catalog-additions.json (23328B)
1 [ 2 { 3 "id": "daemon:reference:aws-identity", 4 "toolId": "daemon:aws", 5 "toolName": "aws", 6 "name": "Identify the active AWS principal", 7 "source": "DAEMON", 8 "platform": [ 9 "Linux", 10 "Windows", 11 "macOS" 12 ], 13 "environment": [ 14 "AWS" 15 ], 16 "capability": [ 17 "Discovery" 18 ], 19 "nativeCategory": [ 20 "Configuration and verification" 21 ], 22 "command": "aws sts get-caller-identity --profile 'lab'", 23 "template": { 24 "command": "aws sts get-caller-identity --profile {{profile}}", 25 "shell": "posix", 26 "variables": [ 27 { 28 "key": "profile", 29 "label": "AWS profile", 30 "default": "lab" 31 } 32 ] 33 }, 34 "description": "Returns the account ID, ARN and user ID for the credentials selected by this profile.", 35 "expected": "Returns the account ID, ARN and user ID for the credentials selected by this profile.", 36 "troubleshooting": "ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.", 37 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 38 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 39 "requires": [ 40 "Authenticated CLI session" 41 ], 42 "mitre": [], 43 "references": [ 44 "https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html" 45 ], 46 "availability": "Installed tool", 47 "verification": "Documentation checked", 48 "reviewedAt": "2026-10-04", 49 "added": true 50 }, 51 { 52 "id": "daemon:reference:aws-config", 53 "toolId": "daemon:aws", 54 "toolName": "aws", 55 "name": "Inspect AWS configuration sources", 56 "source": "DAEMON", 57 "platform": [ 58 "Linux", 59 "Windows", 60 "macOS" 61 ], 62 "environment": [ 63 "AWS" 64 ], 65 "capability": [ 66 "Discovery" 67 ], 68 "nativeCategory": [ 69 "Configuration and verification" 70 ], 71 "command": "aws configure list --profile 'lab'", 72 "template": { 73 "command": "aws configure list --profile {{profile}}", 74 "shell": "posix", 75 "variables": [ 76 { 77 "key": "profile", 78 "label": "AWS profile", 79 "default": "lab" 80 } 81 ] 82 }, 83 "description": "Shows resolved configuration and where each value comes from; credentials are masked.", 84 "expected": "Shows resolved configuration and where each value comes from; credentials are masked.", 85 "troubleshooting": "Environment variables can override profile configuration. Check the source column.", 86 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 87 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 88 "requires": [ 89 "Authenticated CLI session" 90 ], 91 "mitre": [], 92 "references": [ 93 "https://docs.aws.amazon.com/cli/latest/reference/configure/list.html" 94 ], 95 "availability": "Installed tool", 96 "verification": "Documentation checked", 97 "reviewedAt": "2026-10-04", 98 "added": true 99 }, 100 { 101 "id": "daemon:reference:aws-regions", 102 "toolId": "daemon:aws", 103 "toolName": "aws", 104 "name": "List enabled AWS regions", 105 "source": "DAEMON", 106 "platform": [ 107 "Linux", 108 "Windows", 109 "macOS" 110 ], 111 "environment": [ 112 "AWS" 113 ], 114 "capability": [ 115 "Discovery" 116 ], 117 "nativeCategory": [ 118 "Configuration and verification" 119 ], 120 "command": "aws ec2 describe-regions --profile 'lab' --region 'eu-west-2'", 121 "template": { 122 "command": "aws ec2 describe-regions --profile {{profile}} --region {{region}}", 123 "shell": "posix", 124 "variables": [ 125 { 126 "key": "profile", 127 "label": "AWS profile", 128 "default": "lab" 129 }, 130 { 131 "key": "region", 132 "label": "Region", 133 "default": "eu-west-2" 134 } 135 ] 136 }, 137 "description": "Returns enabled region names and endpoints.", 138 "expected": "Returns enabled region names and endpoints.", 139 "troubleshooting": "Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.", 140 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 141 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 142 "requires": [ 143 "Authenticated CLI session" 144 ], 145 "mitre": [], 146 "references": [ 147 "https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html" 148 ], 149 "availability": "Installed tool", 150 "verification": "Documentation checked", 151 "reviewedAt": "2026-10-04", 