Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
gibson — 프로세스-네트워크 연결을 매핑하고, 클라우드 제공업체를 식별하며, 비콘 활동을 탐지하는 네트워크 모니터링 도구 | Kitploit
도구/GitLabGitLab/hackinglz/gibson
Defensive ToolsOSINT (Open Source Intelligence)ForensicsCloud SecurityRed TeamingIncident ResponseDNS AnalysisAnomaly DetectionLog Analysis
GitLabhackinglz/gibson

gibson

프로세스-네트워크 연결을 매핑하고, 클라우드 제공업체를 식별하며, 비콘 활동을 탐지하는 네트워크 모니터링 도구

137개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기웹사이트

Gibson

프로세스-네트워크 연결을 매핑하고, 클라우드 제공자를 식별하며, 방화벽 규칙을 생성하는 네트워크 모니터링 도구입니다. 수집을 위한 경량 에이전트, 집계를 위한 서버, 분석을 위한 파서로 구성됩니다.

스크린샷

크로스 머신 개요 — OS 버전 비교, 공유 IP 탐지, 모든 호스트에서 비콘 후보: 크로스 머신 분석

호스트별 세부 정보 — 중요 알림 (EOL OS, 알 수 없는 IP로 비콘을 보내는 nc.exe): 호스트 세부 정보 - 중요

호스트별 세부 정보 — 경고 (비콘 후보 플래그 지정): 호스트 세부 정보 - 경고

호스트별 세부 정보 — 정상 (이상 없음): 호스트 세부 정보 - 정상

기능

수집기 (에이전트)

  • 🔒 보안: 선택적 AES-256-GCM 암호화
  • 🗜️ 효율적: 선택적 gzip 압축
  • 🌐 클라우드 업로드: API 키 지원으로 HTTP/HTTPS 업로드
  • 📊 실시간: 스트리밍 데이터 수집
  • 🔍 DNS 해석: 선택적 역방향 DNS 조회
  • 💾 유연한 저장: 쉬운 파싱을 위한 JSONL 형식

파서 (분석기)

  • ☁️ 클라우드 탐지: AWS, Azure, GCP, Cloudflare 등 식별
  • 🔥 방화벽 규칙: iptables/Windows 규칙 자동 생성
  • 📈 위험 점수: 의심스러운 프로세스 식별
  • 🗄️ 데이터베이스 내보내기: 추가 분석을 위한 SQL 내보내기
  • 📊 풍부한 보고서: 세부 인사이트가 포함된 JSON 요약

빠른 시작

빌드

cargo build --release

기본 수집 (5분)

# 간단한 수집
cargo run --release -- collect --duration-seconds 300

# DNS 조회 포함
cargo run --release -- collect --duration-seconds 300 --enable-dns

# 압축 및 암호화 포함
cargo run --release -- collect \
  --duration-seconds 300 \
  --compress \
  --encrypt-key "your-secret-password"

수집된 데이터 파싱

# 모든 보고서 생성
cargo run --release -- parse \
  --input connections.jsonl \
  --process-summary processes.json \
  --cloud-analysis cloud.json \
  --firewall-rules-iptables firewall.sh \
  --database-export network.sql

# 로컬 ASN DB를 이용한 오프라인 소유권 조회 (네트워크 호출 없음)
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud.json \
  --asn-db ip2asn-v4.tsv

# 영구 캐시를 사용한 실시간 ARIN 조회 (재실행 시 이미 조회된 IP는 건너뜀)
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud.json \
  --arin-lookup \
  --arin-cache arin_cache.json

올인원 모니터 모드

# 빠른 5분 분석
cargo run --release -- monitor \
  --duration-seconds 300 \
  --output-dir ./analysis \
  --full-analysis

에이전트 빌드

agent 바이너리는 최소한의, 플래그가 필요 없는 배포 대상입니다. 모든 구성은 컴파일 시 환경 변수를 통해 바이너리에 내장됩니다 — 대상 시스템에 배포하고 인수 없이 실행하기만 하면 됩니다.

빌드

AGENT_SERVER="http://10.0.1.5:8080/upload" \
AGENT_KEY="labkey123" \
AGENT_INTERVAL="5" \
AGENT_BATCH="200" \
AGENT_DURATION="0" \
AGENT_DNS="false" \
AGENT_ENCRYPT_KEY="mysecretpassword" \
cargo build --release --bin agent

결과 바이너리 target/release/agent는 외부 종속성이 없으며 플래그가 필요 없습니다:

./agent

환경 변수

변수기본값설명
AGENT_SERVERhttp://localhost:8080/upload업로드 엔드포인트 URL
AGENT_KEY(없음)X-API-Key 헤더 값
AGENT_INTERVAL5소켓 폴링 간격 (초)
AGENT_BATCH200업로드 배치당 레코드 수
AGENT_DURATION0실행 시간 (초) (0 = 무한 실행)
AGENT_DNSfalseIP를 호스트명으로 해석
AGENT_ESTABLISHEDtrueESTABLISHED 연결만
AGENT_LOCAL_COPYfalse업로드와 함께 로컬 .jsonl 사본 유지
AGENT_COMPRESSfalse업로드 전 gzip 압축
AGENT_ENCRYPT_KEY(없음)AES-256-GCM 페이로드 암호화 (비밀번호 또는 64자 16진수 키)
AGENT_UA(reqwest 기본값)HTTP User-Agent 헤더

예: 암호화된 장기 에이전트

AGENT_SERVER="https://collector.internal/upload" \
AGENT_KEY="prod-api-key" \
AGENT_DURATION="0" \
AGENT_INTERVAL="30" \
AGENT_COMPRESS="true" \
AGENT_ENCRYPT_KEY="$(cat /etc/gibson/key)" \
cargo build --release --bin agent

고급 사용법

안전한 원격 수집

1. 업로드가 있는 암호화된 수집

cargo run --release -- collect \
  --duration-seconds 3600 \
  --interval-seconds 10 \
  --compress \
  --encrypt-key "your-32-char-hex-key-or-password" \
  --upload-url "https://your-server.com/api/upload" \
  --api-key "your-api-key" \
  --batch-size 50 \
  --delete-after-upload

2. 장기 모니터링 (24시간)

cargo run --release -- collect \
  --duration-seconds 86400 \
  --interval-seconds 30 \
  --output connections_daily.jsonl \
  --enable-dns \
  --compress

IP 소유권 조회

파서는 일치하지 않는 IP의 소유자를 식별하기 위해 두 가지 상호 배타적인 경로를 지원합니다:

방법플래그속도네트워크가장 적합한 경우
로컬 ASN DB--asn-db즉시없음반복 분석, 에어갭 환경
실시간 ARIN RDAP--arin-lookup느림 (IP별)있음일회성 조회, 로컬 DB 없을 때

ip2asn 데이터베이스 다운로드 (매주 새로고침):

curl -O https://iptoasn.com/data/ip2asn-v4.tsv.gz && gunzip ip2asn-v4.tsv.gz

--asn-db가 제공되면 --arin-lookup은 무시됩니다. --arin-cache를 사용하여 ARIN 결과를 디스크에 유지하면 재실행 시 이미 조회된 IP를 건너뛸 수 있습니다.

클라우드 제공자 분석

# 클라우드 탐지에 초점을 맞춘 파싱
cargo run --release -- parse \
  --input connections.jsonl \
  --cloud-analysis cloud_report.json \
  --min-connections 5 \
  --whitelist-processes "chrome,firefox,safari,edge"

데이터 수집을 위한 웹 서버 설정

옵션 1: 간단한 Python Flask 서버

collector_server.py 생성:

from flask import Flask, request, jsonify
import os
import json
import base64
from datetime import datetime
from Crypto.Cipher import AES
import gzip

app = Flask(__name__)

# Configuration
UPLOAD_DIR = "./collected_data"
API_KEY = "your-secure-api-key"
ENCRYPTION_KEY = bytes.fromhex("your-32-byte-hex-key")  # Optional

os.makedirs(UPLOAD_DIR, exist_ok=True)

def decrypt_data(encrypted_data, key):
    """Decrypt AES-256-GCM encrypted data"""
    decoded = base64.b64decode(encrypted_data)
    nonce = decoded[:12]
    ciphertext = decoded[12:]
    
    cipher = AES.new(key, AES.MODE_GCM, nonce=nonce)
    plaintext = cipher.decrypt_and_verify(ciphertext[:-16], ciphertext[-16:])
    return plaintext

@app.route('/api/upload', methods=['POST'])
def upload():
    # Verify API key
    if request.headers.get('X-API-Key') != API_KEY:
        return jsonify({"error": "Invalid API key"}), 401
    
    try:
        data = request.get_data()
        
        # If data is base64 encoded (encrypted)
        if data.startswith(b'eyJ'):  # JSON starts with {"
            # Not encrypted, parse directly
            batch = json.loads(data)
        else:
            # Encrypted data
            decrypted = decrypt_data(data, ENCRYPTION_KEY)
            batch = json.loads(decrypted)
        
        # Save to file
        hostname = batch.get('hostname', 'unknown')
        timestamp = datetime.now().strftime('%Y%m%d_%H%M%S')
        filename = f"{UPLOAD_DIR}/{hostname}_{timestamp}.json"
        
        with open(filename, 'w') as f:
            json.dump(batch, f)
        
        return jsonify({"status": "success", "file": filename}), 200
        
    except Exception as e:
        return jsonify({"error": str(e)}), 500

if __name__ == '__main__':
    app.run(host='0.0.0.0', port=5000, ssl_context='adhoc')  # Use proper SSL in production

실행:

pip install flask pycryptodome
python collector_server.py

옵션 2: 기본 업로드가 있는 Nginx

/etc/nginx/sites-available/collector 생성:

server {
    listen 443 ssl;
    server_name collector.yourcompany.com;
    
    ssl_certificate /etc/ssl/certs/your-cert.pem;
    ssl_certificate_key /etc/ssl/private/your-key.pem;
    
    client_max_body_size 100M;
    
    location /upload {
        # API key validation
        if ($http_x_api_key != "your-secure-api-key") {
            return 403;
        }
        
        # Save uploaded files
        client_body_in_file_only on;
        client_body_temp_path /var/uploads/;
        
        # Pass to processing script
        proxy_pass http://localhost:8080;
        proxy_set_header X-File $request_body_file;
    }
}

옵션 3: AWS Lambda 함수

// index.js for AWS Lambda
const AWS = require('aws-sdk');
const crypto = require('crypto');
const s3 = new AWS.S3();
도구 다운로드