Commit Graph

453 Commits

Author SHA1 Message Date
Oran Nadler 01b071dfe1 add labels 2018-03-06 00:32:57 -08:00
Itay Mizeretz ee23703bfa Monkey now uses different names for 32,64bit on windows.
No need to use dropper or rename moneky
2018-03-04 17:05:43 +02:00
Oran Nadler 8a3216d812 works 2018-03-04 06:24:22 -08:00
Oran Nadler 00fe34d431 add pth map to ui 2018-03-04 05:22:34 -08:00
Itay Mizeretz abd738acbc Change config value name
Add logs
2018-02-28 19:01:42 +02:00
Itay Mizeretz 260607b685 Use dedicated api to determine server is running 2018-02-28 18:26:31 +02:00
Itay Mizeretz 8509eef48e Add basic logic to windows upgrade 2018-02-28 14:10:01 +02:00
Itay Mizeretz 03c32025aa Update icons 2018-02-27 19:39:32 +02:00
Itay Mizeretz a20cb16b48 Merge branch 'develop' into feature/send-raw-log
# Conflicts:
#	infection_monkey/main.py
#	monkey_island/cc/app.py
#	monkey_island/cc/ui/src/components/map/preview-pane/PreviewPane.js
2018-02-27 19:32:28 +02:00
Itay Mizeretz d8946feb69 Fix CR 2018-02-27 19:13:28 +02:00
Itay Mizeretz 3efc638d1f Add segmentation issues section 2018-02-27 15:54:45 +02:00
Itay Mizeretz 08995796ef Make both segmentation issues and island segmentation issues present the same warning 2018-02-27 15:54:19 +02:00
Itay Mizeretz 57ae31406a Implement backend 2018-02-27 14:17:50 +02:00
Itay Mizeretz aae2a3a8de rename existing cross_segment_issue to island_cross_segment_issue 2018-02-27 14:05:23 +02:00
Itay Mizeretz cacb60b132 Add parent path for python paths (for common code) 2018-02-27 14:03:50 +02:00
Itay Mizeretz d6240ff502 move inaccessible_subnet_groups to seperate category 2018-02-26 17:32:02 +02:00
Itay Mizeretz 5f93f33128 Merge branch 'feature/support-subnet-in-config' into feature/detect-cross-segment-traffic
# Conflicts:
#	infection_monkey/config.py
2018-02-26 16:36:40 +02:00
Itay Mizeretz 0de15736ac rename and move range_fixed 2018-02-26 16:34:23 +02:00
Itay Mizeretz c6881e6147 Merge branch 'feature/support-subnet-in-config' into feature/detect-cross-segment-traffic 2018-02-26 16:13:02 +02:00
Itay Mizeretz be54878ad9 Merge branch 'develop' into feature/support-subnet-in-config 2018-02-26 16:12:24 +02:00
Itay Mizeretz 898644df7b Remove range classes in config
network now scans several range classes according to config
2018-02-26 16:11:52 +02:00
itaymmguardicore d8210bf731
Merge branch 'develop' into feature/secure-island-db 2018-02-26 13:44:14 +02:00
Itay Mizeretz b7f147921e Merge remote-tracking branch 'origin/master' into develop
# Conflicts:
#	monkey_island/cc/main.py
#	monkey_island/cc/ui/src/components/Main.js
2018-02-25 19:15:09 +02:00
Itay Mizeretz ddc93a67fa Fix CR 2018-02-25 18:23:52 +02:00
Itay Mizeretz 38cf36e165 append options to existsing ones 2018-02-25 17:06:40 +02:00
Itay Mizeretz 6f827e5aa9 Add json-loader to package.json 2018-02-25 14:16:57 +02:00
Itay Mizeretz 4364156416 Add server config file and use in frontend+backend 2018-02-22 20:33:40 +02:00
Itay Mizeretz 9bb7148f50 Secure all endpoints 2018-02-22 16:21:03 +02:00
Itay Mizeretz 9e169980e3 Don't query completed steps if not logged in 2018-02-22 16:18:14 +02:00
Itay Mizeretz 28ef2d8708 return 401 on invalid token 2018-02-22 15:43:51 +02:00
Itay Mizeretz c9d644f88a Add login page, and auto redirection to/from login page 2018-02-22 15:23:47 +02:00
Itay Mizeretz 52d75de864 Fix AuthService 2018-02-22 15:22:35 +02:00
Daniel Goldberg f675bed851 CR fixes 2018-02-22 10:59:04 +02:00
