Merge pull request #31 from robert-todora/dev

changed output to include files found in log files and cleaned up som…
This commit is contained in:
Robert Todora
2023-07-31 16:01:08 -04:00
committed by GitHub
3 changed files with 23 additions and 17 deletions
+7 -6
View File
@@ -70,9 +70,9 @@ def is_interest_file(file:RemoteFile, rules: Rules, smb_client: SMBClient, share
file_triage = termcolor.colored(f"{{Yellow}}\\\\{file.target}\\{share}\\{file.name} <KeepBackupFiles>", "light_yellow", "on_white")
try:
file.get(smb_client)
print(file_text, file_triage)
log.info(f"{file_text} {file_triage}")
except FileRetrievalError as e:
smb_client.handle_download_error(share, file.name, e)
smb_client.handle_download_error(share, file.name, e, False)
# MVP Build only, check for files with possible passwords contained inside
for cred in cred_list:
@@ -80,9 +80,9 @@ def is_interest_file(file:RemoteFile, rules: Rules, smb_client: SMBClient, share
file_triage = termcolor.colored(f"{{Black}}\\\\{file.target}\\{share}\\{file.name} <KeepFilesWithInterestName>", "black", "on_white")
try:
file.get(smb_client)
print(file_text, file_triage)
log.info(f"{file_text} {file_triage}")
except FileRetrievalError as e:
smb_client.handle_download_error(share, file.name, e)
smb_client.handle_download_error(share, file.name, e, False)
file_data = ""
@@ -92,9 +92,9 @@ def is_interest_file(file:RemoteFile, rules: Rules, smb_client: SMBClient, share
file_data = str(f.read(10000))
if re.search(ssn_regex, file_data):
file_triage = termcolor.colored(f"{{Red}}\\\\{file.target}\\{share}\\{file.name} <SsnRegexFound>", "light_yellow", "on_white")
print(file_text, file_triage)
log.info(f"{file_text} {file_triage}")
except FileRetrievalError as e:
smb_client.handle_download_error(share, file.name, e)
smb_client.handle_download_error(share, file.name, e, False)
@@ -124,6 +124,7 @@ def is_interest_share(share, rules: Rules):
if rule['MatchAction'] == "Snaffle":
color = rule['Triage']
print(share_text, termcolor.colored(f"{{{rule['Triage']}}} {share} <{rule['RuleName']}>:<{rule['Description']}>",str(color).lower(), 'on_white'))
else:
log.debug(f"{rule['MatchAction']} {share} matched rule {rule['RuleName']}:{rule['Description']}")
+3 -3
View File
@@ -70,11 +70,11 @@ def begin_snaffle(options):
try:
file_text = termcolor.colored("[File]", 'green')
file.get(smb_client)
print(file_text, f"\\\\{target}\\{share}\\{name}")
log.info(f"{file_text} \\\\{target}\\{share}\\{name}")
except FileRetrievalError as e:
# Check if its a directory, and try to list files/more directories here
smb_client.handle_download_error(share, file.name, e)
smb_client.handle_download_error(share, file.name, e, True)
# if str(e).find("ACCESS_DENIED"):
# log.debug(f"Access Denied {file}")
# continue
@@ -85,7 +85,7 @@ def begin_snaffle(options):
try:
is_interest_file(file, snaff_rules, smb_client, share)
except FileRetrievalError as e:
smb_client.handle_download_error(share, file.name, e)
smb_client.handle_download_error(share, file.name, e, False)
continue
except FileListError as e:
+13 -8
View File
@@ -167,15 +167,14 @@ class SMBClient:
self.login(refresh=True)
# Handle download errors and recurse into directories
def handle_download_error(self, share, dir_path, err):
def handle_download_error(self, share, dir_path, err, isFromGoLoud:bool):
if str(err).find("STATUS_FILE_IS_A_DIRECTORY"):
dir_text = termcolor.colored("[Directory]", 'light_blue')
print(dir_text, f"\\\\{self.server}\\{share}\\{dir_path}")
# log.error(f"{self.server} {dir_path} {err}")
# else:
if isFromGoLoud:
log.info(f"{dir_text}\\\\{self.server}\\{share}\\{dir_path}")
try:
subfiles = self.ls(share, str(dir_path))
# print(list(subfiles), len(list(subfiles)))
except FileListError as e:
log.error(f"Access denied, cannot read at \\\\{self.server}\\{share}\\{dir_path}")
@@ -190,16 +189,22 @@ class SMBClient:
subfile.get(self)
file_text = termcolor.colored("[File]", 'green')
print(file_text, f"\\\\{self.server}\\{share}\\{sub_name}")
if isFromGoLoud:
log.info(f"{file_text} \\\\{self.server}\\{share}\\{sub_name}")
# self.handle_download_error(share, sub_name, err)
except Exception as e:
if str(err).find("STATUS_FILE_IS_A_DIRECTORY"):
dir_text = termcolor.colored("[Directory]", 'light_blue')
print(dir_text, f"\\\\{self.server}\\{share}\\{sub_name}")
self.handle_download_error(share, sub_name, e)
if isFromGoLoud:
log.info(f"{dir_text}\\\\{self.server}\\{share}\\{sub_name}")
self.handle_download_error(share, sub_name, e, True)
else:
self.handle_download_error(share, sub_name, e, False)
elif str(err).find("ACCESS_DENIED"):
continue