https://hub.docker.com/r/cmdsolutions/secure-cmd
This container can be used with the 3 Musketeers pattern:
docker-compose.yml
version: '3.7'
services:
cli:
image: cmdsolutions/secure-cmd:1.0.0
container_name: secure-cmd
environment:
- SNYK_TOKEN=${SNYK_TOKEN}
- PHONITO_API_TOKEN=${PHONITO_API_TOKEN}
- GITHUB_PERSONAL_ACCESS_TOKEN=${GITHUB_PERSONAL_ACCESS_TOKEN}
- GITLAB_PRIVATE_TOKEN=${GITLAB_PRIVATE_TOKEN}
volumes:
- /var/run/docker.sock:/var/run/docker.sock # Optional: container scanner
- "${HOME}/.aws:/root/.aws"
- ./LOGS:/var/log/cmd # Optional: debugging
- ./DATA:/tmp/cmd # Optional: debugging
- ./aws-escalate:/root/aws-escalate # development only
- ./parsers:/root/parsers # development only
- ./helpers:/root/helpers # development only
- ./runners:/root/runners # development only
- ./scripts:/root/scripts # development only
- ./config.yaml:/root/config.yaml # development only
Makefile
run: .env
docker-compose up
privesc: .env
docker-compose run --rm cli /root/runners/aws-escalate.sh
docker-compose run --rm --entrypoint=/usr/bin/python3 cli /root/parsers/aws-escalation-results.py
docker-compose run --rm --entrypoint=/usr/bin/python3 cli /root/parsers/aws-escalation-asff.py
docker-compose run --rm --entrypoint=/usr/local/bin/aws cli s3 sync /var/log/cmd s3://bucket/path/prefix/logs/
docker-compose run --rm --entrypoint=/usr/local/bin/aws cli s3 sync /tmp/cmd s3://bucket/path/prefix/
secrets: .env
docker-compose run --rm cli /root/runners/clone-repositories.sh
docker-compose run --rm cli /root/runners/git-secrets.sh
docker-compose run --rm --entrypoint=/usr/bin/python3 cli /root/parsers/aws-escalation-results.py
docker-compose run --rm --entrypoint=/usr/local/bin/aws cli s3 sync /var/log/cmd s3://bucket/path/prefix/logs/
docker-compose run --rm --entrypoint=/usr/local/bin/aws cli s3 sync /tmp/cmd s3://bucket/path/prefix/
Using make run takes you to interactive secureCMD shell.
Using make privesc is noninteractive mode for using the secureCMD AWS escalation tool and publish to AWS SecurityHub.
You can add similiar Makefile entries to automate each tool.
Content type
Image
Digest
Size
393.4 MB
Last updated
over 5 years ago
docker pull cmdsolutions/secure-cmd