* upgrade to dapr postgresv2 statestore * actually make it v2 * dapr state table name, cleanup subscriptions/globals * proper exceptions * formatting/lint * Refactor workflow tracking and improve activity input handling - Extract workflow tracking logic into dedicated WorkflowTrackingService - Simplify activity signatures to accept specific parameters instead of generic dicts - Remove unused asyncio event loop references from enrichment modules - Update YaraRuleManager initialization and method names * re-added workflow tracking in the DB * update uvicorn prod options * enrichment work parallelism, convert queues from broadcast to task queues * Refactor pubsub and improve workflow parallelism - Split Dapr pubsub Dapr yaml components into topic-specific queues (alerting, dotnet, dpapi, files, noseyparker, workflow_monitor) - Update all Dapr volume mounts to reference new topic-specific pubsub components - Converted queues to task queues - Use YAML anchors to reduce duplication for file-enrichment replicas - Pass asyncpg pool to enrichment modules instead of creating connections - Add asyncpg_pool parameter throughout chromium and enrichment module analyzers - Update VSCode workspace (removed InspectAssembly, renamed dotnet_api to dotnet_service) - Added curl commands for Jaeger API to performance docs to help with perf troubleshooting - Created common.queues module to centralize pubsub/topic names (eases future refactoring) * worker mods * Workflow performance tuning, fix pubsub config, CLI arg changes - Fix pubsub deleteWhenUnused typo (deletedWhenUnused) - Add LOG_LEVEL environment variable support across services - CLI: Rename --repeat to --times, add --max-files option - Increase files pubsub prefetchCount from 25 to 50 - Add MAX_PARALLEL_WORKFLOWS configuration - Fix DotNetAssemblyAnalysis null handling with field validators - Update dashboard to show cumulative files/findings over time - Add RUST_LOG environment variable support to noseyparker - Update CHANGELOG for 2.1.4 release notes * Dapr 1.16.2 and use db transactions - Upgrade all Dapr containers from 1.16.1 to 1.16.2 - Reduce enrichment parallelism default from 25 to 5 workflows - Reduce healthcheck intervals from 10s to 5s for alerting and document conversion - Fixed DPAPI eventing to use new pubsubs - Refactor file_linking database operations to use atomic upserts and avoid deadlocks - Add WriteOnceViolationError handling in DPAPI masterkey analyzer - Wrap database operations in transactions for enrichment storage and plaintext indexing - Fix postgres notification handler closure variable capture * remove unused start_time * Scheduler persistence, workflow concurrency tuning, and config cleanup - Add volume for Dapr scheduler and init service - Add scheduler dependency to file enrichment service - Add async workflow client libraries - Format and cleanup compose.yaml (spacing, indentation, empty lines) * Migrate file_enrichment to async Dapr client and optimize Dockerfile - Use async DaprClient where possible in file_enrichment - Improve Dockerfile caching - Add asyncpg connection pool helper and fix typo in secret store name - Include VS Code debug configuration for document_conversion - Remove unused dapr_client from DpapiBlobAnalyzer - Clean up activity return types and better handle exceptions * Enrichment tracking for NoseyParker and logging cleanup - Add workflow_id to NoseyParkerInput and NoseyParkerOutput models - Remove workflow lookup query in noseyparker subscription handler - Adjust jaeger_perf_stats.sh output formatting and precision - Add type hints for async functions * noseyparker scanner perf, tracing for update_enrichment_results --------- Co-authored-by: Lee Chagolla-Christensen <lee@localhost>
Overview
Nemesis is an offensive file enrichment pipeline.
Nemesis 2.0 is built on Docker with heavy Dapr integration, our goal with Nemesis was to create a centralized file processing platform that functions as an "offensive VirusTotal".
Note: the previous Nemesis 1.0.1 code base has been preserved as a branch
Setup / Installation
Follow the quickstart guide.
Usage
See the Nemesis Usage Guide.
Additional Information
Blog Posts:
| Title | Nemesis Version | Date |
|---|---|---|
| Nemesis 2.0 | v2.0 | Aug 5, 2025 |
| Nemesis 1.0.0 | v1.0 | Apr 25, 2024 |
| Summoning RAGnarok With Your Nemesis | v1.0 | Mar 13, 2024 |
| Shadow Wizard Registry Gang: Structured Registry Querying | v1.0 | Sep 5, 2023 |
| Hacking With Your Nemesis | v1.0 | Aug 9, 2023 |
| Challenges In Post-Exploitation Workflows | v1.0 | Aug 2, 2023 |
| On (Structured) Data | v1.0 | Jul 26, 2023 |
Presentations:
| Title | Date |
|---|---|
| OffensiveX 2025 | Jun 19, 2025 |
| x33fcon 2025 | Jun 13, 2025 |
| SAINTCON 2023 | Oct 24, 2023 |
| BSidesAugusta 2023 | Oct 7, 2023 |
| 44CON 2023 | Sep 15, 2023 |
| BlackHat Arsenal USA 2023 | Sep 15, 2023 |
Acknowledgments
Nemesis is built on large chunk of other people's work. Throughout the codebase we've provided citations, references, and applicable licenses for anything used or adapted from public sources. If we're forgotten proper credit anywhere, please let us know or submit a pull request!
We also want to acknowledge Evan McBroom, Hope Walker, and Carlo Alcantara from SpecterOps for their help with the initial Nemesis concept and amazing feedback throughout the development process. Also thanks to Matt Ehrnschwender for tons of k3s and GitHub workflow help in Nemesis 1.0!
And finally, shout out to OpenAI and Claude for helping with this rewrite.
