Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
Expand Up @@ -177,5 +177,5 @@ def generate_report(case_dir, source_device, image_path, tool_used,
print(f" 2. Acquire with dcfldd: dcfldd if={demo_source} of={demo_image} "
f"hash=sha256 hashwindow=1G bs=4096 conv=noerror,sync")
print(f" 3. Verify: compare SHA-256 of {demo_source} and {demo_image}")
print(f" 4. Generate acquisition report with chain-of-custody metadata")
print(" 4. Generate acquisition report with chain-of-custody metadata")
print("\n[*] Agent ready. Provide a source device and case directory to begin.")
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
#!/usr/bin/env python3
"""Browser Forensics Analyzer - Parses Chrome History SQLite for investigation."""
import sqlite3, json, os, sys
import sqlite3
import json
import os
import sys
from datetime import datetime, timedelta

CHROME_EPOCH = datetime(1601, 1, 1)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@

import argparse
import json
import sys
from collections import defaultdict


class AttributionEngine:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -202,7 +202,7 @@ def generate_report(target_domain, ct_results):
for h in report["homoglyph_domains"][:10]:
print(f" [diff={h['char_differences']}] {h['domain']}")

print(f"\n--- Issuer Analysis ---")
print("\n--- Issuer Analysis ---")
for issuer, count in sorted(report["issuer_analysis"]["issuers"].items(),
key=lambda x: -x[1])[:5]:
print(f" {count:4d} | {issuer[:60]}")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ def query_cloudtrail_s3_events(bucket_name, hours_back=24):
start_time = (datetime.utcnow() - timedelta(hours=hours_back)).strftime("%Y-%m-%dT%H:%M:%SZ")
cmd = [
"aws", "cloudtrail", "lookup-events",
"--lookup-attributes", f"AttributeKey=ResourceType,AttributeValue=AWS::S3::Object",
"--lookup-attributes", "AttributeKey=ResourceType,AttributeValue=AWS::S3::Object",
"--start-time", start_time,
"--output", "json",
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,6 @@

import argparse
import json
import os
import struct
import sys
from collections import defaultdict
Expand Down
7 changes: 3 additions & 4 deletions skills/analyzing-disk-image-with-autopsy/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@
import os
import sys
import json
import csv
import datetime


Expand Down Expand Up @@ -162,10 +161,10 @@ def analyze_image(image_path, case_dir):
os.makedirs(case_dir, exist_ok=True)
results = {"image": image_path, "timestamp": datetime.datetime.utcnow().isoformat()}

print(f"[*] Image info...")
print("[*] Image info...")
results["image_info"] = get_image_info(image_path)

print(f"[*] Partition layout...")
print("[*] Partition layout...")
partitions = list_partitions(image_path)
results["partitions"] = partitions

Expand All @@ -180,7 +179,7 @@ def analyze_image(image_path, case_dir):
}
print(f" Total: {len(files)}, Deleted: {results[f'files_offset_{offset}']['deleted']}")

print(f"[*] Creating bodyfile for timeline...")
print("[*] Creating bodyfile for timeline...")
bf_path = os.path.join(case_dir, f"bodyfile_{offset}.txt")
create_bodyfile(image_path, offset, bf_path)

Expand Down
4 changes: 2 additions & 2 deletions skills/analyzing-docker-container-forensics/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,7 @@ def detect_suspicious_files(changes):
for f in changes["changed"]:
for pattern in suspicious_changes:
if pattern in f.lower():
findings.append({"type": "CHANGED", "path": f, "reason": f"Critical file modified"})
findings.append({"type": "CHANGED", "path": f, "reason": "Critical file modified"})
break
return findings

