import-loobins.mjs (2284B)
1 // Import a checked-out upstream into a committed snapshot. Build/deploy is offline. 2 import { readFileSync, readdirSync, writeFileSync, mkdirSync } from 'node:fs'; 3 import { resolve } from 'node:path'; 4 import { execFileSync } from 'node:child_process'; 5 import yaml from 'js-yaml'; 6 import { stableId } from './enrich-data.mjs'; 7 import { CAPABILITIES } from './technique-schema.mjs'; 8 9 const checkout = process.argv[2]; 10 if (!checkout) throw new Error('Usage: node scripts/import-loobins.mjs /path/to/LOOBins-checkout'); 11 const commit = execFileSync('git', ['-C', checkout, 'rev-parse', 'HEAD'], { encoding: 'utf8' }).trim(); 12 const http = u => typeof u === 'string' && /^https?:\/\/\S+$/.test(u); 13 const techniques = []; 14 for (const file of readdirSync(resolve(checkout, 'LOOBins')).filter(f => f.endsWith('.yml')).sort()) { 15 const bin = yaml.load(readFileSync(resolve(checkout, 'LOOBins', file), 'utf8')); 16 for (const use of bin.example_use_cases || []) { 17 if (!use.code?.trim()) continue; 18 const ref = `https://github.com/infosecB/LOOBins/blob/${commit}/LOOBins/${file}`; 19 techniques.push({ 20 id: stableId(`loobins:${bin.name}`, `${use.name}\n${use.code}`), 21 toolId: `loobins:${bin.name}`, toolName: bin.name, name: use.name.trim(), source: 'LOOBins', 22 platform: ['macOS'], capability: (use.tactics || []).filter(t => CAPABILITIES.includes(t)), nativeCategory: use.tactics || [], 23 command: use.code.trim(), description: use.description || bin.full_description, 24 mitre: [], fullPath: bin.paths || [], environment: ['Local host'], availability: 'Built in', 25 verification: 'Upstream reference', compatibility: 'Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.', 26 detection: (bin.detections || []).map(d => ({ type: d.name, value: http(d.url) ? d.url : d.name })), 27 references: [ref, ...(bin.resources || []).map(r => r.url).filter(http)], 28 }); 29 } 30 } 31 mkdirSync('src/data/sources', { recursive: true }); 32 writeFileSync('src/data/sources/loobins.json', JSON.stringify({ repository: 'https://github.com/infosecB/LOOBins', commit, license: 'GPL-3.0', techniques }, null, 2) + '\n'); 33 console.log(`Imported ${techniques.length} use cases at ${commit}.`);