Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
148 changes: 75 additions & 73 deletions installer/cape2.sh
Original file line number Diff line number Diff line change
@@ -1,11 +1,85 @@
#!/bin/bash
# set -ex
# By @doomedraven - https://twitter.com/D00m3dR4v3n
# Copyright (C) 2011-2023 doomedraven.
# Copyright (C) 2011-2026 doomedraven.
# See the file 'LICENSE.md' for copying permission.

# Huge thanks to: @NaxoneZ @kevoreilly @ENZOK @wmetcalf @ClaudioWayne

function usage() {
cat << EndOfHelp
You need to edit NETWORK_IFACE, IFACE_IP and PASSWD for correct install

* This ISN'T a silver bullet, we can't control all changes in all third part software, you are welcome to report updates

Usage: $0 <command> <iface_ip> [options] | tee $0.log
Example: $0 all 192.168.1.1 | tee $0.log
Commands - are case insensitive:
Base - Installs dependencies, CAPE, systemd, see code for full list
All - Installs everything - (don't use it if you don't know what will be installed ;))
Sandbox - Install CAPE
Dependencies - Install all dependencies with performance tricks
Systemd - Install systemd config for cape, we suggest to use systemd
Nginx <domain.com> - Install NGINX with realip plugin and other goodies, pass your domain as argument
LetsEncrypt <domain.com> - Install LetsEncrypt for your site, pass your domain as argument
Suricata - Install latest suricata with performance boost
PostgreSQL - Install latest PostgresSQL
PostgreSQL_Utility - Install pg_activity
Yara - Install latest yara
Yara-x - Install latest yara-x
Volatility3 - Install Volatility3 and windows symbols
Mongo - Install latest mongodb
LetsEncrypt - Install dependencies and retrieves certificate
Dist - will install CAPE distributed stuff
ClamAv - Install ClamAV and unofficial signatures
redsocks2 - install redsocks2
logrotate - install logrotate config to rotate daily or 10G logs
librenms - install and setup LibreNMS support
librenms_cron_config - print the cron entries for the LibreNMS bits
librenms_snmpd_config - print the snmpd config for use with LibreNMS
librenms_sneck_config - print the sneck config for use with LibreNMS
prometheus - Install Prometheus and Grafana
die - Install Detect It Easy
node_exporter - Install node_exporter to report data to Prometheus+Grafana, only on worker servers
jemalloc - Install jemalloc, required for CAPE to decrease memory usage
Details: https://zapier.com/engineering/celery-python-jemalloc/
crowdsecurity - Install CrowdSecurity for NGINX and webgui
introvirt - Install IntroVirt
docker - install docker
osslsigncode - Linux alternative to Windows signtool.exe
modsecurity - install Nginx ModSecurity plugin
Issues - show some known possible bugs/solutions
Options:
--use-uv - Use uv instead of poetry
--disable-mongodb-avx-check - Disable check of AVX CPU feature for MongoDB
--disable-libvirt - Disable libvirt related packages installation

Examples:
sudo bash cape2.sh all | tee cape2.log
Default install - poetry, /opt/CAPEv2
sudo CAPE_ROOT=/mnt/sandbox/CAPEv2 USE_UV=True bash cape2.sh all | tee cape2.log
* Custom install folder, use UV instead of poetry

Useful links - THEY CAN BE OUTDATED; RTFM!!!
* https://cuckoo.sh/docs/introduction/index.html
* https://medium.com/@seifreed/how-to-deploy-cuckoo-sandbox-431a6e65b848
* https://infosecspeakeasy.org/t/howto-build-a-cuckoo-sandbox/27
Cuckoo V2 customizations neat howto
* https://www.adlice.com/cuckoo-sandbox-customization-v2/
EndOfHelp
}

# Check for help options or empty arguments early to avoid running host commands on loading
if [ "$1" = "-h" ] || [ "$1" = "--help" ] || [ "$1" = "help" ] || [ "$1" = "-help" ]; then
usage
exit 0
fi

if [ $# -eq 0 ]; then
usage
exit 1
fi

# Ensure non-interactive mode for apt commands globally to prevent prompts during automated installations
export DEBIAN_FRONTEND=noninteractive

