daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

import-loobins.mjs (2284B)


      1 // Import a checked-out upstream into a committed snapshot. Build/deploy is offline.
      2 import { readFileSync, readdirSync, writeFileSync, mkdirSync } from 'node:fs';
      3 import { resolve } from 'node:path';
      4 import { execFileSync } from 'node:child_process';
      5 import yaml from 'js-yaml';
      6 import { stableId } from './enrich-data.mjs';
      7 import { CAPABILITIES } from './technique-schema.mjs';
      8 
      9 const checkout = process.argv[2];
     10 if (!checkout) throw new Error('Usage: node scripts/import-loobins.mjs /path/to/LOOBins-checkout');
     11 const commit = execFileSync('git', ['-C', checkout, 'rev-parse', 'HEAD'], { encoding: 'utf8' }).trim();
     12 const http = u => typeof u === 'string' && /^https?:\/\/\S+$/.test(u);
     13 const techniques = [];
     14 for (const file of readdirSync(resolve(checkout, 'LOOBins')).filter(f => f.endsWith('.yml')).sort()) {
     15   const bin = yaml.load(readFileSync(resolve(checkout, 'LOOBins', file), 'utf8'));
     16   for (const use of bin.example_use_cases || []) {
     17     if (!use.code?.trim()) continue;
     18     const ref = `https://github.com/infosecB/LOOBins/blob/${commit}/LOOBins/${file}`;
     19     techniques.push({
     20       id: stableId(`loobins:${bin.name}`, `${use.name}\n${use.code}`),
     21       toolId: `loobins:${bin.name}`, toolName: bin.name, name: use.name.trim(), source: 'LOOBins',
     22       platform: ['macOS'], capability: (use.tactics || []).filter(t => CAPABILITIES.includes(t)), nativeCategory: use.tactics || [],
     23       command: use.code.trim(), description: use.description || bin.full_description,
     24       mitre: [], fullPath: bin.paths || [], environment: ['Local host'], availability: 'Built in',
     25       verification: 'Upstream reference', compatibility: 'Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.',
     26       detection: (bin.detections || []).map(d => ({ type: d.name, value: http(d.url) ? d.url : d.name })),
     27       references: [ref, ...(bin.resources || []).map(r => r.url).filter(http)],
     28     });
     29   }
     30 }
     31 mkdirSync('src/data/sources', { recursive: true });
     32 writeFileSync('src/data/sources/loobins.json', JSON.stringify({ repository: 'https://github.com/infosecB/LOOBins', commit, license: 'GPL-3.0', techniques }, null, 2) + '\n');
     33 console.log(`Imported ${techniques.length} use cases at ${commit}.`);