README.md (8260B)
1 <div align="center"> 2 3 # ☧ DÆMONBins 4 5 ### the Off-the-Land Almanac 6 7 https://daemon-sec-lotl.vercel.app/ 8 9 https://daemon-404.github.io/daemon-sec-lotl/ 10 11 *GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, and extended into one filterable catalog.* 12 13 <br> 14 15 [](./LICENSE) 16 [](https://astro.build) 17 [](https://pagefind.app) 18 [](https://lotl.daemon-sec.xyz/) 19 [](https://rosepinetheme.com) 20 21 [](https://lotl.daemon-sec.xyz/catalog) 22 [](https://lotl.daemon-sec.xyz/catalog) 23 [](https://lotl.daemon-sec.xyz/daemon) 24 [](#the-five-collections) 25 26 **[ Open the catalog → ](https://lotl.daemon-sec.xyz/catalog)** 27 28 </div> 29 30 --- 31 32 A static [Astro](https://astro.build) site with [Pagefind](https://pagefind.app) search, in the 33 visual language of [daemon-sec.xyz](https://daemon-sec.xyz). Every living-off-the-land and 34 offensive technique from four public references is flattened to one filterable atom — a 35 **Technique** — and filterable by **platform**, **capability**, **source**, **execution context**, 36 **required access**, **service**, **environment**, **availability**, and **evidence state**. The 37 catalog supports grouped variants, saved commands, configurable templates, shareable URL state, 38 and a compact details inspector. Per-tool pages group a binary's techniques. 39 40 All four upstreams are GPL-3.0, so this combined work is **GPL-3.0**. See 41 [`THIRD_PARTY_NOTICES.md`](./THIRD_PARTY_NOTICES.md) and [`LICENSE`](./LICENSE). 42 43 ## ❀ The five collections 44 45 | Deck | Source | Techniques | What it is | 46 |---|---|--:|---| 47 | 🩵 **GTFOBins** | `acd5246` | 2,125 | Unix binaries abused for shell, file r/w, and SUID / sudo / capabilities privesc | 48 | 💜 **LOLBAS** | `7aca936` | 481 | Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass | 49 | 💛 **WADComs** | `a864cd1` | 100 | Offensive Windows / Active Directory tooling, indexed by what access you hold | 50 | 🩷 **LOOBins** | `399e3c4` | 183 | macOS binaries and documented use cases | 51 | ❤️ **DÆMON** | *authored* | 196 | 134 fact-checked WADComs additions + 17 documented command references, badged **DÆMON** | 52 | | **Total** | **3,085** | **907 tools · all Zod-validated** | 53 54 Everything is placeholder-only reference material (lab IPs, `test.local`, `john` / `password123`) 55 in the spirit of GTFOBins, LOLBAS, WADComs, LOOBins and MITRE ATT&CK. 56 57 ## ☧ Layout 58 59 ``` 60 vendor/{gtfobins,lolbas,wadcoms} the three upstreams (vendored; see setup-vendor.sh) 61 src/data/sources/loobins.json pinned LOOBins snapshot (183 use cases) 62 src/data/sources/wadcoms-additions.json committed authored WADComs snapshot 63 scripts/build-dataset.mjs local ingestion → src/data/*.json + public/data 64 scripts/wadcoms-normalize.mjs WADComs family fixes (Impacket split, case-fold) 65 scripts/split-impacket.mjs one-shot, idempotent migration of the committed data 66 src/data/techniques.json the canonical, committed dataset (a Technique[]) 67 src/data/tools.json per-tool metadata (aliases, Full_Path, contributors) 68 src/data/facets.json derived facet indexes + counts + upstream commits 69 src/data/catalog-additions.json documented DÆMON command references 70 src/pages/ home · /catalog · /<deck> · /<deck>/<tool> · credits · 404 71 src/scripts/catalog.ts the vanilla-TS catalog workspace island 72 src/lib/{taxonomy,techniques,highlight,url}.ts shared vocabulary + pure logic 73 src/styles, src/components, src/fonts design system (cloned from the cheatsheet) 74 ``` 75 76 Routing is by toolId **namespace** (`gtfo:`/`lolbas:`/`wadcoms:`/`daemon:`), so a tool always 77 resolves to one page even when a family mixes upstream and DÆMON-authored techniques; a 78 per-technique NEW badge conveys authorship. 