mirror of
https://github.com/Arcanum-Sec/wraith
synced 2026-08-08 10:45:03 +00:00
Browser-hooking framework for red teams, researchers, and educators: a clean-room successor to BeEF (hook + Pretty Theft overlays) fused with blind-XSS callback tooling, built to hook browsers across modern (incl. AI) app ecosystems. - One-command Docker install (setup.sh): auto-detects public IP/domain, provisions operator username + password, prints hook/XSS URLs - Operator console: live keystrokes, captured creds, page capture, page mirror, calibrated localhost/LAN scan, XSS payload catalog - Overlays (LinkedIn/Facebook/Microsoft), built-in vulnerable practice lab - Apache-2.0 licensed For authorized security testing, research, and education only.
24 lines
844 B
YAML
24 lines
844 B
YAML
# WRAITH — run with: ./setup.sh (writes .env, then brings this up)
|
|
# Or manually: cp .env.example .env && edit it && docker compose up -d --build
|
|
#
|
|
# Compose reads .env automatically for both ${VAR} substitution below AND, via
|
|
# env_file, for injecting config into the container. .env holds your secrets and
|
|
# is gitignored — it is never copied into the image.
|
|
|
|
services:
|
|
wraith:
|
|
build: .
|
|
image: wraith:latest
|
|
container_name: wraith
|
|
restart: unless-stopped
|
|
env_file: .env
|
|
environment:
|
|
# Always bind all interfaces inside the container; the host port mapping
|
|
# below is what actually controls exposure.
|
|
WRAITH_HOST: "0.0.0.0"
|
|
ports:
|
|
- "${WRAITH_PORT:-8090}:${WRAITH_PORT:-8090}"
|
|
volumes:
|
|
# Persist captured sessions on the host, outside the image.
|
|
- ./data:/app/data
|