# BigBrother Module Configuration # Per-module enable/disable and parameters. # Modules gated by hardware tier and engagement phase. # --------------------------------------------------------------------------- # Passive Modules (17) — metadata extraction, zero network noise # --------------------------------------------------------------------------- passive: packet_capture: enabled: true description: "tcpdump wrapper + zstd + AES-256-GCM rotation pipeline" rotation_hours: 1 snap_length: 65535 max_pcap_files: 168 # 1 week at hourly rotation disk_purge_pct: 85 dns_logger: enabled: true description: "Per-host DNS query log to SQLite" batch_size: 1000 flush_interval_s: 60 flag_doh_resolvers: true # Flag DoH blind spots (1.1.1.1, 8.8.8.8, 9.9.9.9) tls_sni_extractor: enabled: true description: "TLS ClientHello SNI extraction to SQLite" credential_sniffer: enabled: true description: "Cleartext + NTLM credential extraction" auto_exfil: true # Immediate push via data_exfil protocols: - ftp - http_basic - http_digest - http_form - snmp - ldap_simple - ntlmv1 - ntlmv2 kerberos_harvester: enabled: true description: "AS-REP/TGS-REP ticket extraction for offline cracking" auto_exfil: true # Tickets expire -- immediate push host_discovery: enabled: true description: "Passive host inventory (ARP/DHCP/mDNS/NetBIOS/SSDP/LLMNR)" dhcp_fingerprinting: true os_fingerprint: enabled: true description: "p0f-style passive TCP/HTTP/DHCP/SMB/SSH fingerprinting" traffic_analyzer: enabled: true description: "Flow tracking, beacon detection, top talkers, bandwidth profiling" beacon_threshold_s: 60 # Min interval to flag as beacon beacon_min_count: 10 # Min occurrences to confirm beacon vlan_discovery: enabled: true description: "802.1Q/DTP/STP/CDP/LLDP/802.1X detection" network_mapper: enabled: true description: "Communication graph construction (all-pairs, protocol/volume)" snapshot_interval_hours: 4 auth_flow_tracker: enabled: true description: "Cross-protocol auth correlation (Kerberos/NTLM/SSH/LDAP)" smb_monitor: enabled: true description: "SMB2/3 share/file access metadata, GPP/SYSVOL detection" cloud_token_harvester: enabled: true description: "Passive AWS/JWT/OAuth token extraction from cleartext HTTP" ldap_harvester: enabled: true description: "LDAP query/response parsing, AD object inventory" rdp_monitor: enabled: true description: "RDP NLA username/hostname/domain extraction" quic_analyzer: enabled: true description: "QUIC Initial packet SNI extraction (RFC 9000/9001)" db_interceptor: enabled: false # Enable per-engagement if DB traffic expected description: "TDS/MySQL/PostgreSQL/Redis/MongoDB login + query metadata" protocols: - mssql - mysql - postgresql - redis - mongodb # --------------------------------------------------------------------------- # Active Modules (9) — operator-enabled, bettercap + tool wrappers # Gated by engagement_phase.mode == active_allowed # --------------------------------------------------------------------------- active: bettercap_mgr: enabled: false description: "Central bettercap orchestrator (REST API lifecycle)" max_restarts: 3 health_poll_interval_s: 10 arp_restore_on_crash: true # Send corrective gratuitous ARPs on crash arp_spoof: enabled: false # OPSEC WARNING: most-detected technique description: "ARP spoofing via bettercap (full-duplex, selective targeting)" targets: [] # Specific IPs only -- never subnet gateway: "auto" dns_poison: enabled: false description: "DNS poisoning via bettercap dns.spoof" domains: {} # domain: target_ip mapping mode: "selective" # selective | all dhcp_spoof: enabled: false description: "DHCPv6 spoofing via bettercap dhcp6.spoof" pool_start: "" pool_end: "" evil_twin: enabled: false description: "hostapd + dnsmasq rogue AP with captive portal" ssid: "" channel: 6 portal: "corporate_login" # Template from templates/captive_portals/ wids_observation_hours: 2 # Run wireless IDS detection before activation ipv6_slaac: enabled: false description: "IPv6 SLAAC spoofing (bettercap dhcp6.spoof + mitm6 WPAD)" responder_mgr: enabled: false description: "Responder subprocess wrapper (LLMNR/NBT-NS/mDNS poisoning)" protocols: llmnr: true nbtns: true mdns: true analyze_mode: false # Analyze only, no poisoning mitmproxy_mgr: enabled: false # OPi Zero 3+ only (100-200MB RAM) description: "mitmproxy transparent