{"id":13845983,"url":"https://github.com/Lifars/gargamel","last_synced_at":"2025-07-12T03:33:09.688Z","repository":{"id":102140213,"uuid":"247667679","full_name":"Lifars/gargamel","owner":"Lifars","description":"A forensic evidence acquirer","archived":false,"fork":false,"pushed_at":"2021-04-14T14:52:47.000Z","size":509,"stargazers_count":85,"open_issues_count":0,"forks_count":14,"subscribers_count":9,"default_branch":"master","last_synced_at":"2024-08-05T17:45:26.813Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Lifars.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2020-03-16T10:00:23.000Z","updated_at":"2023-09-28T11:12:35.000Z","dependencies_parsed_at":null,"dependency_job_id":"e5266790-453b-4ae5-af02-4d8f79e98c3e","html_url":"https://github.com/Lifars/gargamel","commit_stats":null,"previous_names":[],"tags_count":4,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Lifars%2Fgargamel","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Lifars%2Fgargamel/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Lifars%2Fgargamel/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Lifars%2Fgargamel/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Lifars","download_url":"https://codeload.github.com/Lifars/gargamel/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225791478,"owners_count":17524796,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:04:15.017Z","updated_at":"2024-11-21T19:30:56.891Z","avatar_url":"https://github.com/Lifars.png","language":"Rust","funding_links":[],"categories":["Rust"],"sub_categories":[],"readme":"![alt text](logo.png \"Gargamel\")\n\nGargamel\n========\n\nCompile\n-------\n\nCompiled and tested with Rust 1.50+.\nOpen terminal in the project directory and to compile a release build type\n\n```bash\ncargo build --release\n```\n\nDebug build can be compiled using\n\n```bash\ncargo build\n```\n\nCompiled executable is located at `target/release/gargamel.exe` or `target/debug/gargamel.exe`, respectively.\n\n### Set log level\n\nIf you wish to change the logging level:\n* Open `src/main.rs`\n* On lines 42 and 43 change `LevelFilter::Info` to (for example) `LevelFilter::Trace` for more detailed logging.\n    * Beware that the `LevelFilter::Trace` will log everything including passwords.  \n\nUser guide\n----------\n\nRight now, this app works only on Windows and the target computer must use Windows or Linux.\n\nMake sure to have the following programs in the same directory as Gargamel.\n* `psexec`, [download](https://docs.microsoft.com/en-us/sysinternals/downloads/psexec)\n* `paexec`, an open source alternative to PsExec, [download](https://www.poweradmin.com/paexec/)\n* `winpmem`, an open source memory image tool, [download](https://github.com/Velocidex/c-aff4/releases).\n     * Download the newest executable and rename it to *winpmem.exe*\n* `plink` and `pscp`, an open source CLI SSH/SCP clients, [download](https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html)\n* `SharpRDP`, an open source command executor using RDP, [download](https://github.com/vildibald/SharpRDP/releases/tag/v1.0.0)\n* `WMImplant`, as open source PowerShell WMI command executor, [download](https://github.com/vildibald/WMImplant)\n* `7za.exe`, a standalone console version of 7zip archiver, [download](https://www.7-zip.org/download.html)   \n\nNote: We need both the `psexec` and `paexec`. Although both applications are supposed to be functionally equivalent they actually both have different behavior under some circumstances.\n\n### Unleashing the power of Gargamel\n\nGargamel needs to be launched from an elevated terminal to be fully functional.\nCurrently it does not support the UAC dialog nor any kind of notification when running with limited privileges.\nWhen running with limited user privileges, then some operations like target memory dumping will not work.\n\n#### Basic example\n\nAssume you want to connect to a computer with the following parameters:\n* address `192.168.42.47`\n* username `Jano`\n* password `nbusr123`\n\nThe following command will acquire firewall state, network state, logged users, running processes, \nactive network connections, registry, system \u0026 application event logs using PsExec method.\nEvidence will be stored in the `testResults` directory relative to the location of Gargamel.\n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults\n```\n\nGargamel will ask you for password of the remote user, in our example the password is `nbusr123`.