Skip to content

bad lazy version, specifically for jumpcloud logs export to be placed in dumps folder

Notifications You must be signed in to change notification settings

Team-Tritan/Jumpcloud-Attack-Logger

Repository files navigation

Jumpcloud Attack Logs to Discord

This is exactly what the title says lol, it takes jumpcloud exported logs, sifts through them and sends failed attack logs to Discord via webhook. Chinese heckers need to know they aren't safe.

Getting Started

  • Download json of jumpcloud logs daily, weekly, whatever-- it's automated on an interval. Places in ./dump.

  • Install deps, yarn or npm i

  • Install typescript globally, yarn -g typescript ts-node || npm i typescript ts-node -g

  • Fill out config tile, remove .example file extention.

  • Start and let the thing run, it loops every 24 hours and caches what has already been posted for the API. Only posts IPs once, filters out duplicates.

    • yarn dev || npm dev
  • If you're a weirdo and want to compile to javascript:

    • yarn build --> yarn start || npm build --> npm start

Extras

  • Dumps daily IPs into hastebin
  • Posts to discord webhook, with raw dump json file
  • Stores hastebin dumps in ./dump/hastebin_urls.txt
  • Auto cleans storage
  • Has an API that shows both current ones and prior stored URLs
  • Reports attackers to ARIN whois abuse contacts
  • More??? Maybe

Discord Embed

img

About

bad lazy version, specifically for jumpcloud logs export to be placed in dumps folder

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published