Skip to content

Added trajan module - #2966

Merged
TheTechromancer merged 9 commits into
blacklanternsecurity:3.0from
N7WEra:stable
Mar 20, 2026
Merged

Added trajan module#2966
TheTechromancer merged 9 commits into
blacklanternsecurity:3.0from
N7WEra:stable

Conversation

@N7WEra

@N7WEra N7WEra commented Mar 11, 2026

Copy link
Copy Markdown
Contributor

added module for trajan (https://github.com/praetorian-inc/trajan)

example:

$ bbot -t https://github.com/praetorian-inc/trajan -m trajan -c modules.trajan.github_token=github_pat_1REDACTED -y
  ______  _____   ____ _______
 |  ___ \|  __ \ / __ \__   __|
 | |___) | |__) | |  | | | |
 |  ___ <|  __ <| |  | | | |
 | |___) | |__) | |__| | | |
 |______/|_____/ \____/  |_|
 BIGHUGE BLS OSINT TOOL 0.0.0

www.blacklanternsecurity.com/bbot

[INFO] Scan seeded with 1 seed(s) (1 in target)
[INFO] Loaded 1/1 scan modules (trajan)
[INFO] Loaded 6/6 internal modules (aggregate,cloudcheck,dnsresolve,excavate,speculate,unarchive)
[INFO] Loaded 5/5 output modules, (csv,json,python,stdout,txt)
[INFO] internal.speculate: No portscanner enabled. Assuming open ports: 80, 443
[SUCC] Setup succeeded for 12/12 modules.
[SUCC] Starting scan vigorous_sophia
[SCAN]                  vigorous_sophia (SCAN:67407cf18d89bca404eecc216226c350666ba75c) SEED
[URL_UNVERIFIED]        https://github.com/praetorian-inc/trajan        SEED    (cdn, cdn-github, cloud, cloud-microsoft, endpoint, github-domain, github-ip, in-scope, microsoft-domain, seed, target)
[DNS_NAME]              ns-1707.awsdns-21.co.uk NS      (a-record, aaaa-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cloud, cloud-amazon, cloudfront-ip, distance-1, subdomain)
[DNS_NAME]              alt4.aspmx.l.google.com MX      (a-record, aaaa-record, affiliate, cloud, cloud-google, distance-1, google-domain, google-ip, subdomain)
[DNS_NAME]              dns1.p08.nsone.net      SOA     (a-record, aaaa-record, affiliate, distance-1, subdomain)
[DNS_NAME]              mktomail.com    TXT     (a-record, affiliate, distance-1, domain)
[DNS_NAME]              servers.mcsv.net        TXT     (a-record, affiliate, distance-1, subdomain)
[DNS_NAME]              dns3.p08.nsone.net      NS      (a-record, aaaa-record, affiliate, distance-1, subdomain)
[DNS_NAME]              github.com      host    (a-record, cdn, cdn-github, cloud, cloud-microsoft, domain, github-domain, github-ip, in-scope, microsoft-domain, mx-record, ns-record, seed, soa-record, txt-record)
[DNS_NAME]              dns1.p08.nsone.net      NS      (a-record, aaaa-record, affiliate, distance-1, subdomain)
[DNS_NAME]              mail.zendesk.com        TXT     (a-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cloud, cloud-amazon, cloudfront-ip, distance-1, subdomain)
[DNS_NAME]              ns-1283.awsdns-32.org   NS      (a-record, aaaa-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cloud, cloud-amazon, cloudfront-ip, distance-1, subdomain)
[DNS_NAME]              dns2.p08.nsone.net      NS      (a-record, aaaa-record, affiliate, distance-1, subdomain)
[DNS_NAME]              alt2.aspmx.l.google.com MX      (a-record, aaaa-record, affiliate, cloud, cloud-google, distance-1, google-domain, google-ip, subdomain)
[DNS_NAME]              alt3.aspmx.l.google.com MX      (a-record, aaaa-record, affiliate, cloud, cloud-google, distance-1, google-domain, google-ip, subdomain)
[DNS_NAME]              alt1.aspmx.l.google.com MX      (a-record, aaaa-record, affiliate, cloud, cloud-google, distance-1, google-domain, google-ip, subdomain)
[DNS_NAME]              ns-421.awsdns-52.com    NS      (a-record, aaaa-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cloud, cloud-amazon, cloudfront-ip, distance-1, subdomain)
[DNS_NAME]              dns4.p08.nsone.net      NS      (a-record, aaaa-record, affiliate, distance-1, subdomain)
[DNS_NAME]              aspmx.l.google.com      MX      (a-record, aaaa-record, affiliate, cloud, cloud-google, distance-1, google-domain, google-ip, subdomain)
[DNS_NAME]              ns-520.awsdns-01.net    NS      (a-record, aaaa-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cloud, cloud-amazon, cloudfront-ip, distance-1, subdomain)
[ORG_STUB]              github  speculate
[DNS_NAME]              o1.sgmail.github.com    PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain)
[DNS_NAME]              o3.sgmail.github.com    PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain)
[DNS_NAME]              lb-140-82-112-3-iad.github.com  PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, github-ip, in-scope, microsoft-domain, subdomain)
[DNS_NAME]              o2.sgmail.github.com    PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain)
[DNS_NAME]              o6.sgmail.github.com    PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain)
[DNS_NAME]              o5.sgmail.github.com    PTR     (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain)
[DNS_NAME]              mxa.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxa.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxa.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxb.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxa.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxb.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxb.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxb.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxa.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              mxb.mailgun.org MX      (a-record, affiliate, cloud, cloud-google, distance-1, google-ip, subdomain)
