Code Monkey home page Code Monkey logo

chopchopgo's Introduction

go report card

Rapidly Search and Hunt through Linux Forensics Artifacts


ChopChopGo inspired by Chainsaw utilizes Sigma rules for forensics artifact recovery, enabling rapid and comprehensive analysis of logs and other artifacts to identify potential security incidents and threats on Linux.

Features

  • ๐ŸŽฏ Hunt for threats using Sigma detection rules and custom ChopChopGo detection rules
  • โšก Lightning fast, written in go
  • ๐Ÿชถ Clean and lightweight execution and output formats without unnecessary bloat
  • ๐Ÿ’ป Runs on Linux

$ ./ChopChopGo -target syslog -rules ./rules/linux/builtin/syslog/
  โ–„โ–ˆโ–ˆโ–ˆโ–ˆโ–„   โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆ  โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ   โ–ˆโ–ˆโ–“โ–ˆโ–ˆโ–ˆ      โ–„โ–ˆโ–ˆโ–ˆโ–ˆโ–„   โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆ  โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ   โ–ˆโ–ˆโ–“โ–ˆโ–ˆโ–ˆ       โ–„โ–ˆโ–ˆโ–ˆโ–ˆ  โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ
 โ–’โ–ˆโ–ˆโ–€ โ–€โ–ˆ  โ–“โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆโ–’โ–’โ–ˆโ–ˆโ–’  โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆโ–‘  โ–ˆโ–ˆโ–’   โ–’โ–ˆโ–ˆโ–€ โ–€โ–ˆ  โ–“โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆโ–’โ–’โ–ˆโ–ˆโ–’  โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆโ–‘  โ–ˆโ–ˆโ–’    โ–ˆโ–ˆโ–’ โ–€โ–ˆโ–’โ–’โ–ˆโ–ˆโ–’  โ–ˆโ–ˆโ–’
 โ–’โ–“โ–ˆ    โ–„ โ–’โ–ˆโ–ˆโ–€โ–€โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–‘  โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆโ–“โ–’   โ–’โ–“โ–ˆ    โ–„ โ–’โ–ˆโ–ˆโ–€โ–€โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–‘  โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆโ–‘ โ–ˆโ–ˆโ–“โ–’   โ–’โ–ˆโ–ˆโ–‘โ–„โ–„โ–„โ–‘โ–’โ–ˆโ–ˆโ–‘  โ–ˆโ–ˆโ–’
 โ–’โ–“โ–“โ–„ โ–„โ–ˆโ–ˆโ–’โ–‘โ–“โ–ˆ โ–‘โ–ˆโ–ˆ โ–’โ–ˆโ–ˆ   โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–„โ–ˆโ–“โ–’ โ–’   โ–’โ–“โ–“โ–„ โ–„โ–ˆโ–ˆโ–’โ–‘โ–“โ–ˆ โ–‘โ–ˆโ–ˆ โ–’โ–ˆโ–ˆ   โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–„โ–ˆโ–“โ–’ โ–’   โ–‘โ–“โ–ˆ  โ–ˆโ–ˆโ–“โ–’โ–ˆโ–ˆ   โ–ˆโ–ˆโ–‘
 โ–’ โ–“โ–ˆโ–ˆโ–ˆโ–€ โ–‘โ–‘โ–“โ–ˆโ–’โ–‘โ–ˆโ–ˆโ–“โ–‘ โ–ˆโ–ˆโ–ˆโ–ˆโ–“โ–’โ–‘โ–’โ–ˆโ–ˆโ–’ โ–‘  โ–‘   โ–’ โ–“โ–ˆโ–ˆโ–ˆโ–€ โ–‘โ–‘โ–“โ–ˆโ–’โ–‘โ–ˆโ–ˆโ–“โ–‘ โ–ˆโ–ˆโ–ˆโ–ˆโ–“โ–’โ–‘โ–’โ–ˆโ–ˆโ–’ โ–‘  โ–‘   โ–‘โ–’โ–“โ–ˆโ–ˆโ–ˆโ–€โ–’โ–‘ โ–ˆโ–ˆโ–ˆโ–ˆโ–“โ–’โ–‘
 โ–‘ โ–‘โ–’ โ–’  โ–‘ โ–’ โ–‘โ–‘โ–’โ–‘โ–’โ–‘ โ–’โ–‘โ–’โ–‘โ–’โ–‘ โ–’โ–“โ–’โ–‘ โ–‘  โ–‘   โ–‘ โ–‘โ–’ โ–’  โ–‘ โ–’ โ–‘โ–‘โ–’โ–‘โ–’โ–‘ โ–’โ–‘โ–’โ–‘โ–’โ–‘ โ–’โ–“โ–’โ–‘ โ–‘  โ–‘    โ–‘โ–’   โ–’ โ–‘ โ–’โ–‘โ–’โ–‘โ–’โ–‘
   โ–‘  โ–’    โ–’ โ–‘โ–’โ–‘ โ–‘  โ–‘ โ–’ โ–’โ–‘ โ–‘โ–’ โ–‘          โ–‘  โ–’    โ–’ โ–‘โ–’โ–‘ โ–‘  โ–‘ โ–’ โ–’โ–‘ โ–‘โ–’ โ–‘          โ–‘   โ–‘   โ–‘ โ–’ โ–’โ–‘
 โ–‘         โ–‘  โ–‘โ–‘ โ–‘โ–‘ โ–‘ โ–‘ โ–’  โ–‘โ–‘          โ–‘         โ–‘  โ–‘โ–‘ โ–‘โ–‘ โ–‘ โ–‘ โ–’  โ–‘โ–‘          โ–‘ โ–‘   โ–‘ โ–‘ โ–‘ โ–‘ โ–’
 โ–‘ โ–‘       โ–‘  โ–‘  โ–‘    โ–‘ โ–‘              โ–‘ โ–‘       โ–‘  โ–‘  โ–‘    โ–‘ โ–‘                    โ–‘     โ–‘ โ–‘
 โ–‘                                     โ–‘
			By Keyboard Cowboys (M00NL1G7)

