-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
split sysinternals (commando-vm vs flare-vm shortcuts) #942
Comments
I'd vote for the environment variable route to avoid future synchronization issues with different packages. For example, if you update Another option is to consider per-package customizations (this is something I've always wanted). I can imagine per-package customizations working as follows:
There would likely need to be a standardized interface for per-package customization options that are supported (e.g., package shortcut mappings). I can image something like the below: FLARE VM:
COMMANDO VM:
|
I am in agreeance with @MalwareMechanic I think env variables would be the quickest route but also this opens an opportunity to build in a new feature (per-package customizations), so that is what would get my vote |
Some of my thoughts...
In all though, I do like the idea of the per-package customization options, and adding it into the |
I think I would prefer keeping package customizations inside of the package, like placing a single |
Just to clarify, a "suite package" is a package that installs a suite of tools like
Good point! We'd likely need a documentation page to cover customizable options for the packages that support customization. A machine readable format could be useful if we wanted a more sophisticated installer that would allow per-package customization. The installer could parse the machine readable documentation and dynamically show the per-package customization options. That'd be cool!
So in terms of "customization" I think the location of the customization is important. If the options are stored in the package itself, then the options can only be updated via a pull request. If they are stored in the We could have the best of both worlds:
In general, I've always wanted per-package customizations at the |
Details
Since f55f6f5 sysinternals is creating a shortcut for ADExplorer in Reconnaissance. Do we want this tool in FLARE-VM? If not, how do we do it to install different shortcuts for flare-vm and command-vm? Ideas:
@mandiant/vms opinions?
The text was updated successfully, but these errors were encountered: