Git Product home page Git Product logo
Drive Badger photo

drivebadger Goto Github PK

repos: 32.0 gists: 0.0

Name: Drive Badger

Type: Organization

Bio: Open source platform for covert data exfiltration operations, supporting all device types: computers, servers, mobile phones, tablets, pen drives, photo cameras

Twitter: drivebadger

Location: Poznan, Poland

Blog: https://drivebadger.com/

Overview

Drive Badger is a framework for secure, automated, huge scale, time-effective data exfiltration from computers running any version of:

  • Windows (including Windows Server and Windows Embedded)
  • Linux
  • Mac OS (including support for new APFS filesystem)

It runs on any size of hardware, from mini-pcs, through laptops, desktop computers, up to big servers (see hardware compatibility list). Basically on anything, that can run Kali Linux, and have at least 1 working USB port.

It is able to exfiltrate data off encrypted hard drives - it currently supports the following encryption schemes:

Support for other encryption schemes is also planned (see project roadmap).

Drive Badger runs below the operating system level - so it doesn't need any passwords (eg. Active Directory) to exfiltrated computers. Instead, it is able to discover several types of passwords and other resources on its own, and use them to automatically expand the attack surface:

  • on Windows computers, decode FTP passwords saved by Total Commander and use them to exfiltrate data off FTP servers using exfiltrated computer's IP
  • on Linux computers, exfiltrate smb and nfs shares defined statically in /etc/fstab
  • on VMware servers, mount VMDK virtual drive images and recursively exfiltrate virtual machine contents

This is a core repository for Drive Badger product. You can visit its homepage for more details: https://drivebadger.com/

Mobile Badger

Drive Badger can be also run in Mobile Badger mode, as standalone solution for Raspberry Pi or similar hardware. Mobile Badger brings data exfiltration support for:

  • Android phones, tablets and possibly other devices (Android version from 4.x to latest)
  • Apple iOS-based devices (with iOS 14.x)
  • Windows Phone 8/10 (Lumia phones)
  • all sorts of mobile devices supporting USB data transfer (details)

Further reading

Is Drive Badger for me?

Ok, I'm interested, what should I read next?

Mobile Badger - standalone version of Drive Badger:

I want to stay current...

Legal information

This software was written and is meant to be used only by eligible entities, eg:

  • police officers
  • special agents
  • intelligence officers
  • military forces
  • private investigators
  • corporate red teams
  • diplomats or other people with personal immunity

Its usage is always a subject to local legislation, and the user is solely responsible for all potential law infringements and/or misfeasances of duties.

Intention of this product, is not an incitement for a crime. Rather, Drive Badger is mainly intended to be used in countries, where using such tools is legal, or at most, can be a subject to possible disciplinary action between the end user and his/her employer.

Drive Badger's Projects

compat icon compat

Things removed from newer Kali Linux versions, but still required by Drive Badger.

drivebadger icon drivebadger

Open source platform for covert data exfiltration operations, supporting all device types: computers, servers, mobile phones, tablets, pen drives and photo cameras.

exclude-antivirus icon exclude-antivirus

Drive Badger configuration: exclude virus databases and other similar, completely irrelevant files during exfiltration

exclude-devel icon exclude-devel

Drive Badger configuration: exclude irrelevant, software development-related files during exfiltration

exclude-digital icon exclude-digital

Drive Badger configuration: exclude image/audio/video recording/editing/streaming software during exfiltration

exclude-erp icon exclude-erp

Drive Badger configuration: exclude ERP systems installation files during exfiltration

exclude-gaming icon exclude-gaming

Drive Badger configuration: exclude games, game launchers and gaming related content during exfiltration

exclude-linux icon exclude-linux

Drive Badger configuration: exclude Linux system directories during exfiltration

exclude-macos icon exclude-macos

Drive Badger configuration: exclude Mac OS system directories during exfiltration

exclude-messaging icon exclude-messaging

Drive Badger configuration: exclude instant messaging and video conferencing software during exfiltration

exclude-oem icon exclude-oem

Drive Badger configuration: exclude hardware drivers and various preinstalled OEM software during exfiltration

exclude-pdf icon exclude-pdf

Drive Badger configuration: exclude PDF readers and editing software during exfiltration

exclude-software icon exclude-software

Drive Badger configuration: exclude irrelevant files related to various common software during exfiltration

exclude-user icon exclude-user

Drive Badger configuration: exclude multimedia, caches, telemetry etc. directories during exfiltration

exclude-virtual icon exclude-virtual

Drive Badger configuration: exclude virtual drive images during exfiltration

exclude-windows icon exclude-windows

Drive Badger configuration: exclude Windows system files and common Microsoft software during exfiltration

ext-mobile-drivers icon ext-mobile-drivers

Mobile Badger display drivers for various Pimoroni, Waveshare, Adafruit, Uctronics and Bakebit LED/LCD devices.

fieldmanual icon fieldmanual

Drive Badger field manual Wiki: everything that outside the scope of the product itself.

hook-fstab icon hook-fstab

Drive Badger extension: parse /etc/fstab files and exfiltrate NFS/Samba shares

hook-virtual icon hook-virtual

Drive Badger extension: recursively exfiltrate VMware and Hyper-V virtual machines along with virtualization server

hook-wcxftp icon hook-wcxftp

Drive Badger extension: parse wcx_ftp.ini files from Total Commander and exfiltrate data from FTP servers

ignore-known icon ignore-known

Drive Badger configuration: ignore.uuid file for Mobile Badger, with well-known partition UUIDs

mobilebadger icon mobilebadger

Mobile Badger: exfiltrate data from mobile devices. Mobile version of Drive Badger.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.