Skip to content

Repository files navigation

wabbit

the stupidest blue team rootkit ever

THIS IS FOR EDUCATIONAL USE BY BLUE TEAMS IN REGULATED CTFs ONLY. DO NOT USE THIS TO COMMIT CRIMES. IT WILL BE REALLY BAD AT IT.

NOT an edr

Prerequisites

  1. stable rust toolchains: rustup toolchain install stable
  2. nightly rust toolchains: rustup toolchain install nightly --component rust-src
  3. (if cross-compiling) rustup target: rustup target add ${ARCH}-unknown-linux-musl
  4. (if cross-compiling) LLVM: (e.g.) brew install llvm (on macOS)
  5. bpf-linker: cargo install bpf-linker (--no-default-features on macOS)

Build & Run

Use cargo build, cargo check, etc. as normal. Run your program with:

cargo run --release

Cargo build scripts are used to automatically build the eBPF correctly and include it in the program.

The wabbit-initrd binary is a small initrd entry point for applying the same RootFSConfig policy without starting the main tracer or IPC server:

WABBIT_FILESYSTEM_CONFIGURATION_FILE=/etc/wabbit/rootfs.json \
  wabbit-initrd --outer
wabbit-initrd --namespace --inner

Use --outer before entering a private namespace and --inner after entering one. The --namespace option creates and privatizes a mount namespace before applying the inner policy.

When running with WABBIT_READ_ONLY_PATHS and WABBIT_WRITABLE_PATHS (both JSON arrays of paths), wabbit exposes a Unix-domain IPC socket to the namespace process. A client can use wabbit::ipc::NamespaceIpc::connect(socket_path) and call reconfigure_filesystems with one of the RootFSConfig fields and PathOverride entries to describe writable and executable mounts. apply_rootfs_config(&config, false) applies the outer policy, while apply_rootfs_config(&config, true) applies the inner policy after entering a private namespace.

Cross-compiling on macOS

Cross compilation should work on both Intel and Apple Silicon Macs.

cargo build --package wabbit --release \
  --target=${ARCH}-unknown-linux-musl \
  --config=target.${ARCH}-unknown-linux-musl.linker=\"rust-lld\"

The cross-compiled program target/${ARCH}-unknown-linux-musl/release/wabbit can be copied to a Linux server or VM and run there.

License

With the exception of eBPF code, wabbit is distributed under the terms of either the MIT license or the Apache License (version 2.0), at your option.

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this crate by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

eBPF

All eBPF code is distributed under either the terms of the GNU General Public License, Version 2 or the MIT license, at your option.

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this project by you, as defined in the GPL-2 license, shall be dual licensed as above, without any additional terms or conditions.

About

toolkit for cool blue teamers :3

Resources

Stars

0 stars

Watchers

0 watching

Forks

Used by

Contributors

Languages