Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Fennec — Artifact collection tool for *nix systems | Kitploit
Tools/GitHubGitHub/abdulrhmanalfaifi/fennec
ForensicsInformation GatheringDigital ForensicsThreat IntelligenceIncident ResponseLog Analysis
GitHubabdulrhmanalfaifi/fennec

Fennec

Artifact collection tool for *nix systems

View Repository
22020162 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Fennec 🦊

fennec is an artifact collection tool written in Rust to be used during incident response on *nix based systems. fennec allows you to write a configuration file that contains how to collect artifacts.

Features 🌟

  • 🦀 A single statically compiled binary
  • 🔬 Execute any osquery SQL query
  • 💻 Execute system commands and parse there output
  • 📚 Parse any text file using regex
  • 🧰 Ability to collect system logs and files
  • 🧱 Return data in structured manner
  • 🃏 Support multiple output formats (JSONL, CSV and KJSON)
  • 🤸‍♀️ Flexible configuration file
  • 💾 Directly write to ZIP file to save space
  • ⚡ Very fast!

Tests 🧪

OS DetailsArchitectureSuccess?Details
Ubuntu 20.04.3 LTSx86_64✅
Ubuntu 19.04x86_64✅
Ubuntu 18.04.6 LTSx86_64✅
Ubuntu 17.04x86_64✅
Ubuntu 16.04.7 LTSx86_64✅
Ubuntu 15.10x86_64✅
Ubuntu 14.04.6 LTSx86_64✅
Ubuntu 13.04x86_64✅
Ubuntu 12.04.5 LTSx86_64✅
CentOS 8.4.2105x86_64✅
CentOS 7.9.2009x86_64✅
CentOS 6.10x86_64✅
CentOS 5.11x86_64❌osquery requires libc >= 2.12
Ubuntu 20.04aarch64✅
MacOS Monterey v12.0.1x86_64✅configuration tuning is required. If you have experience in MacOS artifact feel free to contribute
Oracle Linux Server 7.9x86_64✅

Usage ✍

fennec 0.4.1
AbdulRhman Alfaifi <[email protected]>
Aritfact collection tool for *nix systems

USAGE:
    fennec [OPTIONS]

OPTIONS:
    -c, --config <FILE>
            Sets a custom config file (Embedded : true)

    -o, --output <FILE>
            Sets output file name [default: ABDULRHMAN-PC.zip]

    -l, --log-level <LEVEL>
            Sets the log level [default: info] [possible values: trace, debug, info, error]

    -f, --log-file <FILE>
            Sets the log file name [default: fennec.log]

    -u, --upload-artifact <CONFIG>...
            Upload configuration string. Supported Protocols:
            * s3 : Upload artifact package to S3 bucket (ex. minio)
                * Format :
            s3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@(http|https)://<HOSTNAME>:<PORT>/<BUCKET_NAME>:<PATH>
                * Example (minio): s3://minioadmin:minioadmin@http://192.168.100.190:9000/fennec:/
            * aws3 : Upload artifact package to AWS S3 bucket
                * Format : aws3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@<AWS_REGOIN>.<BUCKET_NAME>:<PATH>
                * Example: aws3://AKIAXXX:[email protected]:/
            * scp : Upload artifact package to a server using SCP protocol
                * Format : scp://<USERNAME>:<PASSWORD>@<HOSTNAME>:<PORT>:<PATH>
                * Example: scp://testusername:[email protected]:22:/dev/shm

    -q, --quiet
            Do not print logs to stdout

    -t, --timeout <SEC>
            Sets osquery queries timeout in seconds [default: 60]

    -h, --help
            Print help information

        --non-root
            Run Fennec with non root permisions. This isn't recommended, most artifacts require root
            permissions

        --osquery-path <PATH>
            Sets osquery path, if osquery is embedded it will be writen to this path otherwise the
            path will be used to spawn osquery instance (Embedded : true) [default: ./osqueryd]

        --output-format <FORMAT>
            Sets output format [default: jsonl] [possible values: jsonl, csv, kjson]

        --show-config
            Show the embedded configuration file

        --show-embedded
            Show the embedded files metadata

    -V, --version
            Print version information
  • -c, --config : Use the specified configuration file instead of the embedded configuration
  • -f, --log-file : Change the default name for the log file (default: fennec.log)
  • -h, --help : Print help message
  • -l, --log-level : Change the default log level (default: info)
  • -o, --output : Change the default output file name for the zip file (default: {HOSTNAME}.zip, where hostname is the runtime evaluated machine hostname)
  • --osquery-path : Path to osquery executable, This value will be used based on these conditions:
    • If osquery binary is embedded into fennec then extract it and dump it to --osquery-path
    • If osquery is not embedded into fennec then use the osquery binary in the path --osquery-path
  • --output-format : Choose the output format, Supported formats:
    • jsonl : A new line separated JSON objects (default)
    • csv: Comma separated values
    • kjson: Use this format if you want to upload the resulting file to Kuiper analysis platform.
  • -q, --quiet : Do not print logs to stdout
  • --non-root: Run Fennec with non root permissions. By default, Fennec requires root permissions and it will exit with error message if not root.
  • --show-config : Print the embedded configuration then exit
  • --show-embedded : Show embedded files
  • -t, --timeout : Sets the timeout in seconds for each osquery in query artifact type
  • -u, --upload-artifact : Upload artifact package to a remote server. Supported protocoles:
    • s3 : Upload artifact package to S3 bucket
      • Format : s3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@(http|https)://:/<BUCKET_NAME>:
      • Example: s3://minioadmin:minioadmin@http://192.168.100.190:9000/fennec:/
    • aws3 : Upload artifact package to AWS S3 bucket
      • Format : aws3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@<AWS_REGOIN>.<BUCKET_NAME>:
      • Example: aws3://AKIAXXXXXXXXXXXXXXXXX:[email protected]:/
    • scp : Upload artifact package to a server using SCP protocol
      • Format : scp://<USERNAME>:<PASSWORD>@<HOSTNAME>:<PORT>:<PATH>
      • Example: scp://testusername:[email protected]:22:/dev/shm
  • -V, --version : Print fennec version then exit

Compile with dependencies 👨‍💻

Download Tool