{"repo":"bitsadmin/dir2json","free":true,"listed":false,"github":"https://github.com/bitsadmin/dir2json","clone":"git clone https://github.com/bitsadmin/dir2json.git","description":"Tool for efficient directory enumeration","language":"C#","stars":64,"topics":["bash","enumeration","powershell","redteaming"],"license":"BSD-3-Clause","category":"cli-tools","readme_excerpt":"Dir2json Dir2json is a .NET utility which recursively lists drives or network shares storing the directory listing including various attributes in a (gzipped) .json file. Attributes that are collected are: - Name of the file or directory - Size of the file in bytes - Last Modified date of the file or directory - Attributes of the file or directory (.NET FileAttributes) Dir2json can either be executed from the commandline, or from memory in a Cobalt Strike beacon using @CCob's BOF.NET where Cobalt Strike's in-memory download functionality is used to retrieve the resulting file listing. As a .json file is not as easy to search through, the json2csv.ps1 or json2csv.py scripts convert the (hierarchical) JSON structure to a (flat) CSV file which can be easily queried using PowerShell (examples in CheatSheet.ps1 ) or using tools like grep (examples in CheatSheet.sh ). This utility has been developed for use in Red Team assignments to be able to efficiently perform offline searches for interesting files and directories. At the BITSADMIN blog an in-depth article on this tool is available: Digging for Secrets on Corporate Shares. Latest binaries available from the Releases page. Demos In-memory execution in Cobalt Strike cobaltstrike.mp4 Convert JSON to CSV and query CSV powershell.mp4 Example queries A cheat sheet with various PowerShell queries generating, importing and querying the directory listing can be found in the CheatSheet.ps1 file in this repository. Additionally, CheatShee","default_branch":null,"files":null,"tree":[],"storefront":"/r/bitsadmin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bitsadmin/dir2json/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}