daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

curated-additions.mjs (7564B)


      1 // Maintained command references. These commands are displayed, never executed.
      2 const v = (key, label, value) => ({ key, label, default: value });
      3 const profile = v('profile', 'AWS profile', 'lab');
      4 const ns = v('namespace', 'Namespace', 'default');
      5 const project = v('project', 'GCP project', 'lab-project');
      6 const definitions = [
      7   ['aws-identity', 'aws', 'Identify the active AWS principal', 'AWS', 'aws sts get-caller-identity --profile {{profile}}', [profile], 'https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html', 'Returns the account ID, ARN and user ID for the credentials selected by this profile.', 'ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.'],
      8   ['aws-config', 'aws', 'Inspect AWS configuration sources', 'AWS', 'aws configure list --profile {{profile}}', [profile], 'https://docs.aws.amazon.com/cli/latest/reference/configure/list.html', 'Shows resolved configuration and where each value comes from; credentials are masked.', 'Environment variables can override profile configuration. Check the source column.'],
      9   ['aws-regions', 'aws', 'List enabled AWS regions', 'AWS', 'aws ec2 describe-regions --profile {{profile}} --region {{region}}', [profile, v('region', 'Region', 'eu-west-2')], 'https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html', 'Returns enabled region names and endpoints.', 'Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.'],
     10   ['azure-account', 'az', 'Inspect the active Azure subscription', 'Azure', 'az account show --output json', [], 'https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show', 'Shows the active subscription, tenant and account.', 'Run the authorised sign-in workflow if the CLI has no current account.'],
     11   ['azure-subscriptions', 'az', 'List accessible Azure subscriptions', 'Azure', 'az account list --output table', [], 'https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list', 'Shows subscriptions available to the current account.', 'A subscription list does not establish permissions on its resources.'],
     12   ['gcp-projects', 'gcloud', 'List accessible GCP projects', 'GCP', 'gcloud projects list --format=json', [], 'https://cloud.google.com/sdk/gcloud/reference/projects/list', 'Lists visible projects for the active account.', 'Service-account principal-set grants may not appear in this listing.'],
     13   ['gcp-config', 'gcloud', 'Inspect the active gcloud configuration', 'GCP', 'gcloud config list', [], 'https://cloud.google.com/sdk/gcloud/reference/config/list', 'Shows configured account, project and other properties.', 'Configured properties do not prove that the account has access to the selected project.'],
     14   ['gcp-policy', 'gcloud', 'Read a project IAM policy', 'GCP', 'gcloud projects get-iam-policy {{project}} --format=json', [project], 'https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy', 'Shows policy bindings visible to the current account.', 'Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.'],
     15   ['kube-context', 'kubectl', 'Check the current Kubernetes context', 'Containers', 'kubectl config current-context', [], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/', 'Prints the selected kubeconfig context without contacting the cluster.', 'An unset current context must be selected before cluster queries.'],
     16   ['kube-contexts', 'kubectl', 'List kubeconfig contexts', 'Containers', 'kubectl config get-contexts', [], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/', 'Shows configured clusters, identities and namespaces.', 'This lists local configuration, not proof of cluster connectivity or permission.'],
     17   ['kube-permissions', 'kubectl', 'Review permissions in a namespace', 'Containers', 'kubectl auth can-i --list --namespace {{namespace}}', [ns], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/', 'Returns the server-reported rules for the active identity in this namespace.', 'Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.'],
     18   ['kube-pod-permission', 'kubectl', 'Check permission to list pods', 'Containers', 'kubectl auth can-i list pods --namespace {{namespace}}', [ns], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/', 'Returns yes or no for this particular action.', 'The selected context and namespace determine which identity and resources are checked.'],
     19   ['nxc-modules', 'NetExec', 'List available SMB modules', 'Active Directory', 'nxc smb -L', [], 'https://www.netexec.wiki/getting-started/using-modules', 'Lists modules supported by the installed NetExec version.', 'Module names and options vary by release. Inspect module help before using a module.'],
     20   ['nxc-module-options', 'NetExec', 'Inspect options for an SMB module', 'Active Directory', 'nxc smb -M {{module}} --options', [v('module', 'Module', 'spider_plus')], 'https://www.netexec.wiki/getting-started/using-modules', 'Shows the selected module options.', 'This is module help, not a module run. Use the spelling reported by nxc smb -L.'],
     21   ['nxc-help', 'NetExec', 'Inspect SMB authentication and connection options', 'Active Directory', 'nxc smb --help', [], 'https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol', 'Shows flags supported by the installed SMB protocol implementation.', 'Use protocol-specific help because supported flags differ by protocol and version.'],
     22   ['certipy-find-help', 'Certipy', 'Inspect certificate discovery options', 'Active Directory', 'certipy find -h', [], 'https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference', 'Shows discovery, output and authentication options for the installed Certipy release.', 'Compare your installed release with the wiki before adapting an older example.'],
     23   ['certipy-version-help', 'Certipy', 'Inspect Certipy commands and version banner', 'Active Directory', 'certipy -h', [], 'https://github.com/ly4k/Certipy/wiki', 'Shows the installed command set and version banner.', 'The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.'],
     24 ];
     25 
     26 export const curatedAdditions = definitions.map(([id, tool, name, env, command, variables, ref, expected, troubleshooting]) => ({
     27   id: `daemon:reference:${id}`, toolId: tool === 'NetExec' || tool === 'Certipy' ? `wadcoms:${tool}` : `daemon:${tool}`,
     28   toolName: tool, name, source: 'DAEMON', platform: ['Linux', 'Windows', 'macOS'],
     29   environment: [env], capability: ['Discovery'], nativeCategory: ['Configuration and verification'],
     30   command: command.replace(/\{\{(\w+)\}\}/g, (_, k) => `'${variables.find(v => v.key === k).default}'`),
     31   template: variables.length ? { command, shell: 'posix', variables } : undefined,
     32   description: expected, expected, troubleshooting, sideEffects: 'No intentional configuration changes. Remote reads may generate audit events.',
     33   compatibility: 'Examples use POSIX shell quoting. Consult installed tool help for version-specific options.',
     34   requires: /^(aws|az|gcloud)/.test(tool) ? ['Authenticated CLI session'] : tool === 'kubectl' ? ['Kubeconfig'] : [],
     35   mitre: [], references: [ref], availability: 'Installed tool', verification: 'Documentation checked',
     36   reviewedAt: '2026-10-04', added: true,
     37 }));