
Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.
A hub for Red Team activity to aid in record keeping, situational awareness and reporting. Stepping Stones provides a web based UI for the team to log activity and generate report snippets. The UI is intended to be rapid enough to be used throughout the engagement, not just in the reporting phase.
Stepping Stones is a Python Django application, so to get a local copy running:
python -m venv .venv.venv\Scripts\activate or source .venv/bin/activate on *nixpip install -r requirements.txtpython manage.py makemigrations background_taskpython manage.py migratepython manage.py runserver and python manage.py process_tasks concurrentlypython manage.py check --deploy to obtain lockdown advice, and then follow a guide such as:
https://docs.djangoproject.com/en/6.0/howto/deployment/On the team server - punch a hole in the firewall to allow Stepping Stones to connect, e.g.
sudo ufw allow proto tcp from 172.31.16.0/20 to any port 50050If running a local copy, when the code has been updated in git and you want the new features:
sudo service ssbot stopsudo service steppingstones stoprm -rf /tmp/stepping-stones-main; unzip /tmp/stepping-stones-main.zip && cp -R /tmp/stepping-stones-main/* /opt/steppingstones.venv\Scripts\activate or source .venv/bin/activate on *nixpip install -r requirements.txtpython manage.py makemigrations background_taskpython manage.py migrate.
python manage.py makemigrations then STOP and contact the Stepping Stones developers - it is important all users are working from the same set of migration scripts and these should be co-ordinated through the developers.sudo service ssbot restartsudo service steppingstones restartjournalctl -u steppingstonesIf you are using the same instance for different jobs and wish to archive the old data then start afresh you can:
mv db.sqlite3 db.sqlite.OLD_CLIENT_NAMEThe system uses SQLite. Backup the db.sqlite3 file in the server's root or via the Web UI periodically to protect your valuable data.
The configured web hook URLs will each be sent a small JSON document on key events. The JSON document always has the structure:
{
"type": "notification type",
"message": "Human readable message"
}
The type field can be one of:
new beacon (A previously unseen beacon has connected to a monitored Team Server)respawned beacon (A previously seen beacon has connected to a monitored Team Server)returned beacon (A beacon that has been explicitly monitored for reconnection has just reconnected)To consume this, you can use a https://make.com scenario, based on the following blueprint:
{"name":"Webhook to iOS","flow":[{"id":1,"module":"gateway:CustomWebHook","version":1,"parameters":{"hook":129792,"maxResults":1},"mapper":{},"metadata":{"designer":{"x":-386,"y":-129},"restore":{"parameters":{"hook":{"data":{"editable":"true"},"label":"My webhook"}}},"parameters":[{"name":"hook","type":"hook:gateway-webhook","label":"Webhook","required":true},{"name":"maxResults","type":"number","label":"Maximum number of results"}],"interface":[{"name":"type","type":"text"},{"name":"message","type":"text"}]}},{"id":8,"module":"ios:SendNotification","version":1,"parameters":{"device":171760},"mapper":{"body":"{{1.message}}","title":"{{1.type}}","action":"","priority":10,"collapsible":false},"metadata":{"designer":{"x":-31,"y":-128},"restore":{"expect":{"action":{"label":"Default"},"priority":{"label":"Deliver immediately"}},"parameters":{"device":{"data":{"editable":"undefined"},"label":"Personal Phone"}}},"parameters":[{"name":"device","type":"device:apn","label":"Device","required":true}],"expect":[{"name":"title","type":"text","label":"Title","required":true},{"name":"body","type":"text","label":"Body"},{"name":"action","type":"select","label":"Action","validate":{"enum":["open_url"]}},{"name":"priority","type":"select","label":"Priority","required":true,"validate":{"enum":[10,5]}},{"name":"collapsible","type":"boolean","label":"Collapse push notifications","required":true}]}}],"metadata":{"instant":true,"version":1,"scenario":{"roundtrips":1,"maxErrors":3,"autoCommit":true,"autoCommitTriggerLast":true,"sequential":false,"confidential":false,"dataloss":false,"dlq":false},"designer":{"orphans":[]},"zone":"eu1.make.com"}}
Import the above blueprint by creating a blank scenario and using the "Import Blueprint" feature under the "..." (More) menu found in the bottom centre of the Web UI.
Two further steps are then required:
Webhooks can be tested via a button on the Stepping Stones webhook page.
Stepping Stones utilises Django's model level permission system, allowing users to be constrained from creating, editing, viewing and deleting each type of data model.
Groups can be found in the /admin console which assign a set of permissions, e.g. suitable for a Client's Blue Team, to any members of that group.
Existing groups are: