-
-
Notifications
You must be signed in to change notification settings - Fork 670
BBOT 3.0 - blazed_elijah #2007
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
TheTechromancer
wants to merge
179
commits into
dev
Choose a base branch
from
3.0
base: dev
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
BBOT 3.0 - blazed_elijah #2007
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Codecov ReportAttention: Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## dev #2007 +/- ##
======================================
- Coverage 93% 93% -0%
======================================
Files 397 411 +14
Lines 32897 33357 +460
======================================
+ Hits 30429 30847 +418
- Misses 2468 2510 +42 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
New Module: MongoDB Output
New Module: Elastic Output
…ements BBOT server improvements
…ements BBOT server improvements
…ements Pydantic updates
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
BBOT 3.0 "
blazed_elijah
" contains changes needed to store BBOT data in a persistent database. The idea is to release it alongside BBOT server, a tiny CLI-only database. This will be paired with a series of blog posts showing how BBOT server can be used on the command line to script out bug bounty hunting, threat intel, and ASM (i.e. running scheduled scans, exporting to CSV, diffing results over time, etc.).Together, BBOT 3.0 and BBOT server will give us a solid foundation to build a bunch of other useful tooling, like asset inventory. Sometime in the future, it may also be useful to frontend.
Breaking changes
1.
.data
and.data_json
event fieldsThe main breaking change in BBOT 3.0 is that the name of the
.data
field is different based on whether it's astr
ordict
..data
: string.data_json
: dictionaryThe
siem_friendly
option has been removed, since BBOT data is now SIEM-friendly by default.2. Generic names for findings + vulnerabilities
A
name
field has been added to findings and vulns, which holds a generic description common to all vulns of the same type. This makes it easier to collapse and categorize them.Features
Potential changes