mode with addon scripts" addons: - credential_extractor - cloud_token_extractor ca_cn: "" # Override default CA CN to match target PKI ntlm_relay: enabled: false description: "ntlmrelayx subprocess wrapper (SMB/LDAP/ADCS relay)" targets: [] attack: "smb" # smb | ldap | ldaps | http | mssql | adcs # --------------------------------------------------------------------------- # Stealth Modules (12) — OPSEC layer # --------------------------------------------------------------------------- stealth: mac_manager: enabled: true description: "Innocuous MAC profile database + DHCP/TCP stack spoofing" process_disguise: enabled: true description: "Rename all processes (Python/bettercap/tcpdump) to system services" log_suppression: enabled: true description: "rsyslog filter, auditd exclusion, journald rate-limit, history clear" encrypted_storage: enabled: true description: "LUKS encrypted storage with network-derived key" tmpfs_manager: enabled: true description: "tmpfs for active module working dirs (power loss = destruction)" watchdog: enabled: true description: "Monitor all services + subprocesses, auto-restart (max 3)" anti_forensics: enabled: true description: "Timestomp, secure deletion, no core dumps, no swap" traffic_mimicry: enabled: true description: "Shape implant traffic to match 48h baseline patterns" ja3_spoofer: enabled: true description: "Chrome/Firefox/Edge JA3 on all outbound HTTPS" ids_tester: enabled: true description: "Check planned actions against Snort/Suricata rules" lkm_rootkit: enabled: false # Debian host only, requires kernel headers description: "LKM to hide processes/files/connections from /proc" overlayfs_manager: enabled: true description: "Read-only root FS + tmpfs overlay (zero SD writes)" # --------------------------------------------------------------------------- # Intelligence Modules (9) — on-device analysis + aggregation # --------------------------------------------------------------------------- intel: credential_db: enabled: true description: "Central credential store (bettercap/Responder/mitmproxy ingestion)" dedup: true export_formats: - hashcat - csv - json topology_mapper: enabled: true description: "Network topology aggregation + Graphviz DOT/SVG output" net_intel: enabled: true description: "Beacon/C2 detection, anomaly baseline, service dependency mapping" user_timeline: enabled: true description: "Per-user activity timeline (logins, services, files, websites)" supply_chain_detect: enabled: true description: "Detect internal repos, WSUS, CA, SCCM, container registries, CI/CD" change_detector: enabled: true description: "Continuous baseline diff (new hosts, services, scan activity)" check_interval_s: 300 security_posture: enabled: true description: "Detect EDR/SIEM/NAC/honeypots/vuln scanners/network taps" operator_audit: enabled: true description: "Append-only HMAC-chained SSH session + command audit trail" tool_output_parser: enabled: true description: "Parse bettercap events, Responder logs, mitmproxy flows" # --------------------------------------------------------------------------- # Connectivity Modules (8) — operator access + data exfil # --------------------------------------------------------------------------- connectivity: wireguard: enabled: true description: "Primary C2 -- zero traffic when idle, instant on demand" persistent_keepalive: 0 # Silent until operator connects tailscale: enabled: false # Only if WG blocked or target has existing TS traffic description: "Fallback mesh VPN via Tailscale" bridge: enabled: false description: "Transparent inline bridge (802.1X bypass, STP/CDP suppression)" failsafe_timeout_s: 15 # C watchdog failsafe wifi_client: enabled: false description: "WPA2-PSK/Enterprise WiFi client via wpa_supplicant" reverse_tunnel: enabled: false description: "autossh reverse SSH (over WebSocket or TLS, never raw on 443)" cellular_backup: enabled: false # OPi Zero 3+ only (13-pin header USB) description: "LTE modem out-of-band backup (SIM7600/EC25)" ble_emergency: enabled: false description: "BLE GATT server for emergency status/kill/reboot (PSK auth)" data_exfil: enabled: true description: "Priority push (creds), nightly sync (intel), on-demand pull (PCAPs)" cred_push_immediate: true intel_sync_hour: 3 # 03:00 local time respect_mimicry: true # Shape to baseline traffic patterns