Skip to content

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 21:26
· 68 commits to main since this release

Canaries now cover the registry as well as your documents.

What is new since v0.2.0

Decoy saved connections in the registry. Documents were only half of where a
thief looks. PuTTY keeps every saved session in the registry with its hostname
and username; WinSCP keeps its sessions there with a reversibly-encrypted
password beside them; the Remote Desktop client records the machines you have
connected to and the account you used. Infostealers enumerate all three, because
that is what maps out the rest of your estate. So there are decoy sessions there
now too, watched the same way, and a read comes back naming the process that did
it.

Each decoy is a subkey alongside any real ones — never a value inside somebody's
own session — and is named KAM-Security-decoy-do-not-use, so anyone who finds
one in their own PuTTY list can tell at a glance that it is not theirs. A stealer
enumerates every session under those paths rather than opening one by name, so a
decoy does not need to deceive anybody to be found.

Switching canaries on now enables both audit subcategories. Registry auditing
is separate from file auditing in Windows, and having only half of it set
produced no registry events at all while looking perfectly healthy — the failure
mode a canary must never have, because it is indistinguishable from an all-clear.

Three fixes that came from running it rather than reading it

  • The registry canaries armed correctly and caught nothing. Windows names a
    registry object in the kernel's namespace with a hive prefix that depends on
    which account is asking, and the code built the expected name from the caller's
    SID — which the agent has and the shell does not. Trips now match on the tail
    of the path, which carries the decoy's own distinctive name.
  • A careless edit had put the planting call inside the read-only status check,
    which the window polls every few seconds. That would have created decoys on a
    machine whose owner never asked for any.
  • The tests genuinely contend on the registry: a scratch profile gives a test its
    own directory, but there is no scratch hive. The tests that touch it are now
    serialised.

Install

Unzip anywhere. Keep both executables in the same folder — the agent only
serves clients installed alongside it, so separating them stops the shell
working.

Run kam-shell.exe. For the fast disk scan, the behaviour watcher and the
canaries, install the agent as a service from an administrator terminal:

kam-agent.exe --install
sc start KamSecurityAgent

Canaries are off until you turn them on, and turning them on is two deliberate
steps: planting the decoys writes files and registry keys, and switching on
Windows' auditing changes a machine-wide setting. Both are reversible and both
are recorded in the audit log.

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them.
That is expected for an unsigned tool that enumerates every file on disk and runs
an elevated service. Verify the checksum against SHA256SUMS.txt, and build from
source if you would rather not trust a download.

There is still no installer. That and the lack of signing are recorded as
deliberate decisions in PLAN.md rather than oversights.