Project Oxygen & Ideo-LabIDEO LAB Dashboard 2026

đŸ›Ąïž Security Testing & Assessment Toolkit

Guide HTML IDEO-Lab clair — mĂ©thodologie, outils, installation, workflow, tableaux, diagrammes, commandes et remĂ©diation.

Objectif : auditer uniquement une infrastructure que tu possÚdes ou que tu es explicitement autorisé à tester, puis transformer chaque finding en correction vérifiable.

Carte d’audit
Recon→Scan→Enum
Analyse→Fix→Retest
Fil rouge
Network first, staging for active tests, evidence before opinion, remediation before escalation.
0 Facile

Panorama du toolkit

Vue globale : phases, familles de tests, niveau de risque et logique terrain.

MéthodeCarteWorkflow
1 Facile

Cadre légal & périmÚtre

Autorisation, périmÚtre écrit, progressivité et zones interdites en production.

ScopeÉthiqueRisque
2 Facile

Méthodologie en 6 phases

Reconnaissance, scan, énumération, analyse, preuve contrÎlée, reporting.

6 phasesPTESOWASP
3 Moyen

Installation & lab

Poste Ubuntu/Windows, Docker, wordlists, outils de base et cibles d’entraünement.

UbuntuWindowsDocker
4 Facile

Reconnaissance & OSINT

DNS, certificats, sous-domaines, Shodan/Censys et cartographie passive.

OSINTDNSCT logs
5 Moyen

Découverte réseau & ports

Nmap, RustScan, masscan, états open/filtered/closed, ports exposés.

NmapPortsFirewall
6 Moyen

ÉnumĂ©ration des services

HTTP fingerprinting, nmap NSE, whatweb, wafw00f, SSH, DB, DNS, SNMP.

EnumHTTPNSE
7 Moyen

TLS, SSL & headers

testssl.sh, sslscan, sslyze, HSTS, CSP, X-Frame, politique reverse proxy.

TLSHeadersNginx
8 Moyen

DAST : Burp, ZAP, Nikto

Proxy manuel, scan passif, scan actif staging, analyse des alertes.

ZAPBurpNikto
9 Moyen

Content discovery

ffuf, feroxbuster, gobuster, SecLists, endpoints cachés, backups, .git.

ffufSecLists403/200
10 Facile

Scanners CMS

WPScan, droopescan, JoomScan, CMSeeK : plugins, users, versions, CVE.

CMSWPScanDrupal
11 Avancé

Injection & exploitation web

SQLi, XSS, SSTI, LFI, SSRF : preuve minimale, staging uniquement.

SQLiXSSStaging
12 Moyen

Scanners de vulnérabilités

Nuclei, OpenVAS, Nessus, InsightVM : templates, CVE, sévérité, tri.

NucleiCVECVSS
13 Avancé

Frameworks d’exploitation

Metasploit, searchsploit, BeEF : validation contrÎlée, jamais de dégùts.

PoCMetasploitSafe
14 Avancé

Passwords & authentication

Hydra défensif, lockout, MFA, rate limit, sessions, cookies, reset password.

MFALockoutJWT
15 Moyen

API, JWT & BOLA

OpenAPI, autorisations objet, JWT, CORS, tests par rĂŽle, Postman/ZAP API.

APIBOLAJWT
16 Moyen

Cloud & containers AWS

Prowler, security groups, IAM, S3, Trivy, Grype, Docker Bench.

AWSTrivyIAM
17 Facile

SAST, dépendances & secrets

Bandit, Semgrep, pip-audit, Gitleaks, TruffleHog, CodeQL, CI.

SASTSCASecrets
18 Moyen

Analyse trafic réseau

tcpdump, tshark, Wireshark, mitmproxy : preuve, debug, fuite de données.

PCAPTLSProxy
19 Facile

Distributions sécurité

Kali, Parrot, BlackArch, Commando VM : quand les utiliser, quand éviter.

KaliParrotVM
20 Moyen

Application Ă  IDEO-Lab

FastAPI, Nginx, AWS, ports internes, bind localhost, SG, reverse proxy.

FastAPINginxAWS
21 Moyen

Workflow end-to-end

Ordre recommandé, preuves, fichiers de sortie, décisions go/no-go.

RunbookAuditRetest
22 Facile

Reporting & remediation

Fiche finding, matrice de risque, priorisation, patch, re-test, suivi.

ReportCVSSFix
23 Avancé

Lab, fuzzing & RE

Juice Shop, DVWA, RESTler, AFL++, radamsa, Ghidra : limites et utilité.

LabFuzzingRE
A Facile

Master tool table

Table globale : outil, catégorie, intrusivité, usage, sortie attendue.

ToolsMatrixRef
B Facile

Command cheat-sheet

Commandes prĂȘtes Ă  adapter pour ton propre domaine ou staging.

CommandsQuickRunbook