by John Lukach
The mmi
command line interface (CLI) allows anyone and everyone to triage an operating system (OS) with color-coded output.
Blake3 (B3) hashes of the file content, directory name, file name, and full path are automatically collected when the EC2 Image Builder pipeline executes the getmeta
command.
Artifacts, including the following operating systems, are published weekly as a Poppy Bloom filter.
Capturing the Macintosh artifacts was an adventure with Amazon EC2 Dedicated Hosts, which cost $15.60 daily for the mac2
instance type. The collection will remain manual at that price point as new Amazon Machine Images (AMIs) are released. At least a single dedicated host can be used for multiple OS installations as a waiting game for the next launch after instance termination.
Additional file content classifications are available when a B3 hash is not displayed.
Legitimate files found on default OS installations that threat actors can potentially use to perform malicious intent are flagged; this technique is known as living off the land (LOL).
Code was migrated from Python to Rust; a crate is available to install the binary.
tags: artifacts - blake3 - gtfobins - lolbas - loobins - mmi - poppy