Sign inSign up

chopicalqui/kali-intelligence-suite

By chopicalqui

•Updated over 4 years ago

Kali Intelligence Suite (KIS) shall aid in the comprehensive collection of intelligence.

Image
1

781

chopicalqui/kali-intelligence-suite repository overview

⁠Kali Intelligence Suite

Kali Intelligence Suite (KIS) is an intelligence gathering and data mining tool for penetration testers. It shall aid in the fast, autonomous, central, and comprehensive collection of intelligence by automatically:

  • executing Kali Linux tools (e.g., dnsrecon, gobuster, hydra, nmap, etc.)
  • querying publicly available APIs (e.g., Censys.io, Haveibeenpwned.com, Hunter.io, Securitytrails.com, Shodan.io, etc.)
  • sending the collected data to third-party applications like Burp Suite Professional or Aquatone
  • storing the collected data in a central PostgreSQL database
  • providing an interface to query and analyze the gathered intelligence

For more information, refer to KIS' GitHub repository⁠.

⁠Installing KIS

This section describes the deployment of KIS. The provided setup commands are examples that illustrate how the setup process works in general. The commands were tested on OS X and Kali Linux.

On our Docker host machine, we pull the Docker images of KIS and PostgreSQL:

docker pull docker.io/chopicalqui/kali-intelligence-suite:latest
docker pull docker.io/postgres:latest

Afterwards, we create a KIS directory in our home directory and download KIS' docker-compose.yml⁠ file there:

mkdir ~/.kis
wget https://raw.githubusercontent.com/chopicalqui/KaliIntelligenceSuite/main/docker-compose.yml -O ~/.kis/docker-compose.yml

In the KIS directory, we create the file ~/.kis/postgres.txt, which contains the password for the PostgreSQL database:

pwgen -s 30 -N1 > ~/.kis/postgres.txt

This password file will be used by the KIS and PostgreSQL Docker containers.

Afterwards, we make sure that the docker-compose.yml⁠ file contains the correct path to the newly created password file ~/.kis/postgres.txt:

sed -ie 's/^\(.*file:\).*\/postgres.txt$/\1 ~\/.kis\/postgres.txt/' ~/.kis/docker-compose.yml

We start the Docker environment and initialize the KIS database:

docker-compose --file ~/.kis/docker-compose.yml run -d --name kaliintelsuite kaliintelsuite
docker exec -it kaliintelsuite kismanage database --init

Optionally, we can also add API keys for Censys.io, Shodan.io, Burp Suite Professional, etc. as well as verify KIS' setup:

docker exec -it kaliintelsuite bash
kis_shell> vim configs/api.config
kis_shell> kismanage database --test
kis_shell> exit

⁠Updating KIS

We recommend updating KIS only after completing all currently ongoing projects, where KIS is used, for the following reasons:

  1. The new version of KIS might use an updated database model, which differs from the currently deployed database model. Although KIS tries to automatically migrate the deployed database model to the latest available version, migrating might still fail.
  2. In Kali, tools regularly update their command line arguments as well as their output formats. Such updates must be incorporated into KIS as well, so that KIS is able to successfully execute the respective commands as well as correctly parse their outputs. As a result, updating KIS during an engagement might lead to inconsistencies where already executed commands are executed again or the outputs of already collected data cannot be re-analyzed anymore due to the updated output parser.

Therefore, the following activities should be performed before updating the Docker image to ensure that the current state can be restored:

  1. We create a backup of our current KIS database by executing the following commands. Note that we have to set the Bash variable database_backup_file to a persistent file path (e.g. ~/.kis/kis_before-update.sql):
database_backup_file=TODO
docker exec -t kaliinteldb pg_dumpall -c -U kis > $database_backup_file
  1. We create a backup of our current KIS docker image. Note that we have to set the Bash variable docker_backup_file to a persistent file path (e.g. ~/.kis/kis_docker.img)
docker_backup_file=TODO
docker save chopicalqui/kali-intelligence-suite > $docker_backup_file

Next, we pull the new Docker image:

docker pull chopicalqui/kali-intelligence-suite:latest

Finally, we stop and remove the currently running Docker container and start the updated Docker image:

docker stop kaliintelsuite
docker container rm kaliintelsuite
docker-compose --file ~/.kis/docker-compose.yml run -d --name kaliintelsuite kaliintelsuite

⁠Author

Lukas Reiter (@chopicalquy⁠) - Kali Intelligence Suite⁠

⁠License

This project is licensed under the GPLv3 License - see the license⁠ file for details.

Tag summary

Content type

Image

Digest

Size

1.8 GB

Last updated

over 4 years ago

docker pull chopicalqui/kali-intelligence-suite