Itay Mizeretz df95cc73c5 Make all components with server interaction AuthComponents 2018-02-22 10:36:10 +02:00
Itay Mizeretz e02d282c03 Add AuthService 2018-02-22 10:35:31 +02:00
Itay Mizeretz 4bb569dd89 Add JWT authentication to backend 2018-02-22 10:33:37 +02:00
Itay Mizeretz 7111f5b0e2 Add inaccessible_subnet_groups config value 2018-02-21 12:55:36 +02:00
Itay Mizeretz d3ce956224 Change description of config value 2018-02-20 16:21:23 +02:00
Itay Mizeretz ee1a321416 Send log to island is configurable 2018-02-19 18:32:05 +02:00
Itay Mizeretz aa02d8945d Replace base64 with string escaping 2018-02-19 17:22:48 +02:00
Daniel Goldberg 3ea4609975 Remove C&C from all textual and code mentions 2018-02-15 15:36:19 +02:00
Itay Mizeretz 70766e7358 Save some space 2018-02-14 16:58:58 +02:00
Itay Mizeretz 86a0e47d15 Add log downloading from map 2018-02-14 15:51:22 +02:00
Itay Mizeretz dbe7a6a378 Add log sending logic to monkey
Add log processing logic to monkey island backend
2018-02-14 15:50:53 +02:00
Itay Mizeretz 06a2e4f18d encrypt credentials in config+telemetry 2018-02-13 16:34:37 +02:00
Itay Mizeretz 29e85100d2 Add global encryptor 2018-02-13 16:29:24 +02:00
Itay Mizeretz 0ed2f74824 Add encryptor 2018-02-13 12:05:01 +02:00
Itay Mizeretz 74deebb280 Fix bug in telemetry 2018-01-19 13:00:38 +02:00
Itay Mizeretz a76cf7e3f8 Always sort telemetry feed 2018-01-19 11:19:49 +02:00
Itay Mizeretz a5eaea8796 Hotfix: live telemetry feed sorted by timestamp 2018-01-19 10:58:24 +02:00
Itay Mizeretz 0a62abe450 Change report title font + resize sub-titles 2018-01-18 21:44:12 +02:00
Itay Mizeretz 56035df461 Most theme updates 2018-01-18 18:33:02 +02:00
Itay Mizeretz e1803a7ff9 Fixed CR 2018-01-16 17:23:17 +02:00
itaymmguardicore 7e77e2d33b
Merge branch 'develop' into feature/report-backend 2018-01-16 16:24:44 +02:00
Itay Mizeretz 4ef0a53026 Content fixes 2018-01-16 10:50:05 +02:00
Itay Mizeretz 1935d2d6a1 Fix temporary hack 2018-01-09 19:25:18 +02:00
Itay Mizeretz 50c674a2af Add telemetry console frontend 2018-01-09 19:19:16 +02:00
Itay Mizeretz 1ab1dbedb1 Add TelemetryFeed entrypoint + all logic 2018-01-09 19:16:18 +02:00
Itay Mizeretz fb5f1f8302 Monkey icon moved to top left 2018-01-02 19:09:41 +02:00
Itay Mizeretz 59203e29a4 Split main function to smaller functions 2018-01-02 12:55:27 +02:00
Itay Mizeretz d76386e8d3 More content fixing 2018-01-02 12:40:31 +02:00
Itay Mizeretz d16f3fee9b Replace monkey logo with new one 2018-01-02 12:37:20 +02:00
Itay Mizeretz 109a9a5cbb Improve printed badge style 2018-01-02 12:34:59 +02:00
Itay Mizeretz 5649fa7043 Content improvements 2017-12-24 18:34:18 +02:00
Itay Mizeretz 6150c6fcc0 Fix bug where machine was popped out 2017-12-24 18:28:01 +02:00
Itay Mizeretz bb27444c35 use quotation marks on linux as well 2017-12-24 14:43:29 +02:00
Itay Mizeretz 6ee26297ef Add contact us at end of report 2017-12-24 12:11:22 +02:00
Itay Mizeretz 15b4a8778b Add V after generating report 2017-12-24 11:23:57 +02:00
Itay Mizeretz e2a622d117 Remove unecessary paragraph 2017-12-19 20:35:06 +02:00
Itay Mizeretz 0c286a3419 Remove statement if there were no infections 2017-12-19 19:02:10 +02:00
Itay Mizeretz c4f9f774af Fix bug running from path with spaces 2017-12-19 18:43:20 +02:00
Itay Mizeretz 6ddb117723 Minor content fix 2017-12-19 17:58:21 +02:00
Itay Mizeretz b0547c4f7a Add legend to report map 2017-12-19 17:58:07 +02:00
Itay Mizeretz 80914716b7 Show minimal info on services.
