THIRD_PARTY_NOTICES.md (5392B)
1 # Third-party notices 2 3 DÆMONBins — the *Off-the-Land Almanac* — is a merged catalog built from four 4 public, GPL-3.0-licensed living-off-the-land reference projects. Because all 5 four upstreams are licensed under the **GNU General Public License v3.0**, the 6 combined dataset and this site are a single **GPL-3.0** work. The full license 7 text ships in [`LICENSE`](./LICENSE). 8 9 Every technique row on the site shows its source, and every per-tool page links 10 back to the upstream entry. The upstream repositories remain the canonical 11 sources — please star them, contribute back, and report any inaccuracy upstream 12 so the whole community benefits. 13 14 The three repository snapshots are vendored under [`vendor/`](./vendor), while 15 the LOOBins snapshot is committed under [`src/data/sources/`](./src/data/sources) 16 (see 17 [`scripts/setup-vendor.sh`](./scripts/setup-vendor.sh) to formalize them as 18 submodules) and the normalized dataset is regenerated from them with 19 `npm run data`. 20 21 --- 22 23 ## GTFOBins 24 25 - **Project:** GTFOBins — Unix binaries that can be abused to bypass local 26 security restrictions. 27 - **Homepage:** https://gtfobins.github.io/ 28 - **Source:** https://github.com/GTFOBins/GTFOBins.github.io 29 - **Created by:** Emilio Pinna (@norbemi) and the GTFOBins contributors. 30 - **License:** GNU GPL-3.0 (`vendor/gtfobins/LICENSE`). 31 - **Vendored at commit:** `acd5246`. 32 - **What was done here:** each full binary's `functions[fn][i]` examples are 33 expanded per context (`unprivileged` / `sudo` / `suid` / `capabilities`) into 34 individual technique rows; SUID/sudo/capabilities contexts additionally flag 35 Privilege Escalation; `inherit` entries resolve their `from:` binary to union 36 the inherited capabilities. Alias-only files are recorded as aliases on their 37 canonical tool. Function → capability and MITRE mappings follow 38 `_data/functions.yml`. 39 40 ## LOLBAS 41 42 - **Project:** LOLBAS — Living Off The Land Binaries, Scripts and Libraries 43 (Windows). 44 - **Homepage:** https://lolbas-project.github.io/ 45 - **Source:** https://github.com/LOLBAS-Project/LOLBAS 46 - **Created by:** Oddvar Moe (@oddvarmoe) and the LOLBAS contributors. 47 - **License:** GNU GPL-3.0 (`vendor/lolbas/LICENSE`). 48 - **Vendored at commit:** `7aca936`. 49 - **What was done here:** each `Commands[i]` becomes a technique row carrying its 50 Category → unified capability, `Full_Path`, `MitreID`, normalized privilege, 51 and the flattened `Detection` (Sigma / Splunk / Elastic / IOC / …). The 52 `HonorableMentions/` directory is skipped, matching upstream validation. The 53 15-value Category enum is mapped verbatim to the unified capability vocabulary. 54 55 ## WADComs 56 57 - **Project:** WADComs — an interactive index of offensive tools/commands for 58 Windows and Active Directory. 59 - **Homepage:** https://wadcoms.github.io/ 60 - **Source:** https://github.com/WADComs/WADComs.github.io 61 - **Created by:** John Woodman (@JohnWoodman15) and the WADComs contributors. 62 - **License:** GNU GPL-3.0 (`vendor/wadcoms/LICENSE`). 63 - **Vendored at commit:** `a864cd1`. 64 - **What was done here:** the 100 upstream Jekyll entries are ingested verbatim; 65 each `attack_types` value maps to a unified capability while every original 66 label is kept in `nativeCategory`, `items`/`services` are preserved, and 67 Active Directory scope is derived from the services/items each entry declares. 68 69 ## LOOBins 70 71 - **Project:** LOOBins — macOS living-off-the-land binaries and documented use cases. 72 - **Homepage:** https://loobins.io/ 73 - **Source:** https://github.com/infosecB/LOOBins 74 - **Created by:** LOOBins contributors. 75 - **License:** GNU GPL-3.0 (`src/data/sources/loobins.json` records the upstream license). 76 - **Imported at commit:** `399e3c4bdddb55c7dc49beb20bfe43490eac1184`. 77 - **What was done here:** the pinned YAML snapshot is normalized into 183 technique rows; 78 upstream names, descriptions, paths, references, detections, and macOS context are retained. 79 These are labelled **Upstream reference**, not lab-tested results. 80 81 --- 82 83 ## DÆMON additions 84 85 Beyond the three upstreams, DÆMONBins includes original material authored here 86 and contributed **under the same GPL-3.0**, keeping the collection a single 87 GPL-3.0 work. These rows carry `source: "DAEMON"`, are badged **NEW**, and filter 88 under **Source = DÆMON**: 89 90 - **134 Windows / Active Directory additions** — modern tradecraft the 2020-era 91 WADComs snapshot lacked (AD CS / ESC abuse, coercion, modern Rubeus/Impacket 92 ticketing, noPac/pre2k, ntlmrelayx/krbrelayx, bloodyAD/DACL, PowerView/GPO, 93 mimikatz/DPAPI, potatoes, MSSQL, share hunting, offline cracking). Transcribed 94 and fact-checked; each carries canonical references. 95 - **A modernization backlog** — genuinely-missing 2024–2026 living-off-the-land 96 techniques documented for detection and authorized testing, every one with a 97 real, publicly-documented command and a canonical reference. No fabricated 98 commands. 99 100 Everything on the site is placeholder-only reference material (lab IPs, 101 `test.local`, `john` / `password123`) in the same spirit as the upstreams and 102 MITRE ATT&CK. For authorized testing, CTFs, detection engineering and education 103 only. 104 105 --- 106 107 ## Build tooling 108 109 The site is built with [Astro](https://astro.build) (MIT) and 110 [Pagefind](https://pagefind.app) (MIT), themed with 111 [Rosé Pine](https://rosepinetheme.com) (MIT), in the visual language of 112 [daemon-sec.xyz](https://daemon-sec.xyz).