\nNote that password will be hidden when typing.\n\nIt is also possible to specify the password directly as program argument.   \n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -p nbusr123 -o testResults\n```\n\n#### Domain example\n\nAssume you want to connect to a computer in a domain with the following parameters:\n* domain `WORKSPACE`\n* computer name `JanovPC`\n* username `Jano`\n* password `nbusr123`\n\nThe following command will acquire firewall state, network state, logged users, running processes, \nactive network connections, registry, system \u0026 application event logs using PsExec method.\n\n```bash\ngargamel.exe -c JanovPC -u Jano -d WORKSPACE --psexec -o testResults\n```\n\nOr to skip password prompting specify the password directly.\n\n```bash\ngargamel.exe -c JanovPC -u Jano -d WORKSPACE --psexec -p nbusr123 -o testResults\n```\n\n#### Other connection methods\n\nPsExec is one of the 5 supported connection methods.\nYou can replace the `--psexec` with the following options:\n* `--psexec`\n* `--psrem`, if PowerShell remoting is configured on the target machine.\n* `--rdp`, if RDP is enabled on the target machine.\n* `--wmi`.\n* `--ssh`, if the target machine uses Linux.\n\nIt is possible to use several methods at once. \nFor example to use both PsExec and RDP one can use the following command.\n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec --rdp -o testResults\n```\n\nThere is also a special switch `--all` that is equal to specifying `--psexec --rdp --psrem --wmi`.\n\nNote: Launch parameters are order-agnostic, i.e. it does not matter in which order the parameters are specified.\n\n#### Acquire memory\n\nTo acquire also memory dump, then simply add the `-m` flag to the program parameters, i.e.\n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -m\n```\n\nIf you wish to acquire ONLY the memory dump without other evidence then use the following command.\n \n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -m --no-events-search --no-evidence-search --no-registry-search                                                          \n```\n\nThis functionality is available only for Windows targets.\n\n#### Run custom commands\n\nGargamel may run custom Windows CMD or Linux shell commands on remote machine.\n\nFirst create a file `custom-commands.txt` with the following content.\n\n```bash\n# Will be run using any method\nipconfig\n# Will run only when launching with at least one of --all, --psexec, --wmi methods\n:psexec:wmi ipconfig -all\n```  \n\nResults of the above commands will be stored in the directory specified by `-o` option.\n\nTo run the above commands written in `custom-commands.txt` use the `-e` switch, i.e. \n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -e custom-commands.txt                                                           \n```\n\n#### Download custom files\n\nGargamel is able to download remote files.\n\nFirst create a file `custom-files.txt` with the following content.\n\n```bash\nC:\\Users\\Public\\sss*\nC:\\Users\\Jano\\danove.pdf \n# This line and the next one will be ignored\n# C:\\Users\\Jano\\somBajecny.pptx  \n```  \n\n###### Note: Wildcards * and ? are supported but currently only in filenames, not parent directories, i.e. C:\\Users\\J*\\danove.pdf will most likely not work.\n\nResults of the above commands will be stored in the directory specified by `-o` option.\n\nTo run the above commands written in `custom-files.txt` use the `-s` switch, i.e. \n\n```bash\ngargamel.exe -c 192.168.42.47 -u Jano --psexec -o testResults -s custom-files.txt                                                           \n```\n\n#### All options\n\nAll supported switches are described below.\n\n```bash\nUSAGE:\n    gargamel.exe [FLAGS] [OPTIONS] --user \u003cuser\u003e\n\nFLAGS:\n    -a, --all                   Acquire evidence from Windows machine using all supported methods (PsExec, PsRemote,\n                                WMI, RDP).\n        --no-events-search      Disables Windows event logs acquisition.\n        --no-evidence-search    Disables acquisition of evidence that can be usually downloaded quickly (like ipconfig,\n                                firewall status etc..)\n        --no-registry-search    Disables target registry acquisition.\n    -h, --help                  Prints help information\n    -m, --mem-image             Optional: Memory dump of a target Windows machine.\n        --local                 Acquire evidence from local machine.