#file-integrity #change-detection

app boobytrap

Detect and Act on unauthorized access of any kind from any source

7 releases

0.1.61 Dec 7, 2024
0.1.6 Nov 18, 2024
0.1.4 Oct 13, 2024
0.1.3 May 7, 2024

#111 in Filesystem

Download history 2/week @ 2024-09-18 8/week @ 2024-09-25 160/week @ 2024-10-09 27/week @ 2024-10-16 4/week @ 2024-10-30 4/week @ 2024-11-06 235/week @ 2024-11-13 80/week @ 2024-11-20 6/week @ 2024-11-27 164/week @ 2024-12-04 24/week @ 2024-12-11

188 downloads per month

MIT license

40KB
851 lines

Boobytrap

(work-in-progress)

Detect and Act on unauthorized access of any kind from any source

Detect and Act on;

- an increase of USB devices
- network issues or network failure
- filesystem changes
- ssh "burn file"

Observed memory usage <100MB to ~1GB

Install

## install binary
cargo install boobytrap
## configure service with discord webhook
boobytrap install-service webhook=https://discordapp.com/api/webhooks/121946119953658680...

Setup

create config/Settings.toml

## General settings
tick_delay_seconds = "5"
fs_tick_delay_seconds = "60"

### File System Integrity
fs_mon_enabled = "true"
fs_mon_dir = ["/etc", "/bin", "$PATH"]
fs_mon_hash_type = "blake3"

### USB Monitor
usb_mon_enabled = "true"
reboot_on_increase_of_usb_devices = "false"
notify_on_increase_of_usb_devices = "true"
unmount_crypt_on_increase_of_usb_devices = "true"

### Burn File Monitor
burn_file_mon_enabled = "false"
unmount_crypt_on_file_burn = "true"
ssh_check_burn_host = "hostname"
ssh_check_burn_user = "root"
ssh_check_burn_key = "/home/user/.ssh/id_rsa"
ssh_check_burn_path = "/root/.config/burn"
ssh_check_burn_check_interval = "30"
burn_path_1 = "/root/test/"

### Network Monitor
net_mon_enabled = "false"

######## Notification settings
discord_webhook_url = "https://discord.com/api/webhooks/"
discord_webhook_avatar_name = "Lazarus"

Development and Collaboration

Feel free to open a pull request, please run the following prior to your submission please!

echo "Run clippy"; cargo clippy -- -D clippy::all
echo "Format source code"; cargo fmt -- --check

Dependencies

~14–25MB
~375K SLoC