Expand Down Expand Up @@ -235,4 +235,4 @@ def generate_report(container_id, inspect_data, security_findings,
containers = list_containers()
for c in containers:
print(f" {c.get('ID', '?')[:12]} {c.get('Names', '?')} {c.get('Status', '?')}")
print(f"\n[DEMO] Usage: python agent.py <container_id>")
print("\n[DEMO] Usage: python agent.py <container_id>")
Original file line number Diff line number Diff line change
Expand Up @@ -221,9 +221,9 @@ def generate_phishing_indicators(headers, auth, hops, url_mismatches, attachment

indicators = generate_phishing_indicators(headers, auth, hops, url_mismatches, attachments)
if indicators:
print(f"\n[!] PHISHING INDICATORS:")
print("\n[!] PHISHING INDICATORS:")
for ind in indicators:
print(f" - {ind}")
else:
print(f"\n[DEMO] Usage: python agent.py <email.eml>")
print("\n[DEMO] Usage: python agent.py <email.eml>")
print("[*] Provide an EML file for phishing analysis.")
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,6 @@
import argparse
import json
import re
import struct
import sys
from pathlib import Path


PCLNTAB_MAGICS = {
Expand Down
1 change: 0 additions & 1 deletion skills/analyzing-indicators-of-compromise/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@

import re
import os
import json
import datetime

try:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,7 @@
import json
import subprocess
import sys
import re
from datetime import datetime
from pathlib import Path


class ObjectionAssessor:
Expand Down
6 changes: 3 additions & 3 deletions skills/analyzing-linux-elf-malware/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -198,7 +198,7 @@ def detect_malware_type(strings_data):
print(f"[*] SHA256: {hashes['sha256']}")

elf_info = analyze_elf_header(target)
print(f"\n--- ELF Header ---")
print("\n--- ELF Header ---")
for k, v in elf_info.items():
print(f" {k}: {v}")

Expand All @@ -210,7 +210,7 @@ def detect_malware_type(strings_data):
sections = analyze_sections(target)
high_ent = [s for s in sections if s.get("high_entropy")]
if high_ent:
print(f"\n[!] High entropy sections (possible packing/encryption):")
print("\n[!] High entropy sections (possible packing/encryption):")
for s in high_ent:
print(f" {s['name']}: entropy={s['entropy']}, size={s['size']}")

Expand All @@ -226,5 +226,5 @@ def detect_malware_type(strings_data):
classification = detect_malware_type(strings_data)
print(f"\n[*] Classification: {', '.join(classification)}")
else:
print(f"\n[DEMO] Usage: python agent.py <elf_binary>")
print("\n[DEMO] Usage: python agent.py <elf_binary>")
print("[*] Provide a Linux ELF binary for analysis.")
2 changes: 1 addition & 1 deletion skills/analyzing-linux-system-artifacts/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -259,5 +259,5 @@ def find_suspicious_tmp_files(evidence_root):
for t in tmp[:20]:
print(f" {t}")
else:
print(f"\n[DEMO] Usage: python agent.py <evidence_mount_point>")
print("\n[DEMO] Usage: python agent.py <evidence_mount_point>")
print("[*] Mount a forensic image and provide the path for analysis.")
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,7 @@
import os
import sys
import json
import csv
from datetime import datetime, timedelta
from pathlib import Path


FILETIME_EPOCH = datetime(1601, 1, 1)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -242,5 +242,5 @@ def generate_report(filepath, triage, macros, analysis, deobfuscated_urls, dde_f
report = generate_report(target, triage, macros, analysis, list(set(all_urls)), dde)
print(f"\n[*] Report: {json.dumps(report, indent=2, default=str)[:500]}...")
else:
print(f"\n[DEMO] Usage: python agent.py <document.docm|xlsm>")
print("\n[DEMO] Usage: python agent.py <document.docm|xlsm>")
print("[*] Provide an Office document for macro analysis.")
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,6 @@
import os
import hashlib
from datetime import datetime, timezone
from pathlib import Path
from dataclasses import dataclass, field, asdict

try:
Expand Down Expand Up @@ -327,7 +326,7 @@ def format_report(result: URLScanResult) -> str:
lines.append(f" - {ind}")
lines.append("")

lines.append(f"[INFRASTRUCTURE]")
lines.append("[INFRASTRUCTURE]")
lines.append(f" Domains contacted: {len(result.domains_contacted)}")
lines.append(f" IPs contacted: {len(result.ips_contacted)}")
lines.append(f" Resource hashes: {len(result.resource_hashes)}")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -226,28 +226,28 @@ def generate_summary(report, processes, network, dropped, signatures, registry):
registry = analyze_registry(report)
summary = generate_summary(report, processes, network, dropped, signatures, registry)