152 "added": true 153 }, 154 { 155 "id": "daemon:reference:azure-account", 156 "toolId": "daemon:az", 157 "toolName": "az", 158 "name": "Inspect the active Azure subscription", 159 "source": "DAEMON", 160 "platform": [ 161 "Linux", 162 "Windows", 163 "macOS" 164 ], 165 "environment": [ 166 "Azure" 167 ], 168 "capability": [ 169 "Discovery" 170 ], 171 "nativeCategory": [ 172 "Configuration and verification" 173 ], 174 "command": "az account show --output json", 175 "description": "Shows the active subscription, tenant and account.", 176 "expected": "Shows the active subscription, tenant and account.", 177 "troubleshooting": "Run the authorised sign-in workflow if the CLI has no current account.", 178 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 179 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 180 "requires": [ 181 "Authenticated CLI session" 182 ], 183 "mitre": [], 184 "references": [ 185 "https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show" 186 ], 187 "availability": "Installed tool", 188 "verification": "Documentation checked", 189 "reviewedAt": "2026-10-04", 190 "added": true 191 }, 192 { 193 "id": "daemon:reference:azure-subscriptions", 194 "toolId": "daemon:az", 195 "toolName": "az", 196 "name": "List accessible Azure subscriptions", 197 "source": "DAEMON", 198 "platform": [ 199 "Linux", 200 "Windows", 201 "macOS" 202 ], 203 "environment": [ 204 "Azure" 205 ], 206 "capability": [ 207 "Discovery" 208 ], 209 "nativeCategory": [ 210 "Configuration and verification" 211 ], 212 "command": "az account list --output table", 213 "description": "Shows subscriptions available to the current account.", 214 "expected": "Shows subscriptions available to the current account.", 215 "troubleshooting": "A subscription list does not establish permissions on its resources.", 216 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 217 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 218 "requires": [ 219 "Authenticated CLI session" 220 ], 221 "mitre": [], 222 "references": [ 223 "https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list" 224 ], 225 "availability": "Installed tool", 226 "verification": "Documentation checked", 227 "reviewedAt": "2026-10-04", 228 "added": true 229 }, 230 { 231 "id": "daemon:reference:gcp-projects", 232 "toolId": "daemon:gcloud", 233 "toolName": "gcloud", 234 "name": "List accessible GCP projects", 235 "source": "DAEMON", 236 "platform": [ 237 "Linux", 238 "Windows", 239 "macOS" 240 ], 241 "environment": [ 242 "GCP" 243 ], 244 "capability": [ 245 "Discovery" 246 ], 247 "nativeCategory": [ 248 "Configuration and verification" 249 ], 250 "command": "gcloud projects list --format=json", 251 "description": "Lists visible projects for the active account.", 252 "expected": "Lists visible projects for the active account.", 253 "troubleshooting": "Service-account principal-set grants may not appear in this listing.", 254 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 255 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 256 "requires": [ 257 "Authenticated CLI session" 258 ], 259 "mitre": [], 260 "references": [ 261 "https://cloud.google.com/sdk/gcloud/reference/projects/list" 262 ], 263 "availability": "Installed tool", 264 "verification": "Documentation checked", 265 "reviewedAt": "2026-10-04", 266 "added": true 267 }, 268 { 269 "id": "daemon:reference:gcp-config", 270 "toolId": "daemon:gcloud", 271 "toolName": "gcloud", 272 "name": "Inspect the active gcloud configuration", 273 "source": "DAEMON", 274 "platform": [ 275 "Linux", 276 "Windows", 277 "macOS" 278 ], 279 "environment": [ 280 "GCP" 281 ], 282 "capability": [ 283 "Discovery" 284 ], 285 "nativeCategory": [ 286 "Configuration and verification" 287 ], 288 "command": "gcloud config list", 289 "description": "Shows configured account, project and other properties.", 290 "expected": "Shows configured account, project and other properties.", 291 "troubleshooting": "Configured properties do not prove that the account has access to the selected project.", 292 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 293 