
A forensic evidence acquirer

Compiled and tested with Rust 1.50+. Open terminal in the project directory and to compile a release build type
cargo build --release
Debug build can be compiled using
cargo build
Compiled executable is located at target/release/gargamel.exe or target/debug/gargamel.exe, respectively.
If you wish to change the logging level:
src/main.rsLevelFilter::Info to (for example) LevelFilter::Trace for more detailed logging.
LevelFilter::Trace will log everything including passwords.Right now, this app works only on Windows and the target computer must use Windows or Linux.
Make sure to have the following programs in the same directory as Gargamel.
psexec, downloadpaexec, an open source alternative to PsExec, downloadwinpmem, an open source memory image tool, download.
plink and pscp, an open source CLI SSH/SCP clients, downloadSharpRDP, an open source command executor using RDP, downloadWMImplant, as open source PowerShell WMI command executor, download7za.exe, a standalone console version of 7zip archiver, downloadNote: We need both the psexec and paexec. Although both applications are supposed to be functionally equivalent they actually both have different behavior under some circumstances.
Gargamel needs to be launched from an elevated terminal to be fully functional. Currently it does not support the UAC dialog nor any kind of notification when running with limited privileges. When running with limited user privileges, then some operations like target memory dumping will not work.
Assume you want to connect to a computer with the following parameters:
192.168.42.47Janonbusr123The following command will acquire firewall state, network state, logged users, running processes,
active network connections, registry, system & application event logs using PsExec method.
Evidence will be stored in the testResults directory relative to the location of Gargamel.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults
Gargamel will ask you for password of the remote user, in our example the password is nbusr123.
Note that password will be hidden when typing.
It is also possible to specify the password directly as program argument.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -p nbusr123 -o testResults
Assume you want to connect to a computer in a domain with the following parameters:
WORKSPACEJanovPCJanonbusr123The following command will acquire firewall state, network state, logged users, running processes, active network connections, registry, system & application event logs using PsExec method.
gargamel.exe -c JanovPC -u Jano -d WORKSPACE --psexec -o testResults
Or to skip password prompting specify the password directly.
gargamel.exe -c JanovPC -u Jano -d WORKSPACE --psexec -p nbusr123 -o testResults
PsExec is one of the 5 supported connection methods.
You can replace the --psexec with the following options:
--psexec--psrem, if PowerShell remoting is configured on the target machine.--rdp, if RDP is enabled on the target machine.--wmi.--ssh, if the target machine uses Linux.It is possible to use several methods at once. For example to use both PsExec and RDP one can use the following command.
gargamel.exe -c 192.168.42.47 -u Jano --psexec --rdp -o testResults
There is also a special switch --all that is equal to specifying --psexec --rdp --psrem --wmi.
Note: Launch parameters are order-agnostic, i.e. it does not matter in which order the parameters are specified.
To acquire also memory dump, then simply add the -m flag to the program parameters, i.e.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -m
If you wish to acquire ONLY the memory dump without other evidence then use the following command.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -m --no-events-search --no-evidence-search --no-registry-search
This functionality is available only for Windows targets.
Gargamel may run custom Windows CMD or Linux shell commands on remote machine.
First create a file custom-commands.txt with the following content.
# Will be run using any method
ipconfig
# Will run only when launching with at least one of --all, --psexec, --wmi methods
:psexec:wmi ipconfig -all
Results of the above commands will be stored in the directory specified by -o option.
To run the above commands written in custom-commands.txt use the -e switch, i.e.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -e custom-commands.txt
Gargamel is able to download remote files.
First create a file custom-files.txt with the following content.
C:\Users\Public\sss*
C:\Users\Jano\danove.pdf
# This line and the next one will be ignored
# C:\Users\Jano\somBajecny.pptx
Results of the above commands will be stored in the directory specified by -o option.
To run the above commands written in custom-files.txt use the -s switch, i.e.
gargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -s custom-files.txt
All supported switches are described below.
USAGE:
gargamel.exe [FLAGS] [OPTIONS] --user <user>