\n        --nla                   Optional: Use network level authentication when using RDP. (Windows targets only)\n        --no-7z                 Optional: Disable 7zip compression for registry \u0026 memory images.This will significantly\n                                decrease the running time, but WMI and RDP connections will probably not work properly.\n                                    (Windows targets only)\n        --psexec                Acquire evidence from Windows machine using PsExec. Requires both PsExec64.exe and\n                                paexec.exe in the current directory or in the path.\n        --psrem                 Acquire evidence from Windows machine using PowerShell. Requires both PsExec64.exe and\n                                paexec.exe in the current directory or in the path.\n        --rdp                   Acquire evidence from Windows machine using RDP. Requires SharpRDP.exe in the current\n                                directory or in the path.\n        --ssh                   Acquire evidence from Linux machine using SSH. Requires both plink.exe and pscp.exe in\n                                the current directory or in the path.\n    -V, --version               Prints version information\n        --wmi                   Acquire evidence from Windows machine using WMI. Requires WMImplant.ps1 in the current\n                                directory or in the path and PowerShell 3.0+ on the host machine.Note: It is necessary\n                                to disable Windows Defender real-time protection (other AVs not tested).\n\nOPTIONS:\n    -c, --computer \u003ccomputer\u003e                        Remote computer address/name. [default: 127.0.0.1]\n    -u, --user \u003cuser\u003e                                Remote user name\n    -d, --domain \u003cdomain\u003e                            Optional: Remote Windows domain\n    -o, --output \u003clocal-store-directory\u003e\n            Name of local directory to store the evidence [default: evidence-output]\n\n    -p, --password \u003cpassword\u003e\n            Optional: Remote user password. Skipping this option will prompt a possibility to put a password in hidden\n            way.To specify an empty password use `-p \"\"`\n\n        --redownload \u003cre-download\u003e\n            Optional: Download and DELETE specified file from target computer. Use this in case of previous failed\n            partially completed operation. For just downloading a file (without deleting it) please use a `search`\n            switch. If you specify a 7zip chunk (.7z.[chunk-number], e.g. .7z.004), then it will also automatically try to\n            download subsequent chunks.Use also with --psexec --psrem, --rdp, --wmi, --all\n\n    -r, --remote-storage \u003cremote-store-directory\u003e\n            Name of remote directory to be used as a temporary storage. (Windows targets only) [default:\n            C:\\Users\\Public]\n\n    -e, --commands \u003ccustom-command-path\u003e             Optional: File with custom commands to execute on remote computer\n\n    -s, --search \u003csearch-files-path\u003e\n            Optional: File with files names to be searched on remote computer. File names supports also `*` and `?`\n            wildcards on file names (but not yet parent directories).\n\n        --key \u003cssh-key\u003e                              Optional: Name/path of SSH private key file. (Linux target only)\n\n        --timeout \u003ctimeout\u003e\n            Optional: Timeout in seconds for long running operations.This option is a workaround for a bug in\n            WMImplant.ps1 amd SharpRDP.exe where finishing of a long running operation cannot sometimes properly close\n            the connection leaving the Gargamel in seemingly frozen state or executing the next operation with the\n            previous one unfinished on target site.Increasing this timeout may solve issues when acquiring registry or\n            memory image from target machine. [default: 300]\n\n```\n\nKnown issues\n------------\n* WMI cannot write its output to a file with symbol `_` in its path/name.\n\nLicensing and Copyright\n-----------------------\nCopyright (C) 2020 LIFARS LLC\n\nAll Rights Reserved\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLifars%2Fgargamel","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FLifars%2Fgargamel","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLifars%2Fgargamel/lists"}