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 294 "requires": [ 295 "Authenticated CLI session" 296 ], 297 "mitre": [], 298 "references": [ 299 "https://cloud.google.com/sdk/gcloud/reference/config/list" 300 ], 301 "availability": "Installed tool", 302 "verification": "Documentation checked", 303 "reviewedAt": "2026-10-04", 304 "added": true 305 }, 306 { 307 "id": "daemon:reference:gcp-policy", 308 "toolId": "daemon:gcloud", 309 "toolName": "gcloud", 310 "name": "Read a project IAM policy", 311 "source": "DAEMON", 312 "platform": [ 313 "Linux", 314 "Windows", 315 "macOS" 316 ], 317 "environment": [ 318 "GCP" 319 ], 320 "capability": [ 321 "Discovery" 322 ], 323 "nativeCategory": [ 324 "Configuration and verification" 325 ], 326 "command": "gcloud projects get-iam-policy 'lab-project' --format=json", 327 "template": { 328 "command": "gcloud projects get-iam-policy {{project}} --format=json", 329 "shell": "posix", 330 "variables": [ 331 { 332 "key": "project", 333 "label": "GCP project", 334 "default": "lab-project" 335 } 336 ] 337 }, 338 "description": "Shows policy bindings visible to the current account.", 339 "expected": "Shows policy bindings visible to the current account.", 340 "troubleshooting": "Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.", 341 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 342 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 343 "requires": [ 344 "Authenticated CLI session" 345 ], 346 "mitre": [], 347 "references": [ 348 "https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy" 349 ], 350 "availability": "Installed tool", 351 "verification": "Documentation checked", 352 "reviewedAt": "2026-10-04", 353 "added": true 354 }, 355 { 356 "id": "daemon:reference:kube-context", 357 "toolId": "daemon:kubectl", 358 "toolName": "kubectl", 359 "name": "Check the current Kubernetes context", 360 "source": "DAEMON", 361 "platform": [ 362 "Linux", 363 "Windows", 364 "macOS" 365 ], 366 "environment": [ 367 "Containers" 368 ], 369 "capability": [ 370 "Discovery" 371 ], 372 "nativeCategory": [ 373 "Configuration and verification" 374 ], 375 "command": "kubectl config current-context", 376 "description": "Prints the selected kubeconfig context without contacting the cluster.", 377 "expected": "Prints the selected kubeconfig context without contacting the cluster.", 378 "troubleshooting": "An unset current context must be selected before cluster queries.", 379 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 380 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 381 "requires": [ 382 "Kubeconfig" 383 ], 384 "mitre": [], 385 "references": [ 386 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/" 387 ], 388 "availability": "Installed tool", 389 "verification": "Documentation checked", 390 "reviewedAt": "2026-10-04", 391 "added": true 392 }, 393 { 394 "id": "daemon:reference:kube-contexts", 395 "toolId": "daemon:kubectl", 396 "toolName": "kubectl", 397 "name": "List kubeconfig contexts", 398 "source": "DAEMON", 399 "platform": [ 400 "Linux", 401 "Windows", 402 "macOS" 403 ], 404 "environment": [ 405 "Containers" 406 ], 407 "capability": [ 408 "Discovery" 409 ], 410 "nativeCategory": [ 411 "Configuration and verification" 412 ], 413 "command": "kubectl config get-contexts", 414 "description": "Shows configured clusters, identities and namespaces.", 415 "expected": "Shows configured clusters, identities and namespaces.", 416 "troubleshooting": "This lists local configuration, not proof of cluster connectivity or permission.", 417 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 418 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 419 "requires": [ 420 "Kubeconfig" 421 ], 422 "mitre": [], 423 "references": [ 424 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/" 425 ], 426 "availability": "Installed tool", 427 "verification": "Documentation checked", 428 "reviewedAt": "2026-10-04", 429 "added": true 430 }, 431 { 432 "id": "daemon:reference:kube-permissions", 433 "toolId": "daemon:kubectl", 434 "toolName": "kubectl", 435 "name": "Review permissions in a namespace", 436 "source": "DAEMON", 437 "platform": [ 438 "Linux", 439 "Windows", 440 "macOS" 441 ], 442 "environment": [ 443 "Containers" 444 ], 445 "capability": [ 446 "Discovery" 447 ], 448 "nativeCategory": [ 449 "Configuration and verification" 450 ], 451 "command": "kubectl auth can-i --list --namespace 'default'", 452 "template": { 453 "command": "kubectl auth can-i --list --namespace {{namespace}}", 454 "shell": "posix", 455 "variables": [ 456 { 457 "key": "namespace", 458 "label": "Namespace", 459 "default": "default" 460 } 461 ] 462 }, 463 "description": "Returns the server-reported rules for the active identity in this namespace.", 464 "expected": "Returns the server-reported rules for the active identity in this namespace.", 465 "troubleshooting": "Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.", 466 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 467 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 468 "requires": [ 469 "Kubeconfig" 470 ], 471 "mitre": [], 472 "references": [ 473 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/" 474 ], 475 "availability": "Installed tool", 476 "verification": "Documentation checked", 477 "reviewedAt": "2026-10-04", 478 "added": true 479 }, 480 { 481 "id": "daemon:reference:kube-pod-permission", 482 "toolId": "daemon:kubectl", 483 "toolName": "kubectl", 484 "name": "Check permission to list pods", 485 "source": "DAEMON", 486 "platform": [ 487 "Linux", 488 "Windows", 489 "macOS" 490 ], 491 "environment": [ 492 "Containers" 493 ], 494 "capability": [ 495 "Discovery" 496 ], 497 "nativeCategory": [ 498 "Configuration and verification" 499 ], 500 "command": "kubectl auth can-i list pods --namespace 'default'", 501 "template": { 502 "command": "kubectl auth can-i list pods --namespace {{namespace}}", 503 "shell": "posix", 504 "variables": [ 505 { 506 "key": "namespace", 507 "label": "Namespace", 508 "default": "default" 509 } 510 ] 511 }, 512 "description": "Returns yes or no for this particular action.", 513 "expected": "Returns yes or no for this particular action.", 514 "troubleshooting": "The selected context and namespace determine which identity and resources are checked.", 515 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 516 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 517 "requires": [ 518 "Kubeconfig" 519 ], 520 "mitre": [], 521 "references": [ 522 "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/" 523 ], 524 "availability": "Installed tool", 525 "verification": "Documentation checked", 526 "reviewedAt": "2026-10-04", 527 "added": true 528 }, 529 { 530 "id": "daemon:reference:nxc-modules", 531 "toolId": "wadcoms:NetExec", 532 "toolName": "NetExec", 533 "name": "List available SMB modules", 534 "source": "DAEMON", 535 "platform": [ 536 "Linux", 537 "Windows", 538 "macOS" 539 ], 540 "environment": [ 541 "Active Directory" 542 ], 543 "capability": [ 544 "Discovery" 545 ], 546 "nativeCategory": [ 547 "Configuration and verification" 548 ], 549 "command": "nxc smb -L", 550 "description": "Lists modules supported by the installed NetExec version.", 551 "expected": "Lists modules supported by the installed NetExec version.", 552 "troubleshooting": "Module names and options vary by release. Inspect module help before using a module.", 553 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 554 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 555 "requires": [], 556 "mitre": [], 557 "references": [ 558 "https://www.netexec.wiki/getting-started/using-modules" 559 ], 560 "availability": "Installed tool", 561 "verification": "Documentation checked", 562 "reviewedAt": "2026-10-04", 563 "added": true 564 }, 565 { 566 "id": "daemon:reference:nxc-module-options", 567 "toolId": "wadcoms:NetExec", 568 "toolName": "NetExec", 569 "name": "Inspect options for an SMB module", 570 "source": "DAEMON", 571 "platform": [ 572 "Linux", 573 "Windows", 574 "macOS" 575 ], 576 "environment": [ 577 "Active Directory" 578 ], 579 "capability": [ 580 "Discovery" 581 ], 582 "nativeCategory": [ 583 "Configuration and verification" 584 ], 585 "command": "nxc smb -M 'spider_plus' --options", 586 "template": { 587 "command": "nxc