daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

credits.astro (6144B)


      1 ---
      2 import Base from '../layouts/Base.astro';
      3 import SlantTitle from '../components/SlantTitle.astro';
      4 import facets from '../data/facets.json';
      5 import { SOURCE_META } from '../lib/taxonomy';
      6 import { dataset } from '../lib/jsonld';
      7 
      8 const c = facets.counts;
      9 const commits = facets.commits as Record<string, string>;
     10 
     11 const CREDITS = [
     12   {
     13     id: 'LOOBins', commit: commits.loobins,
     14     what: 'Each upstream macOS use case becomes a separate command record. Original names, descriptions, paths and detection references are retained. Tactics outside the catalog capability vocabulary remain in nativeCategory. Imported examples are not labelled as lab tested.',
     15     count: c.bySource.LOOBins,
     16   },
     17   {
     18     id: 'GTFOBins', commit: commits.gtfobins,
     19     what: 'Every full binary is expanded per function × example × context into individual technique rows; SUID / sudo / capabilities contexts also flag Privilege Escalation; `inherit` entries resolve their `from:` binary to union the inherited capabilities.',
     20     count: c.bySource.GTFOBins,
     21   },
     22   {
     23     id: 'LOLBAS', commit: commits.lolbas,
     24     what: 'Each command becomes a row carrying its Category → unified capability, Full_Path, MITRE id, and the flattened Detection (Sigma / Splunk / Elastic / IOC). HonorableMentions are skipped, matching upstream validation.',
     25     count: c.bySource.LOLBAS,
     26   },
     27   {
     28     id: 'WADComs', commit: commits.wadcoms,
     29     what: 'The 100 upstream entries are ingested verbatim from the Jekyll collection; attack_types map to unified capabilities while every original label is kept, and AD scope is derived from the services/items each entry declares.',
     30     count: c.bySource.WADComs,
     31   },
     32 ];
     33 ---
     34 <Base
     35   title="Credits & Licenses — DÆMONBins"
     36   description="Attribution and GPL-3.0 licensing for GTFOBins, LOLBAS, WADComs and LOOBins, the four projects merged into DÆMONBins, plus the DÆMON additions."
     37   jsonLd={dataset(Astro.site, c, commits)}
     38 >
     39   <div class="wrap prose credits" style="max-width:60rem; padding: 2rem 0 5rem;">
     40     <SlantTitle eyebrow="05 · Credits" title="Credits & Licenses" tone="gold" />
     41 
     42     <p style="margin-top:2rem;">
     43       DÆMONBins combines four public, GPL-3.0 command references. All four are
     44       licensed under the GNU GPL-3.0, so this combined dataset and site are a single GPL-3.0 work.
     45       Every technique row shows its source, and per-tool pages link back to the upstream entry.
     46     </p>
     47 
     48     {CREDITS.map((cr) => {
     49       const s = SOURCE_META[cr.id as keyof typeof SOURCE_META];
     50       return (
     51         <section class="credit">
     52           <h2>{s.label}</h2>
     53           <p>{s.blurb}</p>
     54           <div class="slab corners provenance" style={`--acc: var(--${s.accent});`}>
     55             <p class="micro provenance__label">// provenance · {s.tag}</p>
     56             <ul>
     57               <li><strong>Upstream:</strong> <a href={s.repo} target="_blank" rel="noopener">{s.repo.replace(/^https?:\/\//, '')}</a></li>
     58               <li><strong>Created by:</strong> {s.author}</li>
     59               <li><strong>License:</strong> {s.license}</li>
     60               {cr.commit && <li><strong>Merged at commit:</strong> <code>{cr.commit}</code></li>}
     61               <li><strong>Rows here:</strong> {cr.count}</li>
     62               <li><strong>What changed:</strong> {cr.what}</li>
     63             </ul>
     64           </div>
     65         </section>
     66       );
     67     })}
     68 
     69     <section class="credit">
     70       <h2>DÆMON additions</h2>
     71       <p>{SOURCE_META.DAEMON.blurb}</p>
     72       <div class="slab corners provenance" style="--acc: var(--love);">
     73         <p class="micro provenance__label">// provenance · DMN</p>
     74         <ul>
     75           <li><strong>Authored by:</strong> {SOURCE_META.DAEMON.author}</li>
     76           <li><strong>License:</strong> GPL-3.0 — contributed under the same license as the upstreams, keeping the collection a single GPL-3.0 work.</li>
     77           <li><strong>Rows here:</strong> {c.added} (labelled <span class="tag-new">DÆMON</span>, filterable under Source = DÆMON; authorship does not indicate recency)</li>
     78           <li><strong>Provenance rule:</strong> the 134 Windows/AD additions were transcribed and fact-checked; the modernization backlog documents only real, publicly-referenced commands, each with a canonical source. No fabricated commands.</li>
     79         </ul>
     80       </div>
     81     </section>
     82 
     83     <h2>This site</h2>
     84     <p>GTFOBins commands carry Linux compatibility until their exact macOS syntax and context are checked. Native macOS references come from LOOBins. “Documentation checked” means the cited documentation was reviewed; “Upstream reference” means imported reference material. Neither label claims a successful lab run.</p>
     85     <p>
     86       Built with <a href="https://astro.build" target="_blank" rel="noopener">Astro</a> and
     87       <a href="https://pagefind.app" target="_blank" rel="noopener">Pagefind</a>, themed with
     88       <a href="https://rosepinetheme.com" target="_blank" rel="noopener">Rosé Pine</a>, in the visual
     89       language of <a href="https://daemon-sec.xyz" target="_blank" rel="noopener">daemon-sec.xyz</a>.
     90       Full licensing is in <code>THIRD_PARTY_NOTICES.md</code>; the site is licensed
     91       <a href="https://www.gnu.org/licenses/gpl-3.0.en.html" target="_blank" rel="noopener">GPL-3.0</a>.
     92     </p>
     93 
     94     <p class="muted" style="margin-top:2rem;border-top:1px solid var(--rule);padding-top:1rem;">
     95       For authorized testing, CTFs, detection engineering and education only. Know your scope.
     96       If any upstream author would prefer a change, open an issue on the site repository and it will be honoured.
     97     </p>
     98   </div>
     99 </Base>
    100 
    101 <style>
    102   .credit { margin: 2.5rem 0; }
    103   .provenance { padding: 1.1rem 1.3rem; }
    104   .provenance__label { color: var(--fg-faint); margin: 0 0 0.6rem; }
    105   .provenance ul { list-style: none; margin: 0; padding: 0; display: grid; gap: 0.4rem; }
    106   .provenance li { font-size: 14px; line-height: 1.55; }
    107   .provenance strong { color: var(--fg); }
    108   .provenance a { color: var(--accent); }
    109   .tag-new { font-family: var(--font-mono); font-size: 9.5px; background: var(--love); color: var(--base); padding: 0.05rem 0.35rem; letter-spacing: 0.08em; }
    110 </style>