Files
bashbunny-payloads/payloads/library/exfiltration/GhoulGrabber/README.md
GHXSTFPS a670f61a85 Update README with usage instructions for BashBunny
Added important note about renaming BashBunny's Device Name.
2025-11-25 20:20:17 -05:00

3.5 KiB

  ▄████  ██░ ██  ▒█████   █    ██  ██▓      ▄████  ██▀███   ▄▄▄       ▄▄▄▄    ▄▄▄▄   ▓█████  ██▀███  
 ██▒ ▀█▒▓██░ ██▒▒██▒  ██▒ ██  ▓██▒▓██▒     ██▒ ▀█▒▓██ ▒ ██▒▒████▄    ▓█████▄ ▓█████▄ ▓█   ▀ ▓██ ▒ ██▒
▒██░▄▄▄░▒██▀▀██░▒██░  ██▒▓██  ▒██░▒██░    ▒██░▄▄▄░▓██ ░▄█ ▒▒██  ▀█▄  ▒██▒ ▄██▒██▒ ▄██▒███   ▓██ ░▄█ ▒
░▓█  ██▓░▓█ ░██ ▒██   ██░▓▓█  ░██░▒██░    ░▓█  ██▓▒██▀▀█▄  ░██▄▄▄▄██ ▒██░█▀  ▒██░█▀  ▒▓█  ▄ ▒██▀▀█▄  
░▒▓███▀▒░▓█▒░██▓░ ████▓▒░▒▒█████▓ ░██████▒░▒▓███▀▒░██▓ ▒██▒ ▓█   ▓██▒░▓█  ▀█▓░▓█  ▀█▓░▒████▒░██▓ ▒██▒
 ░▒   ▒  ▒ ░░▒░▒░ ▒░▒░▒░ ░▒▓▒ ▒ ▒ ░ ▒░▓  ░ ░▒   ▒ ░ ▒▓ ░▒▓░ ▒▒   ▓▒█░░▒▓███▀▒░▒▓███▀▒░░ ▒░ ░░ ▒▓ ░▒▓░
  ░   ░  ▒ ░▒░ ░  ░ ▒ ▒░ ░░▒░ ░ ░ ░ ░ ▒  ░  ░   ░   ░▒ ░ ▒░  ▒   ▒▒ ░▒░▒   ░ ▒░▒   ░  ░ ░  ░  ░▒ ░ ▒░
░ ░   ░  ░  ░░ ░░ ░ ░ ▒   ░░░ ░ ░   ░ ░   ░ ░   ░   ░░   ░   ░   ▒    ░    ░  ░    ░    ░     ░░   ░ 
      ░  ░  ░  ░    ░ ░     ░         ░  ░      ░    ░           ░  ░ ░       ░         ░  ░   ░     
                                                                           ░       ░                 

🧟‍♂️ GhoulGrabber

This script is very simple but works out of the box without any tweaking, should you want to feel free to make a contribute and I'll look it over theres a ton this could still support but I just tried to keep it simple and stupid

GhoulGrabber is designed for legitimate educational use only.

Features

✔ Collects artifacts from **Chrome, Edge, Firefox, Brave, and Opera

✔ Copies from all profiles

✔ Copies Shit from da browsa

  • History
  • Cookies
  • Bookmarks
  • Login Data
  • Local Storage
  • Cache
  • Extensions
  • SQLite databases

Requirements: BashBunny MK2 (probably works on MK1 just haven't tested myself)

🧙‍♂️ How to Use 🧙‍♂️

⚠️ Important: If you have renamed your BashBunny's Device Name you need to change line 13 of payload.txt ---> label=''YourBashBunnyDeviceNameGoesHere'⚠️

  • Set BashBunny to Arming mode (Closest to the USB Dongle)

  • Place payload.txt and collect.ps1 into switch 1 or 2 it really doesn't matter

  • Should look like this -> (E:\payloads\switch 1\payload.txt)

  • Eject Bash Bunny

  • Place to the correct Switch Setting, furthest from dongle is Switch 1 middle is Switch 2

  • Insert into target machine, When the light turns solid green the script has run successfully leave in for as long as possible to copy as much as possible

  • When finished or spotted remove and run away screaming