forked from asaotomo/DeepSentry
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathconfig.example.yaml
More file actions
328 lines (302 loc) · 17.2 KB
/
Copy pathconfig.example.yaml
File metadata and controls
328 lines (302 loc) · 17.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
# DeepSentry 配置示例 — 复制为 config.yaml 后修改
# 支持 provider: openai | anthropic | google | deepseek | qwen | qianfan | volcengine | hunyuan | tencent_hy | teleai | ctyun | minimax | mimo | glm | xai | grok | ollama | lmstudio | vllm | llamacpp | sglang | localai | custom
# 支持 api_protocol: auto | openai_chat | anthropic_messages | openai_responses
# 各 provider 的内置预设模型(model_name 留空时自动使用;可随时显式覆盖):
# openai: gpt-6-astra (GPT-6 Astra) | anthropic: claude-opus-5-5 | google: gemini-3.8-flash
# deepseek: deepseek-flash | qwen: qwen3.8-max | hunyuan/tencent_hy: hy4-preview
# qianfan: qianfan-code-latest | volcengine: ark-code-latest | teleai/ctyun: GLM-5-Pro
# minimax: MiniMax-M3 | glm: glm-5.3-flash | mimo Token Plan / MiMo Claw: mimo-v2.6-pro
# xai/grok: grok-4.7 | 本地服务: model_name 使用服务 /v1/models 返回的实际 ID
provider: deepseek
api_protocol: auto
api_url: https://api.deepseek.com # 可只填 base,自动补 /chat/completions
api_key: YOUR_API_KEY
model_name: deepseek-flash # 官方 API ID(产品名 V4.1 Flash):1M 上下文、原生多模态图片输入
temperature: 0.0 # 0~2;安全运维/比赛建议保持 0,减少随机漂移
# Agent 运行时。v3 已是默认;遇到兼容问题可显式设为 legacy 回滚。
# v3 启用结构化事件、模型 failover、原生流式多工具调用和 checkpoint v3。
agent_runtime: v3
trace_enabled: true
trace_dir: reports/traces
# TUI 主题。auto 会探测终端背景明暗并自动选择高对比色板;
# 远程终端无法正确响应背景查询时,可固定为 dark 或 light。
terminal_theme: auto # auto | dark | light
# 可选模型链;未配置时继续使用上方单模型字段。只能有一个 primary,
# fallback 按配置顺序尝试。每个 endpoint 的空字段继承上方配置。
# models:
# - id: primary
# role: primary
# provider: deepseek
# model_name: deepseek-flash
# max_retries: 3
# - id: local-fallback
# role: fallback
# provider: ollama
# api_url: http://127.0.0.1:11434/v1
# api_key: none
# model_name: qwen3:14b
# max_retries: 1
# 本地推理服务也可设为 primary;Ollama(11434)、LM Studio(1234)、vLLM(8000)、
# llama.cpp server/LocalAI(8080)、SGLang(30000) 均使用 OpenAI 兼容 /v1/chat/completions。
# 例如 provider: vllm,api_url: http://127.0.0.1:8000/v1,model_name: 服务返回的模型 ID。
# 启用鉴权时填写真实 api_key;未启用时可填 none。上下文长度应填服务实际加载值。
# model_routing:
# failover_on: [rate_limit, timeout, server_error, connection, invalid_output]
# 订阅套餐预设(三选一替换上方 provider/api_url/model_name):
# 百度千帆 Coding Plan:
# provider: qianfan
# api_url: https://qianfan.baidubce.com/v2/coding
# model_name: qianfan-code-latest
# 火山方舟 Coding Plan:
# provider: volcengine
# api_url: https://ark.cn-beijing.volces.com/api/coding/v3
# model_name: ark-code-latest
# Xiaomi MiMo 官方名称为 Token Plan,MiMo Claw/Agent 场景共用该接口;目前无独立 Agent Plan Base URL。
# 模型能力与上下文适配。auto 会分别处理本地小模型和云端长上下文模型。
model_profile: auto # auto | compact | balanced | full
model_parameter_b: 0 # 可选:参数量(B);模型名含 14b/70b 时可自动识别
context_window_tokens: 0 # 0=启动时查询 LM Studio/Ollama 已加载实例的实际窗口;其他服务回退安全默认
context_utilization: 0 # 0=自动;可选 0.40~0.90,为输出和 provider 开销留余量
reserved_output_tokens: 0 # 0=按窗口自动;也是 API 的输出上限建议值
native_tool_limit: 0 # 0=按 profile 自动;compact=8, balanced=20, full=全部
vision_mode: auto # auto|enabled|disabled;本地视觉模型向导会检测并确认;手动配置时 auto 按目录/名称保守识别
# auto 已精确识别:deepseek-flash、deepseek-v4-flash-vision-exp、glm-5.3-flash、
# MiniMax-M3、mimo-v2.6-pro、gpt-6-astra / gpt-6-sol / gpt-6-luna、grok-4.7、gpt-5.6、claude-opus-5-5、
# claude-sonnet-5、claude-haiku-4-5、gemini-3.8-flash、qwen3.8-max。
# 已知纯文本变体不会因同厂商而误开图片;代理/自定义模型无法识别时再显式设 enabled。
# 例:Gemini 1M 可显式填 1048576。本地服务使用实际加载窗口而非模型卡理论上限;
# 查询不到运行时窗口时按 32768 安全窗口运行,可显式填写实际 num_ctx/max_model_len。
use_native_tools: true
# 内置 Go 原生工具支持热插拔:
# enabled_tools 非空时作为白名单;disabled_tools 作为黑名单。
# 默认不配置表示全部启用,但模型会通过 tool_catalog 按需发现,不会每轮展开全部工具。
# 常用安全基线白名单示例:
# enabled_tools: ["read_log", "net_connections", "process_list", "proc_socket_map", "sqlite_inspect", "db_config_audit", "secret_scan"]
# 对生产环境较敏感的远程探测/传输/转发可禁用:
# disabled_tools: ["nmap_scan", "packet_capture", "service_fingerprint", "redis_probe", "mysql_probe", "postgres_probe", "oracle_probe", "cidr_scan", "script_run", "file_upload", "archive_extract", "tcp_forward", "socks5_proxy", "http_proxy"]
llm_timeout_sec: 120
llm_retries: 3
ssh_command_timeout_sec: 90
ssh_max_output_bytes: 524288 # SSH 单命令回传上限(字节),超出截断不报错;大日志请配合 head/tail/wc
max_steps: 30 # 自适应开启时为主 Agent 初始规划窗口
subagent_max_steps: 15 # 自适应开启时为子 Agent 初始规划窗口
execution_budget:
enabled: true # false 恢复原固定步数行为
max_steps: 180 # 主 Agent 单次执行的硬上限
subagent_max_steps: 90 # 单个子 Agent 硬上限
total_steps: 300 # 主 Agent 与所有子 Agent 共享模型调用预算
extension_steps: 15 # 有新工具结果时自动续步
no_progress_steps: 8 # 连续无新结果时保存进度并暂停
# 控制端出站代理(可选):统一影响 LLM、MCP HTTP、HTTP/Web、TCP/CIDR/数据库探测、
# SSH/Telnet/FTP 目标连接和无头浏览器。也可启动时用 -proxy 或 -socks5 临时覆盖。
# 支持 http://、https://、socks5://、socks5h://;留空时使用系统环境变量 HTTP_PROXY/HTTPS_PROXY/NO_PROXY。
controller_proxy: ""
# 控制端浏览器(可选)。留空时自动查找 Chrome/Chromium;browser_browse 的 auto 模式
# 在桌面环境打开隔离的可见 Chrome,无桌面时使用无头模式。不可用时返回安装引导,
# headless_browser/web_snapshot 仍可回退 Go 静态解析。不会复用个人 Chrome profile。
browser_binary: ""
browser_timeout_sec: 20
browser_artifact_dir: reports/browser
archive_max_entries: 10000 # 本地解压最大条目数
archive_max_file_bytes: 536870912 # 单文件最大 512 MiB
archive_max_total_bytes: 2147483648 # 总解压量最大 2 GiB
# 本地控制端定时任务(可选)。任务保存在 scheduler_store;进程运行时会按 interval 检查到期任务。
# 支持自然语言创建:如“明天9点巡检服务器并生成报告发钉钉和飞书通知”。
scheduler_enabled: true
scheduler_store: reports/schedules/tasks.json
scheduler_interval_sec: 30
scheduler_timezone: Local
# 通知通道(可选)。schedule_task notify 支持 dingtalk、feishu、email,也支持逗号多选:
# notify: dingtalk,feishu,email
# 钉钉机器人:需要发钉钉时配置 webhook;加签机器人填写 secret。
dingtalk_webhook: ""
dingtalk_secret: ""
# 飞书/Lark 自定义机器人:需要发飞书时配置 webhook;加签机器人填写 secret。
feishu_webhook: ""
feishu_secret: ""
# 邮件网关:DeepSentry 通过 HTTP JSON POST 调用企业邮件网关。
# 请求体包含 to、from、subject、markdown、text、source 字段。
# email_gateway_header 默认为 Authorization;如果 token 不是 Bearer,可填 X-API-Key 等。
email_gateway_url: ""
email_gateway_token: ""
email_gateway_header: Authorization
email_to: ""
email_from: ""
# TSecBench 跑分平台(可选):配置后 agent 可直接通过内置 tsecbench 工具拉题、启动容器、提交 flag、关闭容器。
# 也兼容大写 YAML key: BENCHMARK_BASE_URL / BENCHMARK_TOKEN,以及环境变量 BENCHMARK_BASE_URL / BENCHMARK_TOKEN。
benchmark_base_url: ""
benchmark_token: ""
# 目标连接模式:local | ssh | telnet | ftp
# 发布模板默认 local,避免复制后误连外部主机。切换远程模式时再填写对应 host。
# 为空时兼容旧配置:优先 ssh_host,其次 telnet_host / ftp_host,否则本地模式。
target_protocol: local
# SSH 远程模式(无端口时默认 :22)
ssh_host: "" # 例:"192.0.2.10:22"(文档保留地址)
ssh_user: root
ssh_password: ""
ssh_key_path: ""
ssh_key_passphrase: "" # 加密私钥口令;未加密可留空
ssh_host_key_policy: accept-new # strict | accept-new | insecure;正式环境禁止 insecure
ssh_known_hosts_path: ~/.deepsentry/known_hosts
ssh_legacy_compat: true # 默认兼容老 OpenSSH / 交换机的 ssh-rsa、DH-SHA1、CBC
ssh_connect_timeout_sec: 25 # 老设备握手慢时可加大
ssh_device_type: auto # auto | linux | huawei | h3c | ruijie | cisco | asa | juniper | fortinet | paloalto | hillstone | sangfor | checkpoint | generic
ssh_prompt: "" # 网络设备交互 CLI prompt;留空自动探测
ssh_enable_password: "" # 华为/H3C 用于 super,Cisco/锐捷/ASA/山石/深信服用于 enable;留空不自动提权
# Telnet 远程模式(老设备/极简环境,无端口时默认 :23)
telnet_host: ""
telnet_user: root
telnet_password: ""
telnet_device_type: auto # auto | huawei | h3c | ruijie | cisco | linux | generic
telnet_auth_prompt_regex: "" # 仅认证阶段;非常规 Password/Passcode 提示才需要