[DNS_NAME]              github.com      speculate       (a-record, cdn, cdn-github, cloud, cloud-microsoft, domain, github-domain, github-ip, in-scope, microsoft-domain, mx-record, ns-record, soa-record, txt-record)
[DNS_NAME]              sgmail.github.com       speculate       (a-record, cdn, cdn-github, cloud, cloud-microsoft, github-domain, in-scope, microsoft-domain, mx-record, subdomain, txt-record)
**[FINDING]               {"confidence": "MODERATE", "description": "Deployment job 'Create Tag' lacks environment protection. This allows deployments without required approvals. (Workflow: .github/workflows/release.yaml)", "host": "github.com", "name": "Trajan - environment_bypass", "severity": "HIGH"}  trajan  (cdn, cdn-github, cloud, cloud-microsoft, confidence-moderate, github-domain, github-ip, in-scope, microsoft-domain, severity-high)
[FINDING]               {"confidence": "MODERATE", "description": "Deployment job 'Create Tag' lacks environment protection. This allows deployments without required approvals. (Workflow: .github/workflows/release.yaml)", "host": "github.com", "name": "Trajan - environment_bypass", "severity": "HIGH"}  trajan  (cdn, cdn-github, cloud, cloud-microsoft, confidence-moderate, github-domain, github-ip, in-scope, microsoft-domain, severity-high)
[FINDING]               {"confidence": "MODERATE", "description": "Deployment job 'Cleanup on Failure' lacks environment protection. This allows deployments without required approvals. (Workflow: .github/workflows/release.yaml)", "host": "github.com", "name": "Trajan - environment_bypass", "severity": "HIGH"}  trajan  (cdn, cdn-github, cloud, cloud-microsoft, confidence-moderate, github-domain, github-ip, in-scope, microsoft-domain, severity-high)
[FINDING]               {"confidence": "MODERATE", "description": "Deployment job 'Cleanup on Failure' lacks environment protection. This allows deployments without required approvals. (Workflow: .github/workflows/release.yaml)", "host": "github.com", "name": "Trajan - environment_bypass", "severity": "HIGH"}  trajan  (cdn, cdn-github, cloud, cloud-microsoft, confidence-moderate, github-domain, github-ip, in-scope, microsoft-domain, severity-high)**
[DNS_NAME]              mx.sendgrid.net MX      (a-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cdn-github, cloud, cloud-amazon, cloudfront-ip, distance-1, github-ip, subdomain)
[DNS_NAME]              sendgrid.net    TXT     (a-record, affiliate, amazon-ip, cdn, cdn-cloudfront, cdn-github, cloud, cloud-amazon, cloudfront-ip, distance-1, domain, github-ip)
[DNS_NAME]              github.com      host    (a-record, cdn, cdn-github, cloud, cloud-microsoft, domain, github-domain, github-ip, in-scope, microsoft-domain, mx-record, ns-record, soa-record, txt-record)
[INFO] Finishing scan
[SCAN]                  vigorous_sophia (SCAN:67407cf18d89bca404eecc216226c350666ba75c) SEED
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | Module     | Produced                     | Consumed                                 |
[INFO] aggregate: +============+==============================+==========================================+
[INFO] aggregate: | MX         | 16 (16 DNS_NAME)             | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | TXT        | 9 (4 DNS_NAME, 5 IP_ADDRESS) | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | NS         | 8 (8 DNS_NAME)               | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | PTR        | 6 (6 DNS_NAME)               | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | speculate  | 3 (2 DNS_NAME, 1 ORG_STUB)   | 48 (28 DNS_NAME, 5 DNS_NAME_UNRESOLVED,  |
[INFO] aggregate: |            |                              | 14 IP_ADDRESS, 1 URL_UNVERIFIED)         |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | trajan     | 2 (2 FINDING)                | 1 (1 URL_UNVERIFIED)                     |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | host       | 2 (2 DNS_NAME)               | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | SOA        | 1 (1 DNS_NAME)               | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | A          | 1 (1 IP_ADDRESS)             | 0                                        |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | dnsresolve | 0                            | 88 (58 DNS_NAME, 2 FINDING, 27           |
[INFO] aggregate: |            |                              | IP_ADDRESS, 1 URL_UNVERIFIED)            |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] aggregate: | cloudcheck | 0                            | 88 (46 DNS_NAME, 12 DNS_NAME_UNRESOLVED, |
[INFO] aggregate: |            |                              | 2 FINDING, 27 IP_ADDRESS, 1              |
[INFO] aggregate: |            |                              | URL_UNVERIFIED)                          |
[INFO] aggregate: +------------+------------------------------+------------------------------------------+
[INFO] output.csv: Saved CSV output to /home/USER/.bbot/scans/vigorous_sophia/output.csv
[INFO] output.json: Saved JSON output to /home/USER/.bbot/scans/vigorous_sophia/output.json
[INFO] output.txt: Saved TXT output to /home/USER/.bbot/scans/vigorous_sophia/output.txt