Expand Down Expand Up @@ -95,69 +169,6 @@ function issues() {
cat "No known problems yet"
}

function usage() {
cat << EndOfHelp
You need to edit NETWORK_IFACE, IFACE_IP and PASSWD for correct install

* This ISN'T a silver bullet, we can't control all changes in all third part software, you are welcome to report updates

Usage: $0 <command> <iface_ip> [options] | tee $0.log
Example: $0 all 192.168.1.1 | tee $0.log
Commands - are case insensitive:
Base - Installs dependencies, CAPE, systemd, see code for full list
All - Installs everything - (don't use it if you don't know what will be installed ;))
Sandbox - Install CAPE
Dependencies - Install all dependencies with performance tricks
Systemd - Install systemd config for cape, we suggest to use systemd
Nginx <domain.com> - Install NGINX with realip plugin and other goodies, pass your domain as argument
LetsEncrypt <domain.com> - Install LetsEncrypt for your site, pass your domain as argument
Suricata - Install latest suricata with performance boost
PostgreSQL - Install latest PostgresSQL
PostgreSQL_Utility - Install pg_activity
Yara - Install latest yara
Yara-x - Install latest yara-x
Volatility3 - Install Volatility3 and windows symbols
Mongo - Install latest mongodb
LetsEncrypt - Install dependencies and retrieves certificate
Dist - will install CAPE distributed stuff
ClamAv - Install ClamAV and unofficial signatures
redsocks2 - install redsocks2
logrotate - install logrotate config to rotate daily or 10G logs
librenms - install and setup LibreNMS support
librenms_cron_config - print the cron entries for the LibreNMS bits
librenms_snmpd_config - print the snmpd config for use with LibreNMS
librenms_sneck_config - print the sneck config for use with LibreNMS
prometheus - Install Prometheus and Grafana
die - Install Detect It Easy
node_exporter - Install node_exporter to report data to Prometheus+Grafana, only on worker servers
jemalloc - Install jemalloc, required for CAPE to decrease memory usage
Details: https://zapier.com/engineering/celery-python-jemalloc/
crowdsecurity - Install CrowdSecurity for NGINX and webgui
introvirt - Install IntroVirt
docker - install docker
osslsigncode - Linux alternative to Windows signtool.exe
modsecurity - install Nginx ModSecurity plugin
Issues - show some known possible bugs/solutions
Options:
--use-uv - Use uv instead of poetry
--disable-mongodb-avx-check - Disable check of AVX CPU feature for MongoDB
--disable-libvirt - Disable libvirt related packages installation

Examples:
sudo bash cape2.sh all | tee cape2.log
Default install - poetry, /opt/CAPEv2
sudo CAPE_ROOT=/mnt/sandbox/CAPEv2 USE_UV=True bash cape2.sh all | tee cape2.log
* Custom install folder, use UV instead of poetry

Useful links - THEY CAN BE OUTDATED; RTFM!!!
* https://cuckoo.sh/docs/introduction/index.html
* https://medium.com/@seifreed/how-to-deploy-cuckoo-sandbox-431a6e65b848
* https://infosecspeakeasy.org/t/howto-build-a-cuckoo-sandbox/27
Cuckoo V2 customizations neat howto
* https://www.adlice.com/cuckoo-sandbox-customization-v2/
EndOfHelp
}

function install_crowdsecurity() {
echo "[+] Install crowdsecurity"
sudo apt-get install -y bash gettext whiptail curl wget
Expand Down Expand Up @@ -1765,17 +1776,8 @@ function install_passivedns() {
# Doesn't work ${$1,,}
COMMAND=$(echo "$1"|tr "{A-Z}" "{a-z}")

case $COMMAND in
'-h')
usage
exit 0;;
esac

if [ $# -ge 2 ] && [[ ! "$2" =~ ^-- ]]; then
IFACE_IP=$2
elif [ $# -eq 0 ]; then
echo "[-] check --help"
exit 1
fi

DISABLE_MONGO_AVX_CHECK=0
Expand Down
Loading