[Bug] Duplicate File Logs for Emulations
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 52/100
Research direction
Start in BaseEmulation and inspect how the console and file handlers are attached to self.elogger. Reproduce the issue through SWAT Shell with an OOTB emulation, then review its file in logs/. Done means each self.elogger.* call appears only once in the respective emulation log.
Written by the indexing model from the issue text.
Description
🐛 Bug Report
Describe the bug
When running an emulation, there is a separate console and file handler set to self.elogger within BaseEmulation. This allows emulations to use a secondary logger to separate logging. The log files written to are within the logs/ directory where the log file name represents the emulation.
There is a bug currently that is duplicating logs within each respective emulation log file.
Steps to reproduce
Steps to reproduce the behavior:
- Start SWAT Shell
- Authenticate with OAuth credentials
- Run any OOTB emulation
- Review log file in
logs/
Expected behavior
The logging should only be happening once per self.elogger.* call.
Screenshots
2023-08-12 15:15:32,486 - initial_access.gmail_phishing_form_link - INFO - Created Google Form: 17b0DwhmBY0Ihv_q85zuZj2fJdPYOFQuiuhuZvbGSgAg (gmail_phishing_form_link.py:47)
2023-08-12 15:15:32,486 - initial_access.gmail_phishing_form_link - INFO - Created Google Form: 17b0DwhmBY0Ihv_q85zuZj2fJdPYOFQuiuhuZvbGSgAg (gmail_phishing_form_link.py:47)
2023-08-12 15:15:32,488 - initial_access.gmail_phishing_form_link - INFO - Created email with Google Form link (gmail_phishing_form_link.py:59)
2023-08-12 15:15:32,488 - initial_access.gmail_phishing_form_link - INFO - Created email with Google Form link (gmail_phishing_form_link.py:59)
2023-08-12 15:15:33,333 - initial_access.gmail_phishing_form_link - INFO - Sent email to [email protected] from [email protected] (gmail_phishing_form_link.py:65)
2023-08-12 15:15:33,333 - initial_access.gmail_phishing_form_link - INFO - Sent email to [email protected] from [email protected] (gmail_phishing_form_link.py:65)
SWAT version
0.0.1
Checklist
Please ensure you've completed the following tasks:
- I've described the bug in as much detail as possible
- I've provided steps to reproduce the bug
- I've added any relevant screenshots or other information
- Dominant language
- Python
- Stars
- 169
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from elastic/SWAT
-
Dependency DashboardOpen
Difficulty 5/5 Over a week Newbie friendliness 15/100
-
[Maintenance] Documentation Screenshots not RenderingMay be free again @terrancedejesus claimed this 1134 days ago, and no pull request is open. Opencommunity maintenance
-
[Feature Request] Create `add-emulation` commandMay be free again @brokensound77 claimed this 1170 days ago, and no pull request is open. Openenhancement
-
[Feature Request] Add Python module for detecting T1098.003 - Additional Cloud RolesMay be free again @terrancedejesus claimed this 1239 days ago, and no pull request is open. OpenAPI: Admin enhancement Subtechnique: 003 Tactic: Persistence Technique: T1098
-
API: Admin API: Gmail enhancement Subtechnique: 003 Tactic: Discovery Technique: T1087
Difficulty 3/5 1-2 days Newbie friendliness 35/100
Similar issues
-
New InternshipOpennew_internship
Difficulty 1/5 Under an hour Newbie friendliness 70/100
-
[BUG] Reports tab: "Unban" button tooltip shows raw `{{ip}}` placeholder instead of the IP addressOpenbug javascript ui
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bunkerity/bunkerweb#4001 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
PedestrianDynamics/pyFDS-Evac#476 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
google/differential-privacy#516 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
adobe-fonts/source-serif#153 ·