Drive Badger is a software tool for data exfiltration – which means, for copying data from the computer to external USB drive. But unlike many other tools from IT security area, Drive Badger is not a Proof-of-Concept kind of tool, bringing some groundbreaking techniques. Everything, what Drive Badger does, can be as well run manually, step by step.
Instead, what Drive Badger really does, is doing it all better, by putting the maximum focus on:
-
Speed - all operation is fully automated, and there are over 340 unique exclude rules, which reduce the amount of files to be copied by eliminating low-value files and directories from the list, and thus save typically over 95% of the time, that would be spent by "naive" script.
-
Stealth - all operation is done below the installed operating system, so totally invisible to the installed security software (anti-virus, DLP, SIEM, EDR etc.).
-
Support for drive encryption - Microsoft BitLocker and Apple FileVault encryption is supported, including automated matching the keys given as flat list, to particular encrypted partitions.
-
Operator safety - there is no way to distinguish between Drive Badger and ordinary Kali Linux Live drive, or to prove the fact of data exfiltration, until someone knows the proper password (and thanks to PBKDF2 algorithm, there is no way to crack it).
So, the real purpose of Drive Badger is to change the economics of covert data exfiltration attacks (make them more affordable), by reducing the overall risk of the operation, and also by lowering the entry threshold for the operator, who no longer needs to have IT background.