telnet_prompt: "" # 仅命令阶段;空值自动捕获 <Huawei>/[H3C]/hostname#/$
telnet_enable_password: "" # 华为/H3C 用于 super,Cisco/锐捷用于 enable;留空不自动提权
telnet_connect_timeout_sec: 10
telnet_login_timeout_sec: 20
telnet_command_timeout_sec: 90
# FTP/FTPS 文件模式(只支持目录/文件读写上传下载,无 shell)
ftp_host: ""
ftp_user: anonymous
ftp_password: ""
ftp_tls_mode: plain # plain | explicit | implicit;implicit 无端口时默认 :990,其余 :21
ftp_tls_server_name: "" # 证书主机名;留空使用 ftp_host 中的主机
ftp_tls_ca_file: "" # 私有 CA/自签证书 PEM;留空使用系统信任库
ftp_tls_insecure_skip_verify: false # 仅临时排障;正式环境必须 false
ftp_data_mode: passive # passive | active | auto;passive 优先 EPSV→PASV,active 优先 EPRT→PORT
ftp_active_address: "" # 主动模式对外广播 IP;留空自动使用控制连接本地 IP
ftp_connect_timeout_sec: 10
ftp_command_timeout_sec: 30
ftp_transfer_timeout_sec: 90
# Fleet 多目标运维清单(可选)
# selector 可使用 name、host、protocol 或 tags;逗号取交集,| 取并集,例如 fleet_exec selector=prod,ssh
# targets:
# - name: web-01
# protocol: ssh
# host: "10.0.0.11:22"
# user: root
# password: ""
# key_path: "~/.ssh/id_ed25519"
# tags: ["prod", "web"]
# - name: legacy-01
# protocol: telnet
# host: "10.0.1.20:23"
# user: admin
# password: "YOUR_PASSWORD"
# device_type: huawei
# auth_prompt_regex: ""
# prompt: "<Core-Switch>" # 仅命令 prompt;可空自动探测
# enable_password: "" # 可选;华为/H3C 登录后自动执行 super
# tags: ["legacy", "network"]
# - name: core-switch-ssh
# protocol: ssh
# host: "10.0.1.21:22"
# user: admin
# password: "YOUR_PASSWORD"
# device_type: h3c
# prompt: "<Core-H3C>" # 可空自动探测;SSH 网络设备使用 PTY CLI
# enable_password: "" # 可选;配置后登录自动执行 super
# tags: ["core", "network"]
# - name: filebox-01
# protocol: ftp
# host: "10.0.2.30:21"
# user: anonymous
# password: ""
# tags: ["ftp", "evidence"]
# 外部 Skills(可选)
# 每个来源目录下面放多个 Skill 子目录,每个 Skill 子目录必须包含 SKILL.md。
# 始终加载发布包内置 bundled-skills;默认还加载 ./skills 和 ~/.deepsentry/skills。
# 配置 skill_sources 后,使用这里声明的目录替代 ./skills。
# skill_sources:
# - "skills"
# - "~/.deepsentry/skills"
# - "/opt/deepsentry-skills"
# disabled_skill_sources:
# - "/opt/old-skills"
# 按 Skill frontmatter 的 name 禁用;不依赖来源路径,也不会被自动加载。
# disabled_skills:
# - "fun-brainstorming"
# skills_disabled: false # true 时全局关闭 Skill;等同 TUI 的 /skill off
# 若只想启用一个已发现的 Skill,可在 TUI 使用:/skill only fofamap
# MCP 扩展(可选)
# 旧短格式仍兼容:name:command:arg1,arg2
# mcp_servers:
# - "myserver:npx:-y,@org/mcp-server"
#
# 推荐使用结构化格式,支持 stdio 与 Streamable HTTP、工具过滤、超时和必需服务。
