daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

README.md (8260B)


      1 <div align="center">
      2 
      3 # ☧ DÆMONBins
      4 
      5 ### the Off-the-Land Almanac
      6 
      7 https://daemon-sec-lotl.vercel.app/
      8 
      9 https://daemon-404.github.io/daemon-sec-lotl/
     10 
     11 *GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, and extended into one filterable catalog.*
     12 
     13 <br>
     14 
     15 [![License](https://img.shields.io/badge/license-GPL--3.0-f6c177?style=flat-square&labelColor=191724)](./LICENSE)
     16 [![Built with Astro](https://img.shields.io/badge/Astro-5-c4a7e7?style=flat-square&labelColor=191724&logo=astro&logoColor=c4a7e7)](https://astro.build)
     17 [![Search: Pagefind](https://img.shields.io/badge/search-Pagefind-9ccfd8?style=flat-square&labelColor=191724)](https://pagefind.app)
     18 [![Deploy: Vercel](https://img.shields.io/badge/deploy-Vercel-e0def4?style=flat-square&labelColor=191724&logo=vercel&logoColor=e0def4)](https://lotl.daemon-sec.xyz/)
     19 [![Theme: Rosé Pine](https://img.shields.io/badge/theme-Ros%C3%A9_Pine-ebbcba?style=flat-square&labelColor=191724)](https://rosepinetheme.com)
     20 
     21 [![Techniques](https://img.shields.io/badge/techniques-3085-eb6f92?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog)
     22 [![Tools](https://img.shields.io/badge/tools-907-9ccfd8?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog)
     23 [![DÆMON additions](https://img.shields.io/badge/D%C3%86MON-196-f6c177?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/daemon)
     24 [![Sources](https://img.shields.io/badge/collections-5-c4a7e7?style=flat-square&labelColor=191724)](#the-five-collections)
     25 
     26 **[ Open the catalog → ](https://lotl.daemon-sec.xyz/catalog)**
     27 
     28 </div>
     29 
     30 ---
     31 
     32 A static [Astro](https://astro.build) site with [Pagefind](https://pagefind.app) search, in the
     33 visual language of [daemon-sec.xyz](https://daemon-sec.xyz). Every living-off-the-land and
     34 offensive technique from four public references is flattened to one filterable atom — a
     35 **Technique** — and filterable by **platform**, **capability**, **source**, **execution context**,
     36 **required access**, **service**, **environment**, **availability**, and **evidence state**. The
     37 catalog supports grouped variants, saved commands, configurable templates, shareable URL state,
     38 and a compact details inspector. Per-tool pages group a binary's techniques.
     39 
     40 All four upstreams are GPL-3.0, so this combined work is **GPL-3.0**. See
     41 [`THIRD_PARTY_NOTICES.md`](./THIRD_PARTY_NOTICES.md) and [`LICENSE`](./LICENSE).
     42 
     43 ## ❀ The five collections
     44 
     45 | Deck | Source | Techniques | What it is |
     46 |---|---|--:|---|
     47 | 🩵 **GTFOBins** | `acd5246` | 2,125 | Unix binaries abused for shell, file r/w, and SUID / sudo / capabilities privesc |
     48 | 💜 **LOLBAS** | `7aca936` | 481 | Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass |
     49 | 💛 **WADComs** | `a864cd1` | 100 | Offensive Windows / Active Directory tooling, indexed by what access you hold |
     50 | 🩷 **LOOBins** | `399e3c4` | 183 | macOS binaries and documented use cases |
     51 | ❤️ **DÆMON** | *authored* | 196 | 134 fact-checked WADComs additions + 17 documented command references, badged **DÆMON** |
     52 | | **Total** | **3,085** | **907 tools · all Zod-validated** |
     53 
     54 Everything is placeholder-only reference material (lab IPs, `test.local`, `john` / `password123`)
     55 in the spirit of GTFOBins, LOLBAS, WADComs, LOOBins and MITRE ATT&CK.
     56 
     57 ## ☧ Layout
     58 
     59 ```
     60 vendor/{gtfobins,lolbas,wadcoms}   the three upstreams (vendored; see setup-vendor.sh)
     61 src/data/sources/loobins.json      pinned LOOBins snapshot (183 use cases)
     62 src/data/sources/wadcoms-additions.json  committed authored WADComs snapshot
     63 scripts/build-dataset.mjs          local ingestion → src/data/*.json + public/data
     64 scripts/wadcoms-normalize.mjs      WADComs family fixes (Impacket split, case-fold)
     65 scripts/split-impacket.mjs         one-shot, idempotent migration of the committed data
     66 src/data/techniques.json           the canonical, committed dataset (a Technique[])
     67 src/data/tools.json                per-tool metadata (aliases, Full_Path, contributors)
     68 src/data/facets.json               derived facet indexes + counts + upstream commits
     69 src/data/catalog-additions.json    documented DÆMON command references
     70 src/pages/                         home · /catalog · /<deck> · /<deck>/<tool> · credits · 404
     71 src/scripts/catalog.ts             the vanilla-TS catalog workspace island
     72 src/lib/{taxonomy,techniques,highlight,url}.ts   shared vocabulary + pure logic
     73 src/styles, src/components, src/fonts             design system (cloned from the cheatsheet)
     74 ```
     75 
     76 Routing is by toolId **namespace** (`gtfo:`/`lolbas:`/`wadcoms:`/`daemon:`), so a tool always
     77 resolves to one page even when a family mixes upstream and DÆMON-authored techniques; a
     78 per-technique NEW badge conveys authorship.
