Features

List all the Features

This is an example of the jibril --features command output. It shows the hierarchy of components available in the Jibril system.

┃▸ component (none)
┃▸  β”œβ”€β”¬ libraries (library)
┃▸  β”‚ β”œβ”€β”€ events (library)
┃▸  β”‚ β”œβ”€β”€ settings (library)
┃▸  β”‚ β”œβ”€β”€ cgroups (library)
┃▸  β”‚ β”œβ”€β”€ ebpf (library)
┃▸  β”‚ β”œβ”€β”€ printers (library)
┃▸  β”‚ β”œβ”€β”€ dispatcher (library)
┃▸  β”‚ β”œβ”€β”€ server (library)
┃▸  β”‚ β”œβ”€β”€ environment (library)
┃▸  β”‚ └── ebpfobjs (library)
┃▸  └─┬ extensions (extension)
┃▸    β”œβ”€β”¬ jibril (extension)
┃▸    β”‚ β”œβ”€β”¬ tests (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testtriesuffix (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testfiledirbase (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testtaskargs (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testtaskflow (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testvmap (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testtaskfile (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testfiletask (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testnetpolicy (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testvmapnest (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testallflows (test)
┃▸    β”‚ β”‚ β”œβ”€β”€ testdomains (test)
┃▸    β”‚ β”‚ └── testflows (test)
┃▸    β”‚ β”œβ”€β”¬ libraries (library)
┃▸    β”‚ β”‚ β”œβ”€β”€ pausedb (library)
┃▸    β”‚ β”‚ β”œβ”€β”¬ cachedfiles (library)
┃▸    β”‚ β”‚ β”‚ β”œβ”€β”€ files (library)
┃▸    β”‚ β”‚ β”‚ └── filerefs (library)
┃▸    β”‚ β”‚ β”œβ”€β”¬ cachedflows (library)
┃▸    β”‚ β”‚ β”‚ β”œβ”€β”€ flows (library)
┃▸    β”‚ β”‚ β”‚ β”œβ”€β”€ flowrefs (library)
┃▸    β”‚ β”‚ β”‚ └── dns (library)
┃▸    β”‚ β”‚ β”œβ”€β”¬ cachedtasks (library)
┃▸    β”‚ β”‚ β”‚ └── tasks (library)
┃▸    β”‚ β”‚ β”œβ”€β”€ protocols (library)
┃▸    β”‚ β”‚ └── fileprinter (library)
┃▸    β”‚ β”œβ”€β”¬ printers (plugin)
┃▸    β”‚ β”‚ β”œβ”€β”€ stdout (printer)
┃▸    β”‚ β”‚ β”œβ”€β”€ varlog (printer)
┃▸    β”‚ β”‚ └── garnet (printer)
┃▸    β”‚ └─┬ plugins (plugin)
┃▸    β”‚   β”œβ”€β”€ hold (plugin)
┃▸    β”‚   β”œβ”€β”€ attenuator (plugin)
┃▸    β”‚   β”œβ”€β”€ jbconfig (plugin)
┃▸    β”‚   β”œβ”€β”¬ netpolicy (plugin)
┃▸    β”‚   β”‚ β”œβ”€β”¬ libraries (library)
┃▸    β”‚   β”‚ β”‚ └── netdrops (library)
┃▸    β”‚   β”‚ └─┬ events (plugin)
┃▸    β”‚   β”‚   β”œβ”€β”€ dropdomain (event)
┃▸    β”‚   β”‚   └── dropip (event)
┃▸    β”‚   β”œβ”€β”€ pause (plugin)
┃▸    β”‚   β”œβ”€β”€ procfs (plugin)
┃▸    β”‚   β”œβ”€β”¬ detect (plugin)
┃▸    β”‚   β”‚ β”œβ”€β”¬ events (plugin)
┃▸    β”‚   β”‚ β”‚ β”œβ”€β”¬ execution (plugin)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ net_scan_tool_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ file_attribute_change (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ hidden_elf_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ binary_executed_by_loader (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ crypto_miner_execution (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ exec_from_unusual_dir (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ runc_suspicious_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ net_sniff_tool_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ passwd_usage (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ webserver_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ webserver_shell_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ data_encoder_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ net_filecopy_tool_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ interpreter_shell_spawn (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ net_suspicious_tool_shell (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ net_mitm_tool_exec (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ code_on_the_fly (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ exec_example (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ denial_of_service_tools (event)
┃▸    β”‚   β”‚ β”‚ β”‚ └── net_suspicious_tool_exec (event)
┃▸    β”‚   β”‚ β”‚ β”œβ”€β”¬ fileaccess (plugin)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ environ_read_from_procfs (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ java_instrument_lib_load (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ core_pattern_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ binary_self_deletion (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ code_modification_through_procfs (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ global_shlib_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ cpu_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ crypto_miner_files (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ shell_config_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ sysrq_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ package_repo_config_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ auth_logs_tamper (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ credentials_files_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ machine_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ ssl_certificate_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ unprivileged_bpf_config_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ filesystem_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ java_debug_lib_load (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ sched_debug_access (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ sudoers_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ file_example (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ capabilities_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ os_network_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ os_status_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”‚ β”œβ”€β”€ pam_config_modification (event)
┃▸    β”‚   β”‚ β”‚ β”‚ └── os_fingerprint (event)
┃▸    β”‚   β”‚ β”‚ β”œβ”€β”¬ netflows (plugin)
┃▸    β”‚   β”‚ β”‚ β”‚ └── flow (event)
┃▸    β”‚   β”‚ β”‚ └─┬ netpeers (plugin)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ adult_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ gambling_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ peer_example (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ piracy_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ plaintext_communication (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ vpnlike_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ fake_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ threat_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ tracking_domain_access (event)
┃▸    β”‚   β”‚ β”‚   β”œβ”€β”€ badware_domain_access (event)
┃▸    β”‚   β”‚ β”‚   └── dyndns_domain_access (event)
┃▸    β”‚   β”‚ └─┬ mechanisms (plugin)
┃▸    β”‚   β”‚   └── baseline (plugin)
┃▸    β”‚   └─┬ github (plugin)
┃▸    β”‚     β”œβ”€β”¬ libraries (library)
┃▸    β”‚     β”‚ β”œβ”€β”€ steps (library)
┃▸    β”‚     β”‚ β”œβ”€β”€ workflow (library)
┃▸    β”‚     β”‚ └── ghcontext (library)
┃▸    β”‚     └─┬ printers (plugin)
┃▸    β”‚       β”œβ”€β”€ listendevdebug (printer)
┃▸    β”‚       └── listendev (printer)
┃▸    β”œβ”€β”¬ simple (extension)
┃▸    β”‚ └─┬ printers (plugin)
┃▸    β”‚   └── voidprinter (printer)
┃▸    β”œβ”€β”€ config (extension)
┃▸    β”œβ”€β”¬ data (extension)
┃▸    β”‚ └─┬ libraries (library)
┃▸    β”‚   β”œβ”€β”€ trie (library)
┃▸    β”‚   └── vmap (library)
┃▸    └─┬ example (extension)
┃▸      β”œβ”€β”€ plugins (plugin)
┃▸      β”œβ”€β”€ helloworld (plugin)
┃▸      β”œβ”€β”€ test01 (plugin)
┃▸      └── test02 (plugin)

Last updated