Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gibson — Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity | Kitploit
Tools/GitLabGitLab/hackinglz/gibson
Defensive ToolsOSINT (Open Source Intelligence)ForensicsCloud SecurityRed TeamingIncident ResponseDNS AnalysisAnomaly DetectionLog Analysis
GitLabhackinglz/gibson

gibson

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

137 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View RepositoryWebsite
Share

Gibson

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and generates firewall rules. Lightweight agent for collection, server for aggregation, parser for analysis.

Screenshots

Cross-machine overview — OS version comparison, shared IP detection, beaconing candidates across all hosts: Cross-machine analysis

Per-host detail — critical alerts (EOL OS, nc.exe beaconing to unknown IP): Host detail - critical

Per-host detail — warning (beacon candidate flagged): Host detail - warning

Per-host detail — clean (no anomalies): Host detail - clean

Features

Collector (Agent)

  • 🔒 Secure: Optional AES-256-GCM encryption
  • 🗜️ Efficient: Optional gzip compression
  • 🌐 Cloud Upload: HTTP/HTTPS upload with API key support
  • 📊 Real-time: Streaming data collection
  • 🔍 DNS Resolution: Optional reverse DNS lookups
  • 💾 Flexible Storage: JSONL format for easy parsing

Parser (Analyzer)

  • ☁️ Cloud Detection: Identifies AWS, Azure, GCP, Cloudflare, etc.
  • 🔥 Firewall Rules: Auto-generates iptables/Windows rules
  • 📈 Risk Scoring: Identifies suspicious processes
  • 🗄️ Database Export: SQL export for further analysis
  • 📊 Rich Reports: JSON summaries with detailed insights

Quick Start

Build

cargo build --release

Basic Collection (5 minutes)

# Simple collection
cargo run --release -- collect --duration-seconds 300

# With DNS lookups
cargo run --release -- collect --duration-seconds 300 --enable-dns

# With compression and encryption
cargo run --release -- collect \
  --duration-seconds 300 \
  --compress \
  --encrypt-key "your-secret-password"

Parse Collected Data

# Generate all reports
cargo run --release -- parse \
  --input connections.jsonl \
  --process-summary processes.json \
  --cloud-analysis cloud.json \
  --firewall-rules-iptables firewall.sh \
  --database-export network.sql

# Offline ownership lookup with local ASN DB (no network calls)
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud.json \
  --asn-db ip2asn-v4.tsv

# Live ARIN lookup with persistent cache (re-run skips already-queried IPs)
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud.json \
  --arin-lookup \
  --arin-cache arin_cache.json

All-in-One Monitor Mode

# Quick 5-minute analysis
cargo run --release -- monitor \
  --duration-seconds 300 \
  --output-dir ./analysis \
  --full-analysis

Agent Build

The agent binary is a minimal, zero-flag deployment target. All configuration is burned into the binary at compile time via environment variables — drop it on a target and run it with no arguments.

Build

AGENT_SERVER="http://10.0.1.5:8080/upload" \
AGENT_KEY="labkey123" \
AGENT_INTERVAL="5" \
AGENT_BATCH="200" \
AGENT_DURATION="0" \
AGENT_DNS="false" \
AGENT_ENCRYPT_KEY="mysecretpassword" \
cargo build --release --bin agent

The resulting binary at target/release/agent has no external dependencies and requires no flags:

./agent

Environment Variables

VariableDefaultDescription
AGENT_SERVERhttp://localhost:8080/uploadUpload endpoint URL
AGENT_KEY(none)X-API-Key header value
AGENT_INTERVAL5Socket poll interval in seconds
AGENT_BATCH200Records per upload batch
AGENT_DURATION0Run duration in seconds (0 = run forever)
AGENT_DNSfalseResolve IPs to hostnames
AGENT_ESTABLISHEDtrueESTABLISHED connections only
AGENT_LOCAL_COPYfalseKeep a local .jsonl copy alongside uploads
AGENT_COMPRESSfalseGzip compress before upload
AGENT_ENCRYPT_KEY(none)AES-256-GCM encrypt payload (password or 64-char hex key)
AGENT_UA(reqwest default)HTTP User-Agent header

Example: Encrypted, Long-term Agent

AGENT_SERVER="https://collector.internal/upload" \
AGENT_KEY="prod-api-key" \
AGENT_DURATION="0" \
AGENT_INTERVAL="30" \
AGENT_COMPRESS="true" \
AGENT_ENCRYPT_KEY="$(cat /etc/gibson/key)" \
cargo build --release --bin agent

Advanced Usage

Secure Remote Collection

1. Encrypted Collection with Upload

cargo run --release -- collect \
  --duration-seconds 3600 \
  --interval-seconds 10 \
  --compress \
  --encrypt-key "your-32-char-hex-key-or-password" \
  --upload-url "https://your-server.com/api/upload" \
  --api-key "your-api-key" \
  --batch-size 50 \
  --delete-after-upload

2. Long-term Monitoring (24 hours)

cargo run --release -- collect \
  --duration-seconds 86400 \
  --interval-seconds 30 \
  --output connections_daily.jsonl \
  --enable-dns \
  --compress

IP Ownership Lookup

The parser supports two mutually exclusive paths for identifying who owns unmatched IPs:

MethodFlagSpeedNetworkBest for
Local ASN DB--asn-dbInstantNoneRepeated analysis, air-gapped environments
Live ARIN RDAP--arin-lookupSlow (per-IP)YesOne-off lookups, no local DB available

Download the ip2asn database (refresh weekly):

curl -O https://iptoasn.com/data/ip2asn-v4.tsv.gz && gunzip ip2asn-v4.tsv.gz

When --asn-db is provided, --arin-lookup is ignored. Use --arin-cache to persist ARIN results to disk so re-runs skip already-queried IPs.

Cloud Provider Analysis

# Parse with cloud detection focus
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud_report.json \
  --min-connections 5 \
  --whitelist-processes "chrome,firefox,safari,edge"

Web Server Setup for Data Collection

Option 1: Simple Python Flask Server

Create collector_server.py:

from flask import Flask, request, jsonify
import os
import json
import base64
from datetime import datetime
from Crypto.Cipher import AES
import gzip

app = Flask(__name__)

# Configuration
UPLOAD_DIR = "./collected_data"
API_KEY = "your-secure-api-key"
ENCRYPTION_KEY = bytes.fromhex("your-32-byte-hex-key")  # Optional

os.makedirs(UPLOAD_DIR, exist_ok=True)

def decrypt_data(encrypted_data, key):
    """Decrypt AES-256-GCM encrypted data"""
    decoded = base64.b64decode(encrypted_data)
    nonce = decoded[:12]
    ciphertext = decoded[12:]
    
    cipher = AES.new(key, AES.MODE_GCM, nonce=nonce)
    plaintext = cipher.decrypt_and_verify(ciphertext[:-16], ciphertext[-16:])
    return plaintext
Download Tool