Strip OPSEC tool identity fingerprints
Replace all sensor.* logger namespaces with __name__ (generic module identifiers instead of discoverable 'sensor.*' prefixes). Change hardcoded 'bb' API user to 'admin' in config and code defaults. Change hardcoded relay_user 'bb' to 'operator' — prevents network profiling from exposing tool identity via SSH config. Fixes #457, #458, #459
This commit is contained in:
@@ -19,7 +19,7 @@ from typing import Optional
|
||||
from modules.base import BaseModule
|
||||
from utils.credential_encryption import emit_credential_found
|
||||
|
||||
logger = logging.getLogger("sensor.intel.tool_output_parser")
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# -----------------------------------------------------------------------
|
||||
# Responder log patterns
|
||||
@@ -372,8 +372,8 @@ class ToolOutputParser(BaseModule):
|
||||
|
||||
api_host = self.config.get("bettercap", {}).get("host", "127.0.0.1")
|
||||
api_port = self.config.get("bettercap", {}).get("port", 8083)
|
||||
api_user = self.config.get("bettercap", {}).get("user", "bb")
|
||||
api_pass = self.config.get("bettercap", {}).get("password", "bb")
|
||||
api_user = self.config.get("bettercap", {}).get("api_user", "admin")
|
||||
api_pass = self.config.get("bettercap", {}).get("api_password", "")
|
||||
|
||||
base_url = f"http://{api_host}:{api_port}"
|
||||
last_event_id = 0
|
||||
|
||||
Reference in New Issue
Block a user