79 80 **Impacket** is a *suite*, not one tool, so its ~48 WADComs techniques are split back out by their 81 actual `examples/<script>.py` — one page per script (`Impacket-secretsdump`, `Impacket-ntlmrelayx`, 82 …). Case-duplicate WADComs families (e.g. `Enum4Linux` / `enum4linux`) are folded onto one canonical 83 page so the static router never silently drops a tool. Both normalisations live in 84 `scripts/wadcoms-normalize.mjs` and are applied by `npm run data` and the one-shot 85 `scripts/split-impacket.mjs`. 86 87 ## 🩵 Develop 88 89 ```bash 90 npm install 91 npm run data # regenerate the dataset from vendor/ + committed source snapshots 92 npm run dev # local dev server 93 npm run build # astro build + pagefind index → dist/ 94 npm run preview # serve the production build 95 ``` 96 97 `npm run build` (what CI runs) only consumes the committed `src/data/techniques.json`; it never 98 re-runs ingestion, so there is no cross-repo dependency at deploy time. 99 100 ## 💛 Regenerating the dataset 101 102 `npm run data` reads the vendored upstreams, the committed authored snapshots in 103 `src/data/sources/`, and `src/data/catalog-additions.json`. It normalizes everything to the unified `Technique` model, 104 validates every record with Zod (failing on any bad or duplicate record), and writes 105 `src/data/{techniques,tools,facets}.json` plus `public/data/techniques.json`. Commit the result. 106 107 `npm run data:enrich` reapplies the metadata pass without re-reading upstreams. It normalizes 108 access labels, execution contexts, environments, availability, evidence state, and compatibility 109 notes, then rebuilds the indexes. The catalog's bookmarks, saved views, density, font size, line 110 wrapping, and reduced-motion preference stay in the browser's local storage. 111 112 To refresh against the latest upstreams (submodule route): 113 114 ```bash 115 git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms 116 npm run data 117 ``` 118 119 ## 💜 Deploy 120 121 The site is a static build hosted on **[Vercel](https://vercel.com)** at the domain root — no base 122 path. Import the GitHub repo as a Vercel project (framework preset: **Astro**) and it deploys on 123 every push to `main`; `vercel.json` pins the build: 124 125 ```jsonc 126 { 127 "framework": "astro", 128 "buildCommand": "npm run build", // data:public + astro build + pagefind index 129 "installCommand": "npm ci", 130 "outputDirectory": "dist", 131 "cleanUrls": true, 132 "trailingSlash": false 133 } 134 ``` 135 136 `npm run build` runs Pagefind over `dist/` and copies the index back into `public/`, so offline 137 search ships with the static output — no adapter, no serverless functions. Set the production origin 138 in one place — `SITE` in `astro.config.mjs` (used for the sitemap, canonical URLs and Open Graph) — 139 to the project's real Vercel domain (custom domain, or the default `*.vercel.app` URL). 140 141 **Web Analytics / Speed Insights** are wired in `src/layouts/Base.astro` (production only, cookieless, 142 zero-dependency) and light up once you enable them under the Vercel project's *Analytics* / 143 *Speed Insights* tabs. 144 145 Because there is no base path, `src/lib/url.ts`'s `url()` helper is a passthrough (it only guarantees 146 a leading slash); if the site is ever moved back under a sub-path, set `base` in `astro.config.mjs` 147 and every internal link already routes through `url()`. 148 149 ## ❤️ Scope 150 151 For authorized testing, CTFs, detection engineering and education only. Know your scope; get 152 permission first. 153 154 <div align="center"> 155 156 --- 157 158 <sub>☧ **DΛΣMӨП//SEC** · built with Astro + Pagefind · themed with Rosé Pine · GPL-3.0 ❀</sub> 159 160 </div>