# mcp_server_configs:
# - name: fs
# type: stdio
# command: npx
# args: ["-y", "@modelcontextprotocol/server-filesystem", "/tmp"]
# cwd: "/tmp"
# env:
# EXAMPLE_TOKEN: "xxx"
# disabled: false
# - name: remote-docs
# type: streamable_http
# url: "https://mcp.example.com/mcp"
# # 敏感 Token 不写入 YAML,只声明其环境变量名;OAuth 可用 /mcp login remote-docs。
# bearer_token_env_var: "REMOTE_MCP_TOKEN"
# headers:
# X-Workspace: "security"
# enabled_tools: ["search", "read"]
# disabled_tools: ["delete"]
# startup_timeout_sec: 30
# tool_timeout_sec: 120
# required: false
# disabled: false
#
# FofaMap v2.0.1 MCP 深度适配(先在 FofaMap 目录运行 fofamap init,将密钥保存到系统钥匙串):
# - name: fofamap
# type: stdio
# # 使用绝对路径,避免 GUI/服务进程没有继承 shell PATH。
# command: "/absolute/path/FofaMap/.venv/bin/python"
# args: ["/absolute/path/FofaMap/mcp_server.py"]
# # 0/省略 = DeepSentry 分工具超时:搜索/导出 120s、Agent 300s、Nuclei 600s。
# tool_timeout_sec: 0
# startup_timeout_sec: 30
# required: false
# disabled: false
#
# HawkEye MCP 1.0.12 深度适配示例(路径换成本机实际位置):
# - name: hawkeye
# type: stdio
# command: node
# args:
# - /absolute/path/DeepSentry-deepagent/hawkeye-mcp-server.mjs
# - --profile
# - full
# # 0/省略 = DeepSentry 客户端超时略高于 Server:Research 205s,
# # Search/Fetch/Captcha/Fuzz 130s,快照/导航等 100s,其余 60s。
# # 如显式填写 tool_timeout_sec,则始终以用户值为准。
# tool_timeout_sec: 0
# startup_timeout_sec: 30
# required: false
# disabled: false
# Agent 配置自管理说明:
# 用户在 TUI 中要求“添加 skill 路径 / 添加 MCP / 保存 SSH 目标”时,
# Agent 会使用 config_manage 工具更新本机 config.yaml,并在写入前自动备份到
# .deepsentry_backups/config_<timestamp>.yaml。
# 聊天控制服务:TUI 输入 /connect,或运行 deepsentry --chat-setup -c config.yaml。
# 飞书、QQ、微信提供扫码绑定;企业微信打开官方扫码弹窗后配对控制账号。
# 扫码凭据自动保存在 binding_file,文件权限 0600,不写入 YAML、不回传给模型。
chat:
listen: "127.0.0.1:8787" # 回调服务;长连接/微信轮询不需要公网地址
store: reports/chat/jobs.json
binding_file: reports/chat/connections.json
task_timeout_sec: 1800
max_concurrent: 5 # 最多 5 路并发任务;不同会话隔离,同一私聊排队续跑
progress_interval_sec: 30 # 公开步骤/工具进度推送最小间隔;/status 随时查看
progress_max_messages: 3 # 每任务最多推送次数(QQ 进一步限制为 1 次)
transcription_url: "" # 可选:OpenAI 兼容 /v1/audio/transcriptions 的完整 HTTPS URL
transcription_key_env: "" # 转写服务密钥的环境变量名,不在这里填写密钥
transcription_model: "whisper-1" # 按所用转写服务填写;微信/企微自带转写文字时无需调用
allow_batch: false # 手动通道的任务执行开关;扫码通道在窗口中单独授权
wecom_source: deepsentry # 企业微信授权来源;平台要求开通时填其分配的标识
channels: [] # 扫码通道自动加载;手动配置示例见 docs/聊天机器人接入.md
# 巡检:设备清单见 inspection.example.yaml(聊天 + 鹰眼;可选 command / 选择器做固定采集)。
inspection:
output_dir: reports/inspections
concurrency: 3
device_timeout_sec: 180
devices: []