Ugly Green Logo

4n6ir.com

Container Registry

GitHub Organization

Grafana Cloud

Slack Workspace

February 09, 2025

Security version of “ls” a.k.a. “dir” command

by John Lukach

The mmi command line interface (CLI) allows anyone and everyone to triage an operating system (OS) with color-coded output.

mmi cli output

Blake3 (B3) hashes of the file content, directory name, file name, and full path are automatically collected when the EC2 Image Builder pipeline executes the getmeta command.

Artifacts, including the following operating systems, are published weekly as a Poppy Bloom filter.

Capturing the Macintosh artifacts was an adventure with Amazon EC2 Dedicated Hosts, which cost $15.60 daily for the mac2 instance type. The collection will remain manual at that price point as new Amazon Machine Images (AMIs) are released. At least a single dedicated host can be used for multiple OS installations as a waiting game for the next launch after instance termination.

Additional file content classifications are available when a B3 hash is not displayed.

Legitimate files found on default OS installations that threat actors can potentially use to perform malicious intent are flagged; this technique is known as living off the land (LOL).

Code was migrated from Python to Rust; a crate is available to install the binary.

tags: artifacts - blake3 - gtfobins - lolbas - loobins - mmi - poppy