print(f"\n--- Analysis Summary ---")
print("\n--- Analysis Summary ---")
print(f" Score: {summary['threat_score']}/10")
print(f" Processes: {summary['process_count']}")
print(f" Suspicious APIs: {summary['suspicious_api_total']}")
print(f" Signatures: {summary['signatures_triggered']} "
f"({summary['high_severity_sigs']} high severity)")

print(f"\n--- Network ---")
print("\n--- Network ---")
print(f" DNS: {summary['dns_queries']}, HTTP: {summary['http_requests']}, "
f"TCP: {summary['tcp_connections']}")
for http in network["http"][:5]:
print(f" {http['method']} {http['host']}{http['uri']}")

print(f"\n--- Dropped Files ---")
print("\n--- Dropped Files ---")
for d in dropped[:5]:
print(f" {d['filepath']} ({d['size']} bytes)")

print(f"\n--- Top Signatures ---")
print("\n--- Top Signatures ---")
for s in signatures[:5]:
print(f" [{s['severity']}/5] {s['name']}: {s['description']}")
else:
print(f"\n[DEMO] Usage:")
print(f" python agent.py <sample.exe> # Submit to Cuckoo")
print(f" python agent.py <task_id> # Parse existing report")
print(f" python agent.py <report.json> # Parse JSON report file")
print("\n[DEMO] Usage:")
print(" python agent.py <sample.exe> # Submit to Cuckoo")
print(" python agent.py <task_id> # Parse existing report")
print(" python agent.py <report.json> # Parse JSON report file")
Original file line number Diff line number Diff line change
Expand Up @@ -239,5 +239,5 @@ def check_suspicious_processes(pslist_procs):
f"{c['local_addr']}:{c['local_port']} -> "
f"{c['foreign_addr']}:{c['foreign_port']}")
else:
print(f"\n[DEMO] Usage: python agent.py <memory.dmp>")
print("\n[DEMO] Usage: python agent.py <memory.dmp>")
print("[*] Provide a memory dump for forensic analysis.")
Original file line number Diff line number Diff line change
Expand Up @@ -202,4 +202,4 @@ def generate_incident_report(pcap_path, beacons, lateral, exfil, dns_queries):
report = generate_incident_report(pcap, beacons, lateral, exfil, dns)
print(f"\n[*] Report summary: {json.dumps(report['findings'], indent=2)}")
else:
print(f"\n[DEMO] Usage: python agent.py <capture.pcap>")
print("\n[DEMO] Usage: python agent.py <capture.pcap>")
Original file line number Diff line number Diff line change
Expand Up @@ -240,4 +240,4 @@ def generate_suricata_signatures(http_requests, dns_tunneling):
for r in rules[:5]:
print(f" {r}")
else:
print(f"\n[DEMO] Usage: python agent.py <malware_traffic.pcap>")
print("\n[DEMO] Usage: python agent.py <malware_traffic.pcap>")
Original file line number Diff line number Diff line change
Expand Up @@ -217,4 +217,4 @@ def apply_display_filter(pcap_path, display_filter, fields):
for s in suspicious:
print(f" [!] {s['type']}: {s['description']} ({s['count']} occurrences)")
else:
print(f"\n[DEMO] Usage: python agent.py <capture.pcap>")
print("\n[DEMO] Usage: python agent.py <capture.pcap>")
Original file line number Diff line number Diff line change
Expand Up @@ -238,4 +238,4 @@ def compare_packed_unpacked(packed_path, unpacked_path):
print(f" [FAIL] {msg}")
print(" [*] Try fixing UPX headers or use dynamic unpacking with a debugger")
else:
print(f"\n[DEMO] Usage: python agent.py <packed_binary.exe>")
print("\n[DEMO] Usage: python agent.py <packed_binary.exe>")
4 changes: 2 additions & 2 deletions skills/analyzing-pdf-malware-with-pdfid/scripts/agent.py
Original file line number Diff line number Diff line change
Expand Up @@ -211,7 +211,7 @@ def generate_report(filepath, keywords, structure, streams, js_blocks,
for kw, info in keywords.items():
print(f" [!] {kw}: {info['count']}x - {info['description']}")

print(f"\n--- Structure ---")
print("\n--- Structure ---")
for key, val in structure.items():
print(f" {key}: {val}")

