Skip to content

DN3RO/BMCacheHunter

Repository files navigation

BMCacheHunter

What is BMCacheHunter?

BMCacheHunter serves as both a Threat Hunting and Digital Forensics tool. Originally developed by Nir Saias, Yossi Sassi, and Rotem Lipowitch as a Proof of Concept for BSIDES 2021 TLV (Watch the presentation), it specializes in collecting BMC files from domain computers.

BMC Image

The process involves formatting the BMC files into JPG collages and extracting text using an OCR mechanism (Tesseract).

OCR Image

This tool offers full customization, enabling users to search for specific strings within the RDP "history" of computers within the domain.

SETUP

Installing

  1. Install Tesseract located in the "BSIDES-BMCacheHunter\tools" folder.
  2. Add the Tesseract executable to the Environment path.
  3. Populate the list of computers you wish to examine in the Computer_List.txt file.
  4. Edit the Indication of Compromised in the IOC.txt.

Execute

PS > .\BMCacheHunter.ps1
PS > .\BMCacheHunter.ps1 -ComputerList .\Computer_list.txt -IOCList .\IOC.txt

Licensing

For licensing details and terms of use, refer to the LICENSE file.

Contact Us

For further inquiries, visit 10Root Cyber Security.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published