-
Notifications
You must be signed in to change notification settings - Fork 1
Roadmap
Tomasz Klim edited this page May 13, 2022
·
19 revisions
Do you want any of the below features? Sponsor us...
- HFS+ (older Mac OS)
- ESET Endpoint Encryption (previously DESlock)
- McAfee Drive Encryption
- FreeBSD
- possibly other *BSD
- AIX
- is it possible to assemble and exfiltrate filesystems spanning multiple drives/hosts, based on discovered data?
- RAID 5/6/...
- ZFS/btrfs, possibly with encryption support
- MooseFS, Ceph, GlusterFS etc.
- look for 802.1X certificate files and passwords
- try to connect to protected networks
- postpone executing all other hooks, until all drives are processed
Support for secured-core PC architecture
- first research, what is really possible and usable in real-life scenarios
- TPM modules
- U2F keys (Yubikey, Google Titan etc.)
- smart cards
- biometric devices
- HSM modules
- Bitlocker PIN codes
- VeraCrypt keyfiles (alone or mixed with passwords)
- LUKS keyfiles
- rewrite Python 2.x-based code to Python 3 (or PHP)
- scan for ~/.ssh/id_rsa or other ssh private keys (parse ~/.ssh/config)
- parse .bash_history and .zsh_history for connections using keys
- try to find frameworks like Ansible and parse their configuration
- use preconfigured keys from repository
- finally, try to exfiltrate other machines via ssh
- look for user passwords saved in browsers (Firefox, Chrome etc.)
- look for ftp/sftp passwords from other programs
- look for remote MySQL/Postgres/Mongo/other credentials, to "backup" them similarly to sf-backup
- try to adapt DonPAPI
- look for Windows password files
- is it possible to extract SMB share credentials from Windows?
- how about AD environment?
- how about standalone Windows + Samba server?
- either mapped to drive letter or not, but still available to open without password
- mapped to drive letter using separate credentials
- properly recognize drive serial numbers behind RAID controllers
- deployment-scripts: support at least for Raspberry Pi with Raspbian
- try to unify event logging between Drive Badger and Mobile Badger
- online ISO setup via admin panel, then build, download, and deploy using Rufus
- goal: no need to use Linux at all (at least during setup stage)
- scripts for repacking external firmware (at least these based on Debian or its derivative, and provided as ISO images, eg. this one)
- scripts preparing automatic imports to Magnet AXIOM, Paraben E3, FTK Forensic Toolkit and Autopsy
- research of Oxygen Forensic Detective and Belkasoft Evidence Center X
© Copyright 2020-2022 by Tomasz Klim Payload.pl