Make optimization for machine label on report
2017-12-12 17:05:57 +02:00
Itay Mizeretz 8ed439e24e Remove irrelevant sentence+link 2017-12-12 16:39:38 +02:00
Itay Mizeretz 434c72f69f Implemented issues and warnings on overview 2017-12-12 16:33:16 +02:00
Itay Mizeretz f2b631745d Fix bug where stolen credentials had '.' in username 2017-12-12 15:45:32 +02:00
Itay Mizeretz 483394d7f5 Report shows message if no monkeys have been run before 2017-12-12 15:44:38 +02:00
Itay Mizeretz 09e04a3763 Fixed condition for showing suggestion to improve monkey success rate 2017-12-12 15:43:47 +02:00
Itay Mizeretz f2e464f2a6 Report now uses initial config when makes sense 2017-12-12 15:42:24 +02:00
Itay Mizeretz d8aff72da0 Exploits in breached servers are now readable 2017-12-12 13:42:08 +02:00
Itay Mizeretz 2c8b510b0c Exploits used are listed only if they're not the default configuration.
Suggestion to improve monkey success rate appears only if no critical issues were found
2017-12-12 12:45:53 +02:00
Itay Mizeretz c8e553721f Report content fix 2017-12-12 12:07:37 +02:00
Itay Mizeretz 8bc9e3a65f Add warning message if watching report while monkeys are running 2017-12-05 17:01:47 +02:00
Itay Mizeretz f14dc8e2fb Add run info under overview section including zero-patients, interesting config values, and config recommendations. 2017-12-05 16:29:18 +02:00
Itay Mizeretz 013e29b76b Improved style of recommendations 2017-11-28 18:46:39 +02:00
Itay Mizeretz 5690ddc5d7 Add print button, improve printability 2017-11-28 18:34:57 +02:00
Itay Mizeretz e3bd980a12 Replace pie-chart with progress bar 2017-11-28 17:55:38 +02:00
Itay Mizeretz 88ea57dc88 Fix most printing format issues
Improve CSS
Shorten lines
2017-11-28 17:16:58 +02:00
Itay Mizeretz 881cf5e793 Collapsible-Collapsable 2017-11-28 17:12:48 +02:00
Itay Mizeretz da55b0b26b Group recommendations by machine.
