Giter VIP home page Giter VIP logo

honeybits-win's Introduction

Honeybits-win

A simple tool to create breadcrumbs and honeytokens, to lead the attackers to your honeypots!

The Linux version of this project: honeybits

Author: Adel "0x4D31" Karimi.

Features:

  • Creating fake credentials in Windows Credential Manager
  • Reading config from a remote Key/Value Store such as Consule or etcd

Requirements:

  • Go Lang 1.7+
  • Viper (go get github.com/spf13/viper)
  • crypt (go get github.com/xordataexchange/crypt/config)

Usage:

> go run honeybits-win.go

  /\  /\___  _ __   ___ _   _| |__ (_) |_ ___
 / /_/ / _ \| '_ \ / _ \ | | | '_ \| | __/ __|
/ __  / (_) | | | |  __/ |_| | |_) | | |_\__ \
\/ /_/ \___/|_| |_|\___|\__, |_.__/|_|\__|___/
========================|___/=================

Failed reading remote config. Reading the local config file...
Local config file loaded.

[+] Generic credential created (192.168.1.66)
[+] Generic credential created (realco-AWS_SECRET_ACCESS_KEY-david)
[+] Domain credential created (domain01)
[+] Domain credential created (winsrv)

TODO:

  • Honeyfiles
    • Type 1 - honeytoken (monitored)
    • Type 2 - breadcrumb (containing false information)
    • Type 3 - beacon docs
  • Content generator module for honeyfiles
  • More traps, including:
    • AWS credentials file
    • Fake entries in CMD/PowerShell commands history
    • Fake browser history, bookmarks and saved passwords
    • Database files/backups: SQLite, MySQL
    • Confoguration, backup, and connection files such as RDP and VPN
    • MS Outlook Data file (.ost/.pst)
    • Hosts files (hosts, lmhosts)
    • Fake ARP entries
    • KeePass file with fake entries (.kdbx)
    • Registery keys (WinSCP, PuTTY, etc.)
    • Injected fake credentials in LSASS
  • Documentation

honeybits-win's People

Contributors

0x4d31 avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.