Expand All @@ -237,4 +237,4 @@ def generate_report(filepath, keywords, structure, streams, js_blocks,
risk = calculate_risk_score(keywords, structure, exploits, js)
print(f"\n[*] Risk Score: {risk}/100")
else:
print(f"\n[DEMO] Usage: python agent.py <document.pdf>")
print("\n[DEMO] Usage: python agent.py <document.pdf>")
Original file line number Diff line number Diff line change
Expand Up @@ -210,6 +210,6 @@ def run_pecmd(prefetch_path, output_dir=None):
header = parse_prefetch_header(target)
print(f" {json.dumps(header, indent=2)}")
else:
print(f"\n[DEMO] Usage:")
print(f" python agent.py <prefetch_dir> # Analyze all .pf files")
print(f" python agent.py <file.pf> # Analyze single prefetch file")
print("\n[DEMO] Usage:")
print(" python agent.py <prefetch_dir> # Analyze all .pf files")
print(" python agent.py <file.pf> # Analyze single prefetch file")
Original file line number Diff line number Diff line change
Expand Up @@ -325,26 +325,26 @@ def generate_report(sample_path=None, encrypted_path=None):
print(f" Possible families: {', '.join(fm.get('families', ['Unknown']))}")

ea = report.get("encryption_analysis", {})
print(f"\n--- Encryption Analysis ---")
print("\n--- Encryption Analysis ---")
print(f" Overall entropy: {ea.get('overall_entropy', 0)}")
print(f" Fully encrypted: {ea.get('fully_encrypted', False)}")
print(f" ECB mode likely: {ea.get('ecb_likely', False)}")
partial = ea.get("partial_encryption", {})
print(f" Partial encryption: {partial.get('likely_partial', False)}")

hc = report.get("header_check", {})
print(f"\n--- Header Check ---")
print("\n--- Header Check ---")
print(f" Known header: {hc.get('detected', False)}")
print(f" Note: {hc.get('note', '')}")

if "feasibility" in report:
f = report["feasibility"]
print(f"\n--- Decryption Feasibility ---")
print("\n--- Decryption Feasibility ---")
print(f" Assessment: {f['feasibility']}")
print(f" Weaknesses:")
print(" Weaknesses:")
for w in f.get("weaknesses", []):
print(f" [!] {w}")
print(f" Strong points:")
print(" Strong points:")
for s in f.get("strong_points", []):
print(f" [+] {s}")
print(f" Recommendation: {f['recommendation']}")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -176,15 +176,15 @@ def generate_intelligence_report(victims, target_org=None):
report = generate_intelligence_report(victims, target_org=query)
analysis = report["analysis"]

print(f"\n--- Top Groups ---")
print("\n--- Top Groups ---")
for g, c in list(analysis["top_groups"].items())[:5]:
print(f" {g:20s} {c} victims")

print(f"\n--- Top Sectors ---")
print("\n--- Top Sectors ---")
for s, c in list(analysis["top_sectors"].items())[:5]:
print(f" {s:30s} {c}")

print(f"\n--- Top Countries ---")
print("\n--- Top Countries ---")
for co, c in list(analysis["top_countries"].items())[:5]:
print(f" {co:20s} {c}")

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ def fetch_tor_exit_nodes():
if line and not line.startswith("#"):
nodes.add(line)
return nodes
except Exception as e:
except Exception:
return set()


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,7 @@ def analyze_wallet(address):

info = report.get("wallet_info", {})
if info:
print(f"\n--- Wallet Summary ---")
print("\n--- Wallet Summary ---")
print(f" Total received: {info.get('total_received_btc', 0):.8f} BTC")
print(f" Total sent: {info.get('total_sent_btc', 0):.8f} BTC")
print(f" Balance: {info.get('final_balance_btc', 0):.8f} BTC")
Expand Down
Loading