Show recommendation with collapsible incident
2017-11-28 17:11:00 +02:00
Itay Mizeretz 96972aeac9 Micro segmentation, not port level segmentation 2017-11-28 14:47:54 +02:00
Itay Mizeretz dff90ab534 Remove duplicate exploits on breached servers 2017-11-28 14:37:11 +02:00
Itay Mizeretz 10375c093e Sort recommendations by machine 2017-11-28 14:33:41 +02:00
Itay Mizeretz 046b18e71c Don't show actual password on stolen creds table 2017-11-28 14:22:11 +02:00
Itay Mizeretz 2aadb12815 Change page structure 2017-11-28 14:16:16 +02:00
Itay Mizeretz 4f6ed95501 Fix bug with exploited nodes 2017-11-28 13:40:51 +02:00
Itay Mizeretz f72b32bb67 Removed duplicate issues 2017-11-27 15:51:56 +02:00
Itay Mizeretz ce10ef00e4 Everything implemented on backend 2017-11-27 15:20:59 +02:00
Itay Mizeretz 82e30040eb Add spaces in time string 2017-11-21 17:39:42 +02:00
Itay Mizeretz 133bd7d80a Following fields use real data now: First monkey time, monkey duration, scanned servers, breached servers, stolen passwords 2017-11-21 17:37:13 +02:00
Itay Mizeretz 35bbd38d2e Report uses data from server now 2017-11-21 16:40:26 +02:00
Itay Mizeretz 83c7c3d13c Report now uses dynamic data 2017-11-21 16:25:39 +02:00
Itay Mizeretz 8632f4d5ca Change machine name to be hostname when possible, and os['version'] otherwise 2017-11-21 13:50:29 +02:00
Itay Mizeretz 4a96c46f3e Some content and cosmetic changes 2017-11-21 11:42:15 +02:00
Itay Mizeretz ebeeabee71 remove , 2017-11-14 16:12:50 +02:00
Itay Mizeretz f787801ab7 Add recommendations to security issues 2017-11-14 16:10:22 +02:00
Itay Mizeretz 13d8d4cfc1 Add scanned-exploited pie chart
Merged stolen passwords section
Styled tables' header
2017-11-14 15:49:14 +02:00
Itay Mizeretz f2e6600d88 Add Stolen Passwords section
Add example of every security issue (both overview and recommendation sections)
Add 'Generating Report' waiting text
2017-11-14 14:48:36 +02:00
Itay Mizeretz c9e6d890e7 Add map to report 2017-11-14 10:59:18 +02:00
Itay Mizeretz 0f2c58b0aa Add skeleton and more of report 2017-11-12 20:52:01 +02:00
Itay Mizeretz 3b30cb9f2d Merge remote-tracking branch 'origin/develop' into feature/report-backend
# Conflicts:
#	monkey_island/cc/resources/monkey.py
2017-11-12 16:22:09 +02:00
Itay Mizeretz 545b49919d Remove mimikatz's stolen credentials from machine's list of stolen creds 2017-11-12 16:20:15 +02:00
Itay Mizeretz 80b709b2ac Add reused passwords 2017-11-12 16:13:40 +02:00
Itay Mizeretz be8feeb3ee Add get config value function 2017-11-12 16:11:12 +02:00
Itay Mizeretz be8d20b2f5 Change creds format in monkey document 2017-11-07 17:02:45 +02:00
Itay Mizeretz b284467fbc Add scanned and exploited to report 2017-11-07 16:33:26 +02:00
Itay Mizeretz 1ad37b1dad Fix bug where 'dead' property of monkey wasn't defined 2017-11-07 14:54:11 +02:00
Itay Mizeretz 8d9068fe40 Add known credentials to monkey documents 2017-11-07 14:52:13 +02:00
Itay Mizeretz e9b6b39a21 Add tunnel info to report 2017-11-07 13:17:02 +02:00
Itay Mizeretz a0dc706a1e Merge branch 'develop' into feature/report-backend
# Conflicts:
#	monkey_island/cc/main.py
2017-11-07 09:53:52 +02:00
Daniel Goldberg 05ddc592ec
Merge pull request #69 from guardicore/feature/add-config-import-export
Feature/add config import export
2017-11-02 19:56:09 +02:00
Itay Mizeretz 2b55258e2e Add current page changes to exported config 2017-10-31 17:09:28 +02:00
Itay Mizeretz 5a2eb9dda4 Implemented import/export buttons 2017-10-31 17:05:16 +02:00
Itay Mizeretz 16a470ee22 Add wait for mongodb 2017-10-31 13:55:29 +02:00
Itay Mizeretz 7807a46769 Add all known telemetry types to dict + don't except when unknown telem_type is received
telem_type + data don't have default value
2017-10-18 16:06:03 +03:00
Itay Mizeretz 93d4f08e90 manually infected machines now show all info shown on infected machines 2017-10-18 16:00:52 +03:00
Itay Mizeretz 31357498e5 Remove non-existing module require 2017-10-18 12:10:52 +03:00
Itay Mizeretz fc8449a2d5 where 2017-10-17 17:59:18 +03:00
Itay Mizeretz e644a77e0a Last content adjustments on island 2017-10-17 17:14:12 +03:00
Itay Mizeretz 8a70ac3a8c Remove unecessary code from run server page 2017-10-17 15:30:42 +03:00
Itay Mizeretz c260508ca1 Rephrase content on start over page 2017-10-17 15:04:20 +03:00
Itay Mizeretz 49bd27a799 Remove console from map for now 2017-10-17 15:03:46 +03:00
Itay Mizeretz d726738868 Rename and number pages 2017-10-17 15:03:26 +03:00
Itay Mizeretz 5121a4fe54 Split readme to landing page + license
Make font even across pages
2017-10-17 14:47:33 +03:00
Itay Mizeretz 786993429e no message 2017-10-17 14:43:37 +03:00
Itay Mizeretz c6a5741c96 Force kill only affects live monkeys, and is reset once a monkey is dead 2017-10-17 12:13:46 +03:00
Itay Mizeretz 57e3677fce Show warning of new infections only if monkeys are running 2017-10-17 12:10:23 +03:00
Itay Mizeretz b58c4ea622 Remove relative range option from config 2017-10-17 11:55:27 +03:00
Itay Mizeretz 1011e731af Improve modal boxes 2017-10-17 11:17:41 +03:00
Itay Mizeretz 085f0d2d69 Make font consistent on run-monkey 2017-10-17 11:08:52 +03:00
Itay Mizeretz 9cbe35cddd Run monkey page improved visually 2017-10-17 11:04:13 +03:00
Itay Mizeretz d95515d678 Add tooltips to preview pane 2017-10-16 18:54:13 +03:00
Itay Mizeretz 246c653029 Legend improvement 2017-10-16 18:10:58 +03:00
Itay Mizeretz cb1d4f3445 Merge remote-tracking branch 'origin/develop' into feature/improve-ui 2017-10-16 17:54:19 +03:00
Itay Mizeretz 377a7a3c5e Minor improvements to preview pane 2017-10-16 17:54:00 +03:00
Itay Mizeretz e277bf6694 Add console to map 2017-10-16 17:40:27 +03:00
Itay Mizeretz 7380f93ef8 Remove map legend require 2017-10-16 17:40:11 +03:00
Itay Mizeretz 768cfc3bb1 Change start over to be un-numbered 2017-10-16 17:37:55 +03:00
Itay Mizeretz d247da61a8 Update legend to textual one 2017-10-16 17:37:11 +03:00
Daniel Goldberg f7b8554c26 Merge pull request #60 from guardicore/feature/change-exploit-telemetry
Feature/change exploit telemetry
2017-10-16 17:32:03 +03:00
Itay Mizeretz b3d89937ba Page width varies on screen size 2017-10-16 17:29:43 +03:00
Itay Mizeretz 8675a7bb0b Remove description 2017-10-16 17:28:39 +03:00
Itay Mizeretz 61bc36b9ff Fix CR 2017-10-16 17:07:56 +03:00
Itay Mizeretz 4077ce15e2 Revert "add telemetry console and map legend"
This reverts commit 8b239c66c6.
2017-10-16 16:00:25 +03:00
Barak Argaman 8b239c66c6 add telemetry console and map legend 2017-10-16 15:46:04 +03:00
Itay Mizeretz 739edeff2a Add option to debug server 2017-10-16 10:40:07 +03:00
Itay Mizeretz 22105eabe3 Add basic report logic 2017-10-15 20:06:26 +03:00
Itay Mizeretz 095f05370f emove console log 2017-10-15 18:12:41 +03:00
Itay Mizeretz 484ed3c508 Update node/edge's data regarding exploits 2017-10-15 16:01:39 +03:00
Itay Mizeretz 5a7adf7a48 Split readme page to sections 2017-10-15 13:26:08 +03:00
Itay Mizeretz 13bd4eb8c3 Minor improvements on Run Monkey page 2017-10-15 13:25:50 +03:00
Itay Mizeretz c8df03355b Pages now utilize all available width 2017-10-15 13:25:26 +03:00
Itay Mizeretz 1b558e72be Add readme section 2017-10-10 19:26:25 +03:00
Itay Mizeretz 9b6c008330 Merge remote-tracking branch 'origin/develop' into bugfix/various-island-fixes
# Conflicts:
#	monkey_island/cc/services/config.py
2017-10-09 10:53:32 +03:00
Itay Mizeretz 48790b6ecb Improve map physics 2017-10-08 19:57:41 +03:00
Itay Mizeretz bf5fb10838 Fix CR 2017-10-08 19:23:34 +03:00
Itay Mizeretz 8ba6ccf939 Add warning to reset environment 2017-10-08 17:58:40 +03:00
Itay Mizeretz a2bdf0da90 Add warning to kill all monkeys 2017-10-08 17:11:46 +03:00
Itay Mizeretz a807e3f8b6 Organize and improve documentation of config 2017-10-08 15:36:12 +03:00
Itay Mizeretz e29f95b28e Utilize entire screen for Graph 2017-10-08 14:09:58 +03:00
Itay Mizeretz ff4c68f94c Add warning to unsafe config values 2017-10-04 16:01:01 +03:00
Itay Mizeretz 6197f4253e Improve config buttons and message 2017-10-04 15:26:02 +03:00
Itay Mizeretz f9206ff817 Remove unsafe exploits from default config 2017-10-04 15:25:34 +03:00
Itay Mizeretz 8ecb895244 Change default for victims_max_find
Move things around in config
2017-10-04 14:57:56 +03:00
Itay Mizeretz 70c4a99e83 Add clean node image 2017-10-04 14:08:43 +03:00
Itay Mizeretz 4625378737 minor fixes 2017-10-04 14:07:38 +03:00
Itay Mizeretz 65f5dbeaaf Sleep only *between* life cycles 2017-10-03 15:47:50 +03:00
Itay Mizeretz 65872d9518 Fix SambaCry not working for non-root user 2017-10-02 17:11:51 +03:00
Itay Mizeretz a04f34bb41 Commented out Useless button 2017-10-02 11:59:48 +03:00
Itay Mizeretz fd85bfb044 Add map legend 2017-10-02 11:43:23 +03:00
Itay Mizeretz 48be73bc3f Fix edge width and tunnel edge color 2017-10-01 18:36:23 +03:00
Itay Mizeretz 27d9e8bcee Fix bug in processing tunnel edges 2017-10-01 16:34:11 +03:00
Itay Mizeretz 22ff980923 Merge remote-tracking branch 'origin/develop' into bugfix/various-fixes 2017-10-01 11:36:12 +03:00
Daniel Goldberg e8583a5bd8 Merge pull request #52 from guardicore/feature/pass-the-hash
Feature/pass the hash
2017-09-28 19:27:12 +03:00
Itay Mizeretz 3c345679b3 Change skip exploit if monkey exist to false 2017-09-28 14:44:18 +03:00
Itay Mizeretz cf9fa82b67 Change C&C map physics to something decent 2017-09-28 11:13:00 +03:00
Itay Mizeretz 48ce135194 Merge remote-tracking branch 'origin/develop' into feature/pass-the-hash
# Conflicts:
#	monkey_island/cc/services/config.py
2017-09-27 18:42:25 +03:00
itaymmguardicore 9242fe3232 Merge pull request #51 from guardicore/feature/elasticgroovy
Feature/elasticgroovy
2017-09-27 15:41:40 +03:00
Itay Mizeretz 22ce3d9387 Expand config env variables on demand 2017-09-27 11:24:42 +03:00
Itay Mizeretz 7e2e2aa15f Global config updates of creds now apply to running monkeys
Fix issue caused by moving of the credentials to basic tab
2017-09-26 20:00:56 +03:00
Itay Mizeretz 89b442be58 Implement pass the hash for SMB 2017-09-26 18:11:13 +03:00
Daniel Goldberg 798b2a8794 Add Elastic Exploit to the UI 2017-09-26 15:45:43 +03:00
Itay Mizeretz 5e133b78f3 Hotfix to monkey island pseudo edges 2017-09-26 14:16:17 +03:00
Itay Mizeretz 76d2807a75 Add some package info 2017-09-26 11:54:30 +03:00
Itay Mizeretz 96b1adda36 Fix bug in redirecting to index page 2017-09-26 11:33:08 +03:00
Itay Mizeretz 48b5785ef8 Update config on island 2017-09-26 11:32:35 +03:00
Itay Mizeretz c7ba1b5442 update react-jsonschema-form 2017-09-25 19:12:39 +03:00
Itay Mizeretz 4e223c5ae2 Add force-kill monkey toggle 2017-09-25 11:48:16 +03:00
Itay Mizeretz 1e254b9409 Now accessing a page by url works 2017-09-24 20:12:43 +03:00