smb -M {{module}} --options", 588 "shell": "posix", 589 "variables": [ 590 { 591 "key": "module", 592 "label": "Module", 593 "default": "spider_plus" 594 } 595 ] 596 }, 597 "description": "Shows the selected module options.", 598 "expected": "Shows the selected module options.", 599 "troubleshooting": "This is module help, not a module run. Use the spelling reported by nxc smb -L.", 600 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 601 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 602 "requires": [], 603 "mitre": [], 604 "references": [ 605 "https://www.netexec.wiki/getting-started/using-modules" 606 ], 607 "availability": "Installed tool", 608 "verification": "Documentation checked", 609 "reviewedAt": "2026-10-04", 610 "added": true 611 }, 612 { 613 "id": "daemon:reference:nxc-help", 614 "toolId": "wadcoms:NetExec", 615 "toolName": "NetExec", 616 "name": "Inspect SMB authentication and connection options", 617 "source": "DAEMON", 618 "platform": [ 619 "Linux", 620 "Windows", 621 "macOS" 622 ], 623 "environment": [ 624 "Active Directory" 625 ], 626 "capability": [ 627 "Discovery" 628 ], 629 "nativeCategory": [ 630 "Configuration and verification" 631 ], 632 "command": "nxc smb --help", 633 "description": "Shows flags supported by the installed SMB protocol implementation.", 634 "expected": "Shows flags supported by the installed SMB protocol implementation.", 635 "troubleshooting": "Use protocol-specific help because supported flags differ by protocol and version.", 636 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 637 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 638 "requires": [], 639 "mitre": [], 640 "references": [ 641 "https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol" 642 ], 643 "availability": "Installed tool", 644 "verification": "Documentation checked", 645 "reviewedAt": "2026-10-04", 646 "added": true 647 }, 648 { 649 "id": "daemon:reference:certipy-find-help", 650 "toolId": "wadcoms:Certipy", 651 "toolName": "Certipy", 652 "name": "Inspect certificate discovery options", 653 "source": "DAEMON", 654 "platform": [ 655 "Linux", 656 "Windows", 657 "macOS" 658 ], 659 "environment": [ 660 "Active Directory" 661 ], 662 "capability": [ 663 "Discovery" 664 ], 665 "nativeCategory": [ 666 "Configuration and verification" 667 ], 668 "command": "certipy find -h", 669 "description": "Shows discovery, output and authentication options for the installed Certipy release.", 670 "expected": "Shows discovery, output and authentication options for the installed Certipy release.", 671 "troubleshooting": "Compare your installed release with the wiki before adapting an older example.", 672 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 673 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 674 "requires": [], 675 "mitre": [], 676 "references": [ 677 "https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference" 678 ], 679 "availability": "Installed tool", 680 "verification": "Documentation checked", 681 "reviewedAt": "2026-10-04", 682 "added": true 683 }, 684 { 685 "id": "daemon:reference:certipy-version-help", 686 "toolId": "wadcoms:Certipy", 687 "toolName": "Certipy", 688 "name": "Inspect Certipy commands and version banner", 689 "source": "DAEMON", 690 "platform": [ 691 "Linux", 692 "Windows", 693 "macOS" 694 ], 695 "environment": [ 696 "Active Directory" 697 ], 698 "capability": [ 699 "Discovery" 700 ], 701 "nativeCategory": [ 702 "Configuration and verification" 703 ], 704 "command": "certipy -h", 705 "description": "Shows the installed command set and version banner.", 706 "expected": "Shows the installed command set and version banner.", 707 "troubleshooting": "The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.", 708 "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", 709 "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", 710 "requires": [], 711 "mitre": [], 712 "references": [ 713 "https://github.com/ly4k/Certipy/wiki" 714 ], 715 "availability": "Installed tool", 716 "verification": "Documentation checked", 717 "reviewedAt": "2026-10-04", 718 "added": true 719 } 720 ]