62 lines
3.4 KiB
Markdown
62 lines
3.4 KiB
Markdown
```ruby
|
|
██████╗██████╗ ███████╗██████╗ ███████╗███╗ ██╗██╗ ██╗███╗ ███╗
|
|
██╔════╝██╔══██╗██╔════╝██╔══██╗██╔════╝████╗ ██║██║ ██║████╗ ████║
|
|
██║ ██████╔╝█████╗ ██║ ██║█████╗ ██╔██╗ ██║██║ ██║██╔████╔██║
|
|
██║ ██╔══██╗██╔══╝ ██║ ██║██╔══╝ ██║╚██╗██║██║ ██║██║╚██╔╝██║
|
|
╚██████╗██║ ██║███████╗██████╔╝███████╗██║ ╚████║╚██████╔╝██║ ╚═╝ ██║
|
|
╚═════╝╚═╝ ╚═╝╚══════╝╚═════╝ ╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝
|
|
```
|
|
|
|
[](https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/main/PROJECTS/intermediate/credential-enumeration)
|
|
[](https://nim-lang.org)
|
|
[](https://www.gnu.org/licenses/agpl-3.0)
|
|
[](https://attack.mitre.org/techniques/T1552/)
|
|
|
|
> Post-access credential exposure detection for Linux systems, written in Nim.
|
|
|
|
*This is a quick overview. Security theory, architecture, and full walkthroughs are in the [learn modules](#learn).*
|
|
|
|
## What It Does
|
|
|
|
- Scans Linux home directories for exposed credentials across 7 categories
|
|
- Detects unprotected SSH keys, plaintext cloud credentials, browser credential stores, shell history secrets, keyrings, Git tokens, and application credentials
|
|
- Classifies findings by severity based on file permissions and exposure risk
|
|
- Reports in terminal with color-coded output or structured JSON for automation
|
|
- Compiles to a single static binary with zero runtime dependencies
|
|
|
|
## Quick Start
|
|
|
|
```bash
|
|
bash install.sh
|
|
credenum
|
|
```
|
|
|
|
> [!TIP]
|
|
> This project uses [`just`](https://github.com/casey/just) as a command runner. Type `just` to see all available commands.
|
|
>
|
|
> Install: `curl -sSf https://just.systems/install.sh | bash -s -- --to ~/.local/bin`
|
|
|
|
## Stack
|
|
|
|
**Language:** Nim 2.2+ (ORC memory management)
|
|
|
|
**Build:** Just, Nimble, musl (static linking), UPX (compression), zigcc (cross-compilation)
|
|
|
|
**Testing:** Nim unittest, Docker (integration tests with planted credentials)
|
|
|
|
## Learn
|
|
|
|
This project includes step-by-step learning materials covering security theory, architecture, and implementation.
|
|
|
|
| Module | Topic |
|
|
|--------|-------|
|
|
| [00 - Overview](learn/00-OVERVIEW.md) | Prerequisites and quick start |
|
|
| [01 - Concepts](learn/01-CONCEPTS.md) | Security theory and real-world breaches |
|
|
| [02 - Architecture](learn/02-ARCHITECTURE.md) | System design and data flow |
|
|
| [03 - Implementation](learn/03-IMPLEMENTATION.md) | Code walkthrough |
|
|
| [04 - Challenges](learn/04-CHALLENGES.md) | Extension ideas and exercises |
|
|
|
|
## License
|
|
|
|
AGPL 3.0
|