taxonomy.ts (5513B)
1 // Single source of truth for DÆMONBins facet vocabulary + the hue each facet 2 // wears. Accents are the site's theme-aware Rosé Pine semantic tokens 3 // (--love/--iris/--pine/--foam/--gold/--rose), so a chip reads the same role 4 // in Dawn and Night. Mirrors the cheatsheet's src/lib/taxonomy.ts pattern. 5 6 export type Accent = 'love' | 'iris' | 'pine' | 'foam' | 'gold' | 'rose'; 7 export type Platform = 'Linux' | 'Windows' | 'macOS' | 'ActiveDirectory'; 8 export type SourceId = 'GTFOBins' | 'LOLBAS' | 'WADComs' | 'LOOBins' | 'DAEMON'; 9 10 export const PLATFORMS: Platform[] = ['Linux', 'Windows', 'macOS', 'ActiveDirectory']; 11 export const SOURCES: SourceId[] = ['GTFOBins', 'LOLBAS', 'WADComs', 'LOOBins', 'DAEMON']; 12 13 export const CAPABILITIES = [ 14 'Execution', 'Reverse/Bind Shell', 15 'File Download', 'File Upload', 'File Read', 'File Write', 'File Copy', 16 'Library Load', 'Compile', 17 'Privilege Escalation', 'UAC Bypass', 'AWL / Policy Bypass', 18 'Defense Evasion', 'Credential Access', 19 'Discovery', 'Enumeration', 'Persistence', 'Lateral Movement', 'Collection', 20 ] as const; 21 export type Capability = (typeof CAPABILITIES)[number]; 22 23 export interface SourceDef { 24 id: SourceId; 25 label: string; 26 tag: string; 27 accent: Accent; 28 blurb: string; 29 homepage: string; 30 repo: string; 31 author: string; 32 license: string; 33 } 34 35 export const SOURCE_META: Record<SourceId, SourceDef> = { 36 LOOBins: { 37 id: 'LOOBins', label: 'LOOBins', tag: 'ORCHARD', accent: 'rose', 38 blurb: 'Native macOS binaries, with upstream use cases, paths, detection references and explicit compatibility notes.', 39 homepage: 'https://loobins.io/', repo: 'https://github.com/infosecB/LOOBins', 40 author: 'Brendan Chamberlain (@infosecB) & contributors', license: 'GPL-3.0', 41 }, 42 GTFOBins: { 43 id: 'GTFOBins', label: 'GTFOBins', tag: 'GTFO', accent: 'foam', 44 blurb: 'Unix binaries abused to break out of restricted shells, read/write files, and escalate via SUID, sudo, and capabilities.', 45 homepage: 'https://gtfobins.github.io/', repo: 'https://github.com/GTFOBins/GTFOBins.github.io', 46 author: 'Emilio Pinna (@norbemi) & contributors', license: 'GPL-3.0', 47 }, 48 LOLBAS: { 49 id: 'LOLBAS', label: 'LOLBAS', tag: 'LOL', accent: 'iris', 50 blurb: 'Windows living-off-the-land binaries, scripts, and libraries — signed and built-in tools for execution, download, and AWL bypass.', 51 homepage: 'https://lolbas-project.github.io/', repo: 'https://github.com/LOLBAS-Project/LOLBAS', 52 author: 'Oddvar Moe (@oddvarmoe) & contributors', license: 'GPL-3.0', 53 }, 54 WADComs: { 55 id: 'WADComs', label: 'WADComs', tag: 'WAD', accent: 'gold', 56 blurb: 'Offensive tools and commands for Windows and Active Directory, indexed by what access you already hold.', 57 homepage: 'https://wadcoms.github.io/', repo: 'https://github.com/WADComs/WADComs.github.io', 58 author: 'John Woodman (@JohnWoodman15) & contributors', license: 'GPL-3.0', 59 }, 60 DAEMON: { 61 id: 'DAEMON', label: 'DÆMON', tag: 'DMN', accent: 'love', 62 blurb: 'Authored command references for Windows, Active Directory, containers and cloud administration. Verification and prerequisites are recorded per entry.', 63 homepage: 'https://daemon-sec.xyz', repo: 'https://github.com/DAEMON-404/daemon-sec-lotl', 64 author: 'DÆMON (DAEMON-404)', license: 'GPL-3.0', 65 }, 66 }; 67 68 export const PLATFORM_META: Record<Platform, { accent: Accent; short: string }> = { 69 Linux: { accent: 'foam', short: 'NIX' }, 70 Windows: { accent: 'iris', short: 'WIN' }, 71 macOS: { accent: 'rose', short: 'MAC' }, 72 ActiveDirectory: { accent: 'gold', short: 'AD' }, 73 }; 74 75 export const CAPABILITY_META: Record<string, { accent: Accent }> = { 76 Execution: { accent: 'love' }, 77 'Reverse/Bind Shell': { accent: 'love' }, 78 'File Download': { accent: 'foam' }, 79 'File Upload': { accent: 'foam' }, 80 'File Read': { accent: 'foam' }, 81 'File Write': { accent: 'foam' }, 82 'File Copy': { accent: 'foam' }, 83 'Library Load': { accent: 'foam' }, 84 Compile: { accent: 'foam' }, 85 'Privilege Escalation': { accent: 'gold' }, 86 'UAC Bypass': { accent: 'gold' }, 87 'AWL / Policy Bypass': { accent: 'iris' }, 88 'Defense Evasion': { accent: 'iris' }, 89 'Credential Access': { accent: 'rose' }, 90 Discovery: { accent: 'pine' }, 91 Enumeration: { accent: 'pine' }, 92 Persistence: { accent: 'pine' }, 93 'Lateral Movement': { accent: 'pine' }, 94 Collection: { accent: 'pine' }, 95 }; 96 97 export function accentOf(kind: 'platform' | 'capability' | 'source', value: string): Accent { 98 if (kind === 'platform') return PLATFORM_META[value as Platform]?.accent ?? 'foam'; 99 if (kind === 'capability') return CAPABILITY_META[value]?.accent ?? 'foam'; 100 return SOURCE_META[value as SourceId]?.accent ?? 'foam'; 101 } 102 103 /** Slug a source id for the /<source>/<tool> route prefix. */ 104 export const SOURCE_ROUTE: Record<SourceId, string> = { 105 GTFOBins: 'gtfobins', LOLBAS: 'lolbas', WADComs: 'wadcoms', LOOBins: 'loobins', DAEMON: 'daemon', 106 }; 107 108 // A tool's route deck is decided by its toolId NAMESPACE (the prefix before 109 // ':'), never by a per-technique source — a wadcoms: family can hold both 110 // upstream and daemon-authored techniques, and all of them must resolve to the 111 // same page. The 134 daemon-authored WADComs additions live in the wadcoms: 112 // namespace (they extend that collection); the daemon: namespace is the 113 // standalone modernization backlog. 114 export const NS_SOURCE: Record<string, SourceId> = { 115 gtfo: 'GTFOBins', lolbas: 'LOLBAS', wadcoms: 'WADComs', loobins: 'LOOBins', daemon: 'DAEMON', 116 };