\r\nIn this case, I would like to **not import** the initial scan results into DefectDojo but still run the Cascading Scan hook.\r\n\r\n### Describe the solution you'd like\r\nOnce #695 is merged, we could use Hook Priorities to solve this problem. One could deploy Cascading Scans with a priority of `1` and DefectDojo with `0`. Then on a per-scan basis one may define what hook ranges to execute.\r\n\r\n```yaml\r\napiVersion: \"execution.securecodebox.io/v1\"\r\nkind: Scan\r\nmetadata:\r\n name: \"nmap-open-ports\"\r\nspec:\r\n hookRanges:\r\n - \"1\"\r\n scanType: \"nmap\"\r\n parameters:\r\n - \"-p-\"\r\n # Against Host\r\n - \"example.com\"\r\n```\r\n\r\n`hookRanges` would be a list of ranges to execute. A range could have the following formats:\r\n\r\n* `0-1`: Execute hooks with priority between `0` and `1` (inclusive)\r\n* `0`: Execute hooks with priority `0`.\r\n\r\nThe `orderedHookStatusses` status field would still include the skipped hooks but marks them with state `Skipped`.\r\n\r\n### Describe alternatives you've considered\r\nProposed workarounds involved setting up multiple namespaces with different hooks installed and then running the scan in that namespace.\r\n","author":{"url":"https://github.com/EndPositive","@type":"Person","name":"EndPositive"},"datePublished":"2021-10-14T08:58:11.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":4},"url":"https://github.com/728/secureCodeBox/issues/728"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:d8674e45-f289-4523-d32d-6b3a31d85a86 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | B87E:125C99:B4D0BB:E454B9:6991810F |
| html-safe-nonce | 7f0a38f980e93c2c4d904b4bfa1f8031c77dc3471305ecf610e497ecf5d597c4 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCODdFOjEyNUM5OTpCNEQwQkI6RTQ1NEI5OjY5OTE4MTBGIiwidmlzaXRvcl9pZCI6IjY1MTQxOTMzMzY0NTQxODUyMzEiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | ce385fe48b2f2882232aff67aa37d82780c69ed1929d296d2d1b5f6bf40982e8 |
| hovercard-subject-tag | issue:1026141203 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/secureCodeBox/secureCodeBox/728/issue_layout |
| twitter:image | https://opengraph.githubassets.com/862aa6f361f503ac159b356c2b783581359f1236e9ec91117c873058145bb8c7/secureCodeBox/secureCodeBox/issues/728 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/862aa6f361f503ac159b356c2b783581359f1236e9ec91117c873058145bb8c7/secureCodeBox/secureCodeBox/issues/728 |
| og:image:alt | ➹ New Feature implementation request It would be extremely helpful if you can decide on a per-scan basis which hooks to run. Example use case Installed hooks: Cascading Scans, DefectDojo persistenc... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | EndPositive |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-preview |
| go-import | github.com/secureCodeBox/secureCodeBox git https://github.com/secureCodeBox/secureCodeBox.git |
| octolytics-dimension-user_id | 34573705 |
| octolytics-dimension-user_login | secureCodeBox |
| octolytics-dimension-repository_id | 80711933 |
| octolytics-dimension-repository_nwo | secureCodeBox/secureCodeBox |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 80711933 |
| octolytics-dimension-repository_network_root_nwo | secureCodeBox/secureCodeBox |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 848bc6032dcc93a9a7301dcc3f379a72ba13b96e |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width