Add VANGUARD9_SCAN_PROMPTS.md — world-class standalone scan prompt arsenal

6 fully rewritten professional-grade prompts for use during Strix scan sessions:

1. PROMPT 1 — Initial Full Scan Kickoff: 10-subagent army, full phase methodology,
   anti-FP rules, evidence gates, human-like UI testing mandate
2. PROMPT 2 — Start with Account Creation + Deep UI Hunt: account setup protocol,
   nested UI hierarchy testing to infinite depth, IDOR immediate testing after every creation
3. PROMPT 3 — Multi-Subagent Parallel Assault: 8 specialized subagents with exact
   mission briefs (Recon, BAC, Auth, Injection, XSS, Business Logic, SSRF/CORS, GraphQL/API),
   central coordinator rules, real-time finding synchronization across subagents
4. PROMPT 4 — BAC + Auth + Login + UI Hierarchy Specialist: 3 parallel tracks with
   surgical depth on IDOR/privilege escalation/mass assignment (Track 1), every auth
   attack (login bypass/password reset/MFA bypass/JWT/session) with exact techniques (Track 2),
   infinite-depth UI hierarchy mapping (Track 3)
5. PROMPT 5 — Resume / Re-Scan Boost: resume protocol, report upgrade checklist,
   deepening pass (WAF bypass/403 techniques/expert methods), false positive purge
6. PROMPT 6 — Deep Validation + False Positive Purge: per-vulnerability-type validation
   protocol, 5-step evidence reconstruction, 11-section report upgrade, FP classification,
   final report structure with 5 sections

All prompts include:
- Anti-false-positive engine (JSON XSS, 500=type mismatch, DNS SSRF, CORS on public endpoints)
- Real impact gates with severity evidence requirements per vuln type
- Raw HTTP mandate with ← marker format
- UI reproduction steps requirement
- Evidence quick-reference card

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
root 2026-04-05 01:01:21 +02:00
parent 458c1d4950
commit b962a8d6b0

1267
VANGUARD9_SCAN_PROMPTS.md Normal file

File diff suppressed because it is too large Load diff