
Artifact collection tool for *nix systems
fennec is an artifact collection tool written in Rust to be used during incident response on *nix based systems. fennec allows you to write a configuration file that contains how to collect artifacts.
| OS Details | Architecture | Success? | Details |
|---|---|---|---|
| Ubuntu 20.04.3 LTS | x86_64 | ✅ | |
| Ubuntu 19.04 | x86_64 | ✅ | |
| Ubuntu 18.04.6 LTS | x86_64 | ✅ | |
| Ubuntu 17.04 | x86_64 | ✅ | |
| Ubuntu 16.04.7 LTS | x86_64 | ✅ | |
| Ubuntu 15.10 | x86_64 | ✅ | |
| Ubuntu 14.04.6 LTS | x86_64 | ✅ | |
| Ubuntu 13.04 | x86_64 | ✅ | |
| Ubuntu 12.04.5 LTS | x86_64 | ✅ | |
| CentOS 8.4.2105 | x86_64 | ✅ | |
| CentOS 7.9.2009 | x86_64 | ✅ | |
| CentOS 6.10 | x86_64 | ✅ | |
| CentOS 5.11 | x86_64 | ❌ | osquery requires libc >= 2.12 |
| Ubuntu 20.04 | aarch64 | ✅ | |
| MacOS Monterey v12.0.1 | x86_64 | ✅ | configuration tuning is required. If you have experience in MacOS artifact feel free to contribute |
| Oracle Linux Server 7.9 | x86_64 | ✅ |
fennec 0.4.1
AbdulRhman Alfaifi <[email protected]>
Aritfact collection tool for *nix systems
USAGE:
fennec [OPTIONS]
OPTIONS:
-c, --config <FILE>
Sets a custom config file (Embedded : true)
-o, --output <FILE>
Sets output file name [default: ABDULRHMAN-PC.zip]
-l, --log-level <LEVEL>
Sets the log level [default: info] [possible values: trace, debug, info, error]
-f, --log-file <FILE>
Sets the log file name [default: fennec.log]
-u, --upload-artifact <CONFIG>...
Upload configuration string. Supported Protocols:
* s3 : Upload artifact package to S3 bucket (ex. minio)
* Format :
s3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@(http|https)://<HOSTNAME>:<PORT>/<BUCKET_NAME>:<PATH>
* Example (minio): s3://minioadmin:minioadmin@http://192.168.100.190:9000/fennec:/
* aws3 : Upload artifact package to AWS S3 bucket
* Format : aws3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@<AWS_REGOIN>.<BUCKET_NAME>:<PATH>
* Example: aws3://AKIAXXX:[email protected]:/
* scp : Upload artifact package to a server using SCP protocol
* Format : scp://<USERNAME>:<PASSWORD>@<HOSTNAME>:<PORT>:<PATH>
* Example: scp://testusername:[email protected]:22:/dev/shm
-q, --quiet
Do not print logs to stdout
-t, --timeout <SEC>
Sets osquery queries timeout in seconds [default: 60]
-h, --help
Print help information
--non-root
Run Fennec with non root permisions. This isn't recommended, most artifacts require root
permissions
--osquery-path <PATH>
Sets osquery path, if osquery is embedded it will be writen to this path otherwise the
path will be used to spawn osquery instance (Embedded : true) [default: ./osqueryd]
--output-format <FORMAT>
Sets output format [default: jsonl] [possible values: jsonl, csv, kjson]
--show-config
Show the embedded configuration file
--show-embedded
Show the embedded files metadata
-V, --version
Print version information
-c, --config : Use the specified configuration file instead of the embedded configuration-f, --log-file : Change the default name for the log file (default: fennec.log)-h, --help : Print help message-l, --log-level : Change the default log level (default: info)-o, --output : Change the default output file name for the zip file (default: {HOSTNAME}.zip, where hostname is the runtime evaluated machine hostname)--osquery-path : Path to osquery executable, This value will be used based on these conditions:
fennec then extract it and dump it to --osquery-pathfennec then use the osquery binary in the path --osquery-path--output-format : Choose the output format, Supported formats:
-q, --quiet : Do not print logs to stdout--non-root: Run Fennec with non root permissions. By default, Fennec requires root permissions and it will exit with error message if not root.--show-config : Print the embedded configuration then exit--show-embedded : Show embedded files-t, --timeout : Sets the timeout in seconds for each osquery in query artifact type-u, --upload-artifact : Upload artifact package to a remote server. Supported protocoles:
s3 : Upload artifact package to S3 bucket
Format : s3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@(http|https)://:/<BUCKET_NAME>:Example: s3://minioadmin:minioadmin@http://192.168.100.190:9000/fennec:/aws3 : Upload artifact package to AWS S3 bucket
Format : aws3://<ACCESS_KEY>:<SECRET_ACCESS_KEY>@<AWS_REGOIN>.<BUCKET_NAME>:Example: aws3://AKIAXXXXXXXXXXXXXXXXX:[email protected]:/scp : Upload artifact package to a server using SCP protocol
Format : scp://<USERNAME>:<PASSWORD>@<HOSTNAME>:<PORT>:<PATH>Example: scp://testusername:[email protected]:22:/dev/shm-V, --version : Print fennec version then exit