November 30, 2022 in activity reports by Esther Onfroy3 minutes
PiRogue Tool Suite is a reboot of PiRanhaLysis project. Today, PiRanhaLysis is used by a lot of people ranging from universities (the University of Yale as an example), activists, NGOs and gets a lot of traction. Too much traction in fact to be maintained in our spare time as we have done until now. Currently, the project is at the proof-of-concept stage. To get to wider adoption by the general public, we need to streamline the build process and smooth the interface. Our goal is to make the project accessible to anyone.
The problem: the lack of open-source means (hardware + software) to assess both privacy and security of mobile devices. Depending on HRD goals, they should want to educate, conduct emergency assessment or off-the-field investigations.
The plan: As with all the other projects we do, we are the first users of the technologies we develop and we aim to provide open-source, low-cost, well maintained, easy to use and easy to build hardware and software.
We have three functioning modes for PTS:
a kiosk mode for anyone who wants to know which servers a mobile device is communicating with
an on-the-field mode
an expert mode for technical people to:
The PiRogue is an open hardware device based on a Raspberry Pi operating as a network router (like any ISP router) analyzing network traffic in real time.
You can check out our work on GitHub at https://github.com/PiRogueToolSuite/ or on our website at https://pts-project.org/.
The software meant to be deployed on NGO infrastructure has now a name: Colander.
We have almost finished the implementation of the different entities managed by Colander and started working on observable enrichment and artifact analysis. Analysis and enrichment are defined in a separate service (colander-analyzers) that can be used without Colander. This service, for the enrichment part, is mainly based on harpoon and will provide the integration with 3rd party services such VirusTotal, RiskIQ, etc.
Colander-analyzers exposes a unified REST API allowing any other tool to request observable enrichment such has whois, VirusTotal report, etc and artifact analysis such as PCAP analysis (based on NFStream and Suricata), APK analysis (based on Pithus) and more.
Finally, we also have defined the UI structure which is split in 5 workspaces:
We are facing issues on the packaging of the latest version of Frida. Find more details at https://github.com/PiRogueToolSuite/pirogue-os/issues/18.