├── .env ├── .gitignore ├── Dockerfile ├── LICENSE ├── README.md ├── TODO.md ├── blueprints ├── access.py ├── assessment.py ├── assessment_export.py ├── assessment_import.py ├── assessment_utils.py ├── testcase.py └── testcase_utils.py ├── compose.yml ├── custom ├── knowledgebase │ └── T1003.yaml ├── reports │ └── sample.docx └── testcases.json ├── entrypoint.sh ├── flask.cfg ├── model.py ├── pops-backup.py ├── purpleops.py ├── requirements.txt ├── seeder.py ├── static ├── images │ ├── demo.gif │ ├── logo.ico │ └── logo.png ├── scripts │ ├── access.js │ ├── access.random_pass.js │ ├── assessment.js │ ├── assessment.stats.js │ ├── assessments.js │ ├── bootstrap-select.min.js │ ├── bootstrap-table-cookie.min.js │ ├── bootstrap-table-filter-control.min.js │ ├── bootstrap-table.min.js │ ├── bootstrap.bundle.min.js │ ├── jquery.min.js │ ├── popper.min.js │ └── testcase.js └── style │ ├── bootstrap-icons.css │ ├── bootstrap-select.min.css │ ├── bootstrap-table.min.css │ ├── bootstrap.min.css │ ├── bootstrap.min.css.map │ ├── bootstrappulse.min.css │ └── fonts │ └── bootstrap-icons.woff2 ├── templates ├── access.html ├── access_modals.html ├── assessment.html ├── assessment_hexagons.svg ├── assessment_modals.html ├── assessment_navigator.html ├── assessment_stats.html ├── assessments.html ├── assessments_modals.html ├── login.html ├── macros.html ├── master.html ├── master_modals.html ├── mfa_register.html ├── mfa_verify.html ├── password_change.html ├── testcase.html ├── testcase_blue.html ├── testcase_modals.html └── testcase_red.html └── utils.py /.env: -------------------------------------------------------------------------------- 1 | MONGO_DB=assessments3 2 | MONGO_HOST=mongodb 3 | MONGO_PORT=27017 4 | 5 | FLASK_DEBUG=True 6 | FLASK_MFA=False 7 | 8 | HOST=0.0.0.0 9 | PORT=8888 10 | NAME=dev 11 | -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- 1 | # Byte-compiled / optimized / DLL files 2 | __pycache__/ 3 | *.py[cod] 4 | *$py.class 5 | 6 | # C extensions 7 | *.so 8 | 9 | # Distribution / packaging 10 | .Python 11 | build/ 12 | develop-eggs/ 13 | dist/ 14 | downloads/ 15 | eggs/ 16 | .eggs/ 17 | lib/ 18 | lib64/ 19 | parts/ 20 | sdist/ 21 | var/ 22 | wheels/ 23 | pip-wheel-metadata/ 24 | share/python-wheels/ 25 | *.egg-info/ 26 | .installed.cfg 27 | *.egg 28 | MANIFEST 29 | 30 | # PyInstaller 31 | # Usually these files are written by a python script from a template 32 | # before PyInstaller builds the exe, so as to inject date/other infos into it. 33 | *.manifest 34 | *.spec 35 | 36 | # Installer logs 37 | pip-log.txt 38 | pip-delete-this-directory.txt 39 | 40 | # Unit test / coverage reports 41 | htmlcov/ 42 | .tox/ 43 | .nox/ 44 | .coverage 45 | .coverage.* 46 | .cache 47 | nosetests.xml 48 | coverage.xml 49 | *.cover 50 | *.py,cover 51 | .hypothesis/ 52 | .pytest_cache/ 53 | 54 | # Translations 55 | *.mo 56 | *.pot 57 | 58 | # Django stuff: 59 | *.log 60 | local_settings.py 61 | db.sqlite3 62 | db.sqlite3-journal 63 | 64 | # Flask stuff: 65 | instance/ 66 | .webassets-cache 67 | 68 | # Scrapy stuff: 69 | .scrapy 70 | 71 | # Sphinx documentation 72 | docs/_build/ 73 | 74 | # PyBuilder 75 | target/ 76 | 77 | # Jupyter Notebook 78 | .ipynb_checkpoints 79 | 80 | # IPython 81 | profile_default/ 82 | ipython_config.py 83 | 84 | # pyenv 85 | .python-version 86 | 87 | # pipenv 88 | # According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control. 89 | # However, in case of collaboration, if having platform-specific dependencies or dependencies 90 | # having no cross-platform support, pipenv may install dependencies that don't work, or not 91 | # install all needed dependencies. 92 | #Pipfile.lock 93 | 94 | # PEP 582; used by e.g. github.com/David-OConnor/pyflow 95 | __pypackages__/ 96 | 97 | # Celery stuff 98 | celerybeat-schedule 99 | celerybeat.pid 100 | 101 | # SageMath parsed files 102 | *.sage.py 103 | 104 | # Environments 105 | .env 106 | .venv 107 | env*/ 108 | venv/ 109 | ENV/ 110 | env.bak/ 111 | venv.bak/ 112 | 113 | # Spyder project settings 114 | .spyderproject 115 | .spyproject 116 | 117 | # Rope project settings 118 | .ropeproject 119 | 120 | # mkdocs documentation 121 | /site 122 | 123 | # mypy 124 | .mypy_cache/ 125 | .dmypy.json 126 | dmypy.json 127 | 128 | # Pyre type checker 129 | .pyre/ 130 | 131 | # Dev artifacts 132 | *.xlsx 133 | files/ 134 | 135 | supervisord.pid 136 | sampledata/sigma/* 137 | external/* 138 | INITIAL_ADMIN_PASSWORD.TXT -------------------------------------------------------------------------------- /Dockerfile: -------------------------------------------------------------------------------- 1 | # pull official base image 2 | FROM python:3.11.3-slim-buster 3 | 4 | # set work directory 5 | WORKDIR /usr/src/app 6 | 7 | # set environment variables 8 | ENV PYTHONDONTWRITEBYTECODE 1 9 | ENV PYTHONUNBUFFERED 1 10 | 11 | # install system dependencies 12 | RUN apt-get update && apt-get install -y netcat git 13 | 14 | # install dependencies 15 | RUN pip install --upgrade pip 16 | COPY ./requirements.txt /usr/src/app/requirements.txt 17 | RUN pip install -r requirements.txt 18 | 19 | # copy project 20 | COPY . /usr/src/app/ 21 | 22 | # run entrypoint.sh 23 | ENTRYPOINT ["/usr/src/app/entrypoint.sh"] -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | Copyright 2023 Willem Mouton & Harrison Mitchell 2 | 3 | Licensed under the Apache License, Version 2.0 (the "License"); 4 | you may not use this file except in compliance with the License. 5 | You may obtain a copy of the License at 6 | 7 | http://www.apache.org/licenses/LICENSE-2.0 8 | 9 | Unless required by applicable law or agreed to in writing, software 10 | distributed under the License is distributed on an "AS IS" BASIS, 11 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12 | See the License for the specific language governing permissions and 13 | limitations under the License. -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 |
17 | Key Features • 18 | Installation • 19 | Contact Us • 20 | Credit • 21 | License 22 |
23 | 24 |
25 |
26 |