mirror of
https://github.com/cisagov/snafflepy
synced 2026-09-24 18:22:23 +00:00
working on file classifier
This commit is contained in:
+23
-2
@@ -6,6 +6,7 @@ import logging
|
||||
import termcolor
|
||||
|
||||
from impacket.smbconnection import SessionError, SMBConnection
|
||||
from .smb import *
|
||||
from .file import *
|
||||
|
||||
log = logging.getLogger('snafflepy.classifier')
|
||||
@@ -48,9 +49,29 @@ class Rules:
|
||||
|
||||
# TODO
|
||||
|
||||
def is_interest_file(file:RemoteFile, rules, smb_client, share):
|
||||
file.get(smb_client)
|
||||
def is_interest_file(file:RemoteFile, rules: Rules, smb_client: SMBClient, share):
|
||||
backup_ext_list = [".bak", ".mdf", ".sqldump", ".sdf"]
|
||||
cred_list = ["creds", "password", "passw", "credentials"]
|
||||
|
||||
file_text = termcolor.colored(f"[File]", "green")
|
||||
ssn_regex = str("^\d{{3}}-\d{{2}}-\d{{4}}$")
|
||||
for ext in backup_ext_list:
|
||||
if re.search(str(ext), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Yellow}}\\\\{file.target}\\{share}\\{file.name} <KeepBackupFiles>", "light_yellow", "on_white")
|
||||
try:
|
||||
file.get(smb_client)
|
||||
print(file_text, file_triage)
|
||||
except FileRetrievalError as e:
|
||||
smb_client.handle_download_error(share, file.name, e)
|
||||
for cred in cred_list:
|
||||
if re.search(str(cred), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Black}}\\\\{file.target}\\{share}\\{file.name} <KeepFilesWithInterestName>", "black", "on_white")
|
||||
file.get(smb_client)
|
||||
print(file_text, file_triage)
|
||||
|
||||
|
||||
|
||||
|
||||
def is_interest_share(share, rules: Rules):
|
||||
|
||||
# Tedium City to find match in wordlist. Did not prepare rules beforehand except by putting each MatchLocation in its own list
|
||||
|
||||
@@ -85,8 +85,7 @@ def begin_snaffle(options):
|
||||
try:
|
||||
is_interest_file(file, snaff_rules, smb_client, share)
|
||||
except FileRetrievalError as e:
|
||||
# if str(e).find("ACCESS_DENIED"):
|
||||
# log.debug(f"Access Denied, cannot download \\\\{target}\\{share}\\{file}")
|
||||
smb_client.handle_download_error(share, file.name, e)
|
||||
continue
|
||||
|
||||
except FileListError as e:
|
||||
|
||||
+2
-2
@@ -178,8 +178,7 @@ class SMBClient:
|
||||
# print(list(subfiles), len(list(subfiles)))
|
||||
except FileListError as e:
|
||||
log.error(f"Access denied, cannot read at \\\\{self.server}\\{share}\\{dir_path}")
|
||||
# print(len(list(subfiles)))
|
||||
# while str(err).find("STATUS_FILE_IS_A_DIRECTORY") != -1:
|
||||
|
||||
|
||||
for subfile in subfiles:
|
||||
|
||||
@@ -193,6 +192,7 @@ class SMBClient:
|
||||
file_text = termcolor.colored("[File]", 'green')
|
||||
print(file_text, f"\\\\{self.server}\\{share}\\{sub_name}")
|
||||
|
||||
yield subfile
|
||||
# self.handle_download_error(share, sub_name, err)
|
||||
except Exception as e:
|
||||
if str(err).find("STATUS_FILE_IS_A_DIRECTORY"):
|
||||
|
||||
Reference in New Issue
Block a user