Skip to content

Drive Badger extension: recursively exfiltrate VMware and Hyper-V virtual machines along with virtualization server

License

Notifications You must be signed in to change notification settings

drivebadger/hook-virtual

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

This is an extension for Drive Badger. It provides a so called hook script, that:

  • scans given filesystem for virtual drive image files (*.vmdk for VMware, *.vhd and *.vhdx for Hyper-V)
  • mounts and exfiltrates found files (instead of just copying the whole images to the storage drive)

Installing

Clone this repository as /opt/drivebadger/hooks/hook-virtual directory on your Drive Badger persistent partition.

When you install this hook, you should also install exclude-virtual configuration repository - it excludes additional files: ISO images and Hyper-V virtual machine state files.

Also, you should read notes about fine tuning this hook.

More information

About

Drive Badger extension: recursively exfiltrate VMware and Hyper-V virtual machines along with virtualization server

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages