daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

THIRD_PARTY_NOTICES.md (5392B)


      1 # Third-party notices
      2 
      3 DÆMONBins — the *Off-the-Land Almanac* — is a merged catalog built from four
      4 public, GPL-3.0-licensed living-off-the-land reference projects. Because all
      5 four upstreams are licensed under the **GNU General Public License v3.0**, the
      6 combined dataset and this site are a single **GPL-3.0** work. The full license
      7 text ships in [`LICENSE`](./LICENSE).
      8 
      9 Every technique row on the site shows its source, and every per-tool page links
     10 back to the upstream entry. The upstream repositories remain the canonical
     11 sources — please star them, contribute back, and report any inaccuracy upstream
     12 so the whole community benefits.
     13 
     14 The three repository snapshots are vendored under [`vendor/`](./vendor), while
     15 the LOOBins snapshot is committed under [`src/data/sources/`](./src/data/sources)
     16 (see
     17 [`scripts/setup-vendor.sh`](./scripts/setup-vendor.sh) to formalize them as
     18 submodules) and the normalized dataset is regenerated from them with
     19 `npm run data`.
     20 
     21 ---
     22 
     23 ## GTFOBins
     24 
     25 - **Project:** GTFOBins — Unix binaries that can be abused to bypass local
     26   security restrictions.
     27 - **Homepage:** https://gtfobins.github.io/
     28 - **Source:** https://github.com/GTFOBins/GTFOBins.github.io
     29 - **Created by:** Emilio Pinna (@norbemi) and the GTFOBins contributors.
     30 - **License:** GNU GPL-3.0 (`vendor/gtfobins/LICENSE`).
     31 - **Vendored at commit:** `acd5246`.
     32 - **What was done here:** each full binary's `functions[fn][i]` examples are
     33   expanded per context (`unprivileged` / `sudo` / `suid` / `capabilities`) into
     34   individual technique rows; SUID/sudo/capabilities contexts additionally flag
     35   Privilege Escalation; `inherit` entries resolve their `from:` binary to union
     36   the inherited capabilities. Alias-only files are recorded as aliases on their
     37   canonical tool. Function → capability and MITRE mappings follow
     38   `_data/functions.yml`.
     39 
     40 ## LOLBAS
     41 
     42 - **Project:** LOLBAS — Living Off The Land Binaries, Scripts and Libraries
     43   (Windows).
     44 - **Homepage:** https://lolbas-project.github.io/
     45 - **Source:** https://github.com/LOLBAS-Project/LOLBAS
     46 - **Created by:** Oddvar Moe (@oddvarmoe) and the LOLBAS contributors.
     47 - **License:** GNU GPL-3.0 (`vendor/lolbas/LICENSE`).
     48 - **Vendored at commit:** `7aca936`.
     49 - **What was done here:** each `Commands[i]` becomes a technique row carrying its
     50   Category → unified capability, `Full_Path`, `MitreID`, normalized privilege,
     51   and the flattened `Detection` (Sigma / Splunk / Elastic / IOC / …). The
     52   `HonorableMentions/` directory is skipped, matching upstream validation. The
     53   15-value Category enum is mapped verbatim to the unified capability vocabulary.
     54 
     55 ## WADComs
     56 
     57 - **Project:** WADComs — an interactive index of offensive tools/commands for
     58   Windows and Active Directory.
     59 - **Homepage:** https://wadcoms.github.io/
     60 - **Source:** https://github.com/WADComs/WADComs.github.io
     61 - **Created by:** John Woodman (@JohnWoodman15) and the WADComs contributors.
     62 - **License:** GNU GPL-3.0 (`vendor/wadcoms/LICENSE`).
     63 - **Vendored at commit:** `a864cd1`.
     64 - **What was done here:** the 100 upstream Jekyll entries are ingested verbatim;
     65   each `attack_types` value maps to a unified capability while every original
     66   label is kept in `nativeCategory`, `items`/`services` are preserved, and
     67   Active Directory scope is derived from the services/items each entry declares.
     68 
     69 ## LOOBins
     70 
     71 - **Project:** LOOBins — macOS living-off-the-land binaries and documented use cases.
     72 - **Homepage:** https://loobins.io/
     73 - **Source:** https://github.com/infosecB/LOOBins
     74 - **Created by:** LOOBins contributors.
     75 - **License:** GNU GPL-3.0 (`src/data/sources/loobins.json` records the upstream license).
     76 - **Imported at commit:** `399e3c4bdddb55c7dc49beb20bfe43490eac1184`.
     77 - **What was done here:** the pinned YAML snapshot is normalized into 183 technique rows;
     78   upstream names, descriptions, paths, references, detections, and macOS context are retained.
     79   These are labelled **Upstream reference**, not lab-tested results.
     80 
     81 ---
     82 
     83 ## DÆMON additions
     84 
     85 Beyond the three upstreams, DÆMONBins includes original material authored here
     86 and contributed **under the same GPL-3.0**, keeping the collection a single
     87 GPL-3.0 work. These rows carry `source: "DAEMON"`, are badged **NEW**, and filter
     88 under **Source = DÆMON**:
     89 
     90 - **134 Windows / Active Directory additions** — modern tradecraft the 2020-era
     91   WADComs snapshot lacked (AD CS / ESC abuse, coercion, modern Rubeus/Impacket
     92   ticketing, noPac/pre2k, ntlmrelayx/krbrelayx, bloodyAD/DACL, PowerView/GPO,
     93   mimikatz/DPAPI, potatoes, MSSQL, share hunting, offline cracking). Transcribed
     94   and fact-checked; each carries canonical references.
     95 - **A modernization backlog** — genuinely-missing 2024–2026 living-off-the-land
     96   techniques documented for detection and authorized testing, every one with a
     97   real, publicly-documented command and a canonical reference. No fabricated
     98   commands.
     99 
    100 Everything on the site is placeholder-only reference material (lab IPs,
    101 `test.local`, `john` / `password123`) in the same spirit as the upstreams and
    102 MITRE ATT&CK. For authorized testing, CTFs, detection engineering and education
    103 only.
    104 
    105 ---
    106 
    107 ## Build tooling
    108 
    109 The site is built with [Astro](https://astro.build) (MIT) and
    110 [Pagefind](https://pagefind.app) (MIT), themed with
    111 [Rosé Pine](https://rosepinetheme.com) (MIT), in the visual language of
    112 [daemon-sec.xyz](https://daemon-sec.xyz).