daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

wadcoms.test.mjs (1934B)


      1 import { test } from 'node:test';
      2 import assert from 'node:assert/strict';
      3 import { impacketScript, splitImpacket, canonicalizeFamilyCase } from '../scripts/wadcoms-normalize.mjs';
      4 
      5 test('impacketScript prefers the examples/<script>.py reference, then the command', () => {
      6   assert.equal(impacketScript(['https://github.com/fortra/impacket/blob/master/examples/secretsdump.py'], ''), 'secretsdump');
      7   assert.equal(impacketScript(['https://example.com/'], 'python3 GetUserSPNs.py -request test.local/john'), 'GetUserSPNs');
      8   assert.equal(impacketScript([], 'certipy find -u john@test.local'), null);
      9 });
     10 
     11 test('splitImpacket refiles umbrella techniques and is idempotent', () => {
     12   const t = { toolId: 'wadcoms:Impacket', toolName: 'Impacket', command: 'psexec.py test.local/john@10.10.10.10', references: [] };
     13   const once = splitImpacket(t);
     14   assert.equal(once.toolId, 'wadcoms:Impacket-psexec');
     15   assert.equal(once.toolName, 'Impacket-psexec');
     16   assert.deepEqual(splitImpacket(once), once);
     17   const other = { toolId: 'wadcoms:Rubeus', toolName: 'Rubeus', command: 'Rubeus.exe', references: [] };
     18   assert.equal(splitImpacket(other), other);
     19 });
     20 
     21 test('canonicalizeFamilyCase folds case-variants onto the busier spelling', () => {
     22   const rows = [
     23     { id: '1', toolId: 'wadcoms:Enum4Linux', toolName: 'Enum4Linux' },
     24     { id: '2', toolId: 'wadcoms:enum4linux', toolName: 'enum4linux' },
     25     { id: '3', toolId: 'wadcoms:Enum4Linux', toolName: 'Enum4Linux' },
     26     { id: '4', toolId: 'wadcoms:Rubeus', toolName: 'Rubeus' },
     27   ];
     28   const out = canonicalizeFamilyCase(rows);
     29   assert.deepEqual(out.map((r) => r.toolId), ['wadcoms:Enum4Linux', 'wadcoms:Enum4Linux', 'wadcoms:Enum4Linux', 'wadcoms:Rubeus']);
     30   assert.equal(out[1].toolName, 'Enum4Linux');
     31   assert.equal(out[1].id, '2', 'other fields untouched');
     32   const solo=[rows[3]];
     33   assert.equal(canonicalizeFamilyCase(solo), solo, 'no variants → same array back');
     34 });