Using syslog file: /var/log/messages
 100% |โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ| (67504/67504, 27840 it/s)
+-----------------+--------------------------------+-----------------------------------------+
|    TIMESTAMP    |            MESSAGE             |                  TAGS                   |
+-----------------+--------------------------------+-----------------------------------------+
| Mar  2 20:04:38 | fedora systemd[1]:             | attack.defense_evasion-attack.t1562.004 |
|                 | iptables.service: Deactivated  |                                         |
|                 | successfully.                  |                                         |
| Mar  4 10:19:03 | DESKTOP-RNL1DBO systemd[1]:    | attack.defense_evasion-attack.t1562.004 |
|                 | iptables.service: Deactivated  |                                         |
|                 | successfully.                  |                                         |
+-----------------+--------------------------------+-----------------------------------------+
Processed 67504 syslog events

Quick Start Guide

Downloading and Running

For an all-in-one zip container the ChopChopGo binary, and the official sigma rules to go with it, check out the releases section In this releases section you will also find pre-compiled binary-only versions of ChopChopGo.

If you want to compile ChopChopGo yourself, you can clone the ChopChopGo repo:

git clone https://github.com/M00NLIG7/ChopChopGo.git

and compile the code yourself by running: go build.

Command Examples

./ChopChopGo # Defaults to searching through auditd
./ChopChopGo -target syslog -rules ./rules/linux/builtin/syslog/ # This searches through syslog with the official sigma rules
./ChopChopGo -target journald -rules ./rules/linux/builtin/ # This searches through journald with specified rules

Alternative Output Formats

You may wish to use ChopChopGo in an automated fashion. The CSV and JSON output options are useful for this purpose. With both of these options, the header and progress statistics are not printed to the console.

Each option can be specified using the -out parameter.

CSV
./ChopChopGo -target sylog -rules ./rules/linux/builtin/syslog/ -out csv # This searches through syslog with the official sigma rules, then outputs the data in CSV format
JSON
./ChopChopGo -target syslog -rules ./rules/linux/builtin/syslog/ -out json # This searches through syslog with the official sigma rules, then outputs the data as JSON

chopchopgo's People

Contributors

m00nlig7 avatar weslambert avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.