daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

taxonomy.ts (5513B)


      1 // Single source of truth for DÆMONBins facet vocabulary + the hue each facet
      2 // wears. Accents are the site's theme-aware Rosé Pine semantic tokens
      3 // (--love/--iris/--pine/--foam/--gold/--rose), so a chip reads the same role
      4 // in Dawn and Night. Mirrors the cheatsheet's src/lib/taxonomy.ts pattern.
      5 
      6 export type Accent = 'love' | 'iris' | 'pine' | 'foam' | 'gold' | 'rose';
      7 export type Platform = 'Linux' | 'Windows' | 'macOS' | 'ActiveDirectory';
      8 export type SourceId = 'GTFOBins' | 'LOLBAS' | 'WADComs' | 'LOOBins' | 'DAEMON';
      9 
     10 export const PLATFORMS: Platform[] = ['Linux', 'Windows', 'macOS', 'ActiveDirectory'];
     11 export const SOURCES: SourceId[] = ['GTFOBins', 'LOLBAS', 'WADComs', 'LOOBins', 'DAEMON'];
     12 
     13 export const CAPABILITIES = [
     14   'Execution', 'Reverse/Bind Shell',
     15   'File Download', 'File Upload', 'File Read', 'File Write', 'File Copy',
     16   'Library Load', 'Compile',
     17   'Privilege Escalation', 'UAC Bypass', 'AWL / Policy Bypass',
     18   'Defense Evasion', 'Credential Access',
     19   'Discovery', 'Enumeration', 'Persistence', 'Lateral Movement', 'Collection',
     20 ] as const;
     21 export type Capability = (typeof CAPABILITIES)[number];
     22 
     23 export interface SourceDef {
     24   id: SourceId;
     25   label: string;
     26   tag: string;
     27   accent: Accent;
     28   blurb: string;
     29   homepage: string;
     30   repo: string;
     31   author: string;
     32   license: string;
     33 }
     34 
     35 export const SOURCE_META: Record<SourceId, SourceDef> = {
     36   LOOBins: {
     37     id: 'LOOBins', label: 'LOOBins', tag: 'ORCHARD', accent: 'rose',
     38     blurb: 'Native macOS binaries, with upstream use cases, paths, detection references and explicit compatibility notes.',
     39     homepage: 'https://loobins.io/', repo: 'https://github.com/infosecB/LOOBins',
     40     author: 'Brendan Chamberlain (@infosecB) & contributors', license: 'GPL-3.0',
     41   },
     42   GTFOBins: {
     43     id: 'GTFOBins', label: 'GTFOBins', tag: 'GTFO', accent: 'foam',
     44     blurb: 'Unix binaries abused to break out of restricted shells, read/write files, and escalate via SUID, sudo, and capabilities.',
     45     homepage: 'https://gtfobins.github.io/', repo: 'https://github.com/GTFOBins/GTFOBins.github.io',
     46     author: 'Emilio Pinna (@norbemi) & contributors', license: 'GPL-3.0',
     47   },
     48   LOLBAS: {
     49     id: 'LOLBAS', label: 'LOLBAS', tag: 'LOL', accent: 'iris',
     50     blurb: 'Windows living-off-the-land binaries, scripts, and libraries — signed and built-in tools for execution, download, and AWL bypass.',
     51     homepage: 'https://lolbas-project.github.io/', repo: 'https://github.com/LOLBAS-Project/LOLBAS',
     52     author: 'Oddvar Moe (@oddvarmoe) & contributors', license: 'GPL-3.0',
     53   },
     54   WADComs: {
     55     id: 'WADComs', label: 'WADComs', tag: 'WAD', accent: 'gold',
     56     blurb: 'Offensive tools and commands for Windows and Active Directory, indexed by what access you already hold.',
     57     homepage: 'https://wadcoms.github.io/', repo: 'https://github.com/WADComs/WADComs.github.io',
     58     author: 'John Woodman (@JohnWoodman15) & contributors', license: 'GPL-3.0',
     59   },
     60   DAEMON: {
     61     id: 'DAEMON', label: 'DÆMON', tag: 'DMN', accent: 'love',
     62     blurb: 'Authored command references for Windows, Active Directory, containers and cloud administration. Verification and prerequisites are recorded per entry.',
     63     homepage: 'https://daemon-sec.xyz', repo: 'https://github.com/DAEMON-404/daemon-sec-lotl',
     64     author: 'DÆMON (DAEMON-404)', license: 'GPL-3.0',
     65   },
     66 };
     67 
     68 export const PLATFORM_META: Record<Platform, { accent: Accent; short: string }> = {
     69   Linux: { accent: 'foam', short: 'NIX' },
     70   Windows: { accent: 'iris', short: 'WIN' },
     71   macOS: { accent: 'rose', short: 'MAC' },
     72   ActiveDirectory: { accent: 'gold', short: 'AD' },
     73 };
     74 
     75 export const CAPABILITY_META: Record<string, { accent: Accent }> = {
     76   Execution: { accent: 'love' },
     77   'Reverse/Bind Shell': { accent: 'love' },
     78   'File Download': { accent: 'foam' },
     79   'File Upload': { accent: 'foam' },
     80   'File Read': { accent: 'foam' },
     81   'File Write': { accent: 'foam' },
     82   'File Copy': { accent: 'foam' },
     83   'Library Load': { accent: 'foam' },
     84   Compile: { accent: 'foam' },
     85   'Privilege Escalation': { accent: 'gold' },
     86   'UAC Bypass': { accent: 'gold' },
     87   'AWL / Policy Bypass': { accent: 'iris' },
     88   'Defense Evasion': { accent: 'iris' },
     89   'Credential Access': { accent: 'rose' },
     90   Discovery: { accent: 'pine' },
     91   Enumeration: { accent: 'pine' },
     92   Persistence: { accent: 'pine' },
     93   'Lateral Movement': { accent: 'pine' },
     94   Collection: { accent: 'pine' },
     95 };
     96 
     97 export function accentOf(kind: 'platform' | 'capability' | 'source', value: string): Accent {
     98   if (kind === 'platform') return PLATFORM_META[value as Platform]?.accent ?? 'foam';
     99   if (kind === 'capability') return CAPABILITY_META[value]?.accent ?? 'foam';
    100   return SOURCE_META[value as SourceId]?.accent ?? 'foam';
    101 }
    102 
    103 /** Slug a source id for the /<source>/<tool> route prefix. */
    104 export const SOURCE_ROUTE: Record<SourceId, string> = {
    105   GTFOBins: 'gtfobins', LOLBAS: 'lolbas', WADComs: 'wadcoms', LOOBins: 'loobins', DAEMON: 'daemon',
    106 };
    107 
    108 // A tool's route deck is decided by its toolId NAMESPACE (the prefix before
    109 // ':'), never by a per-technique source — a wadcoms: family can hold both
    110 // upstream and daemon-authored techniques, and all of them must resolve to the
    111 // same page. The 134 daemon-authored WADComs additions live in the wadcoms:
    112 // namespace (they extend that collection); the daemon: namespace is the
    113 // standalone modernization backlog.
    114 export const NS_SOURCE: Record<string, SourceId> = {
    115   gtfo: 'GTFOBins', lolbas: 'LOLBAS', wadcoms: 'WADComs', loobins: 'LOOBins', daemon: 'DAEMON',
    116 };