     79 
     80 **Impacket** is a *suite*, not one tool, so its ~48 WADComs techniques are split back out by their
     81 actual `examples/<script>.py` — one page per script (`Impacket-secretsdump`, `Impacket-ntlmrelayx`,
     82 …). Case-duplicate WADComs families (e.g. `Enum4Linux` / `enum4linux`) are folded onto one canonical
     83 page so the static router never silently drops a tool. Both normalisations live in
     84 `scripts/wadcoms-normalize.mjs` and are applied by `npm run data` and the one-shot
     85 `scripts/split-impacket.mjs`.
     86 
     87 ## 🩵 Develop
     88 
     89 ```bash
     90 npm install
     91 npm run data     # regenerate the dataset from vendor/ + committed source snapshots
     92 npm run dev      # local dev server
     93 npm run build    # astro build + pagefind index → dist/
     94 npm run preview  # serve the production build
     95 ```
     96 
     97 `npm run build` (what CI runs) only consumes the committed `src/data/techniques.json`; it never
     98 re-runs ingestion, so there is no cross-repo dependency at deploy time.
     99 
    100 ## 💛 Regenerating the dataset
    101 
    102 `npm run data` reads the vendored upstreams, the committed authored snapshots in
    103 `src/data/sources/`, and `src/data/catalog-additions.json`. It normalizes everything to the unified `Technique` model,
    104 validates every record with Zod (failing on any bad or duplicate record), and writes
    105 `src/data/{techniques,tools,facets}.json` plus `public/data/techniques.json`. Commit the result.
    106 
    107 `npm run data:enrich` reapplies the metadata pass without re-reading upstreams. It normalizes
    108 access labels, execution contexts, environments, availability, evidence state, and compatibility
    109 notes, then rebuilds the indexes. The catalog's bookmarks, saved views, density, font size, line
    110 wrapping, and reduced-motion preference stay in the browser's local storage.
    111 
    112 To refresh against the latest upstreams (submodule route):
    113 
    114 ```bash
    115 git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms
    116 npm run data
    117 ```
    118 
    119 ## 💜 Deploy
    120 
    121 The site is a static build hosted on **[Vercel](https://vercel.com)** at the domain root — no base
    122 path. Import the GitHub repo as a Vercel project (framework preset: **Astro**) and it deploys on
    123 every push to `main`; `vercel.json` pins the build:
    124 
    125 ```jsonc
    126 {
    127   "framework": "astro",
    128   "buildCommand": "npm run build",   // data:public + astro build + pagefind index
    129   "installCommand": "npm ci",
    130   "outputDirectory": "dist",
    131   "cleanUrls": true,
    132   "trailingSlash": false
    133 }
    134 ```
    135 
    136 `npm run build` runs Pagefind over `dist/` and copies the index back into `public/`, so offline
    137 search ships with the static output — no adapter, no serverless functions. Set the production origin
    138 in one place — `SITE` in `astro.config.mjs` (used for the sitemap, canonical URLs and Open Graph) —
    139 to the project's real Vercel domain (custom domain, or the default `*.vercel.app` URL).
    140 
    141 **Web Analytics / Speed Insights** are wired in `src/layouts/Base.astro` (production only, cookieless,
    142 zero-dependency) and light up once you enable them under the Vercel project's *Analytics* /
    143 *Speed Insights* tabs.
    144 
    145 Because there is no base path, `src/lib/url.ts`'s `url()` helper is a passthrough (it only guarantees
    146 a leading slash); if the site is ever moved back under a sub-path, set `base` in `astro.config.mjs`
    147 and every internal link already routes through `url()`.
    148 
    149 ## ❤️ Scope
    150 
    151 For authorized testing, CTFs, detection engineering and education only. Know your scope; get
    152 permission first.
    153 
    154 <div align="center">
    155 
    156 ---
    157 
    158 <sub>☧ **DΛΣMӨП//SEC** · built with Astro + Pagefind · themed with Rosé Pine · GPL-3.0 ❀</sub>
    159 
    160 </div>