@TheTechromancer
TheTechromancer changed the base branch from stable to 3.0 March 16, 2026 15:15
@TheTechromancer

Copy link
Copy Markdown
Contributor

@N7WEra thanks for your work on this! I've written some tests and added some improvements to the module, which now consumes TECHNOLOGY events. This helps for situations where maybe Jenkins is running on a server, but "jenkins" is not in the URL.

Let me know what you think and we can get this merged.

@TheTechromancer TheTechromancer self-assigned this Mar 16, 2026
@codecov

codecov Bot commented Mar 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 90.56047% with 32 lines in your changes missing coverage. Please review.
✅ Project coverage is 91%. Comparing base (3f7a2fa) to head (e3e5a89).
⚠️ Report is 48 commits behind head on 3.0.

Files with missing lines Patch % Lines
bbot/modules/trajan.py 85% 26 Missing ⚠️
...est/test_step_2/module_tests/test_module_trajan.py 97% 6 Missing ⚠️
Additional details and impacted files
@@          Coverage Diff           @@
##             3.0   #2966    +/-   ##
======================================
- Coverage     91%     91%    -0%     
======================================
  Files        436     438     +2     
  Lines      36333   36678   +345     
======================================
+ Hits       33057   33359   +302     
- Misses      3276    3319    +43     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@liquidsec

Copy link
Copy Markdown
Collaborator

@TheTechromancer should they use self.run_process() instead of self.helpers.run()?

@liquidsec

liquidsec commented Mar 17, 2026

Copy link
Copy Markdown
Collaborator

@N7WEra @TheTechromancer A few concerns. As I understand it, the point is to audit your own jenkins instance.

But if you have the module on, and you have a jenkins cred defined - maybe you left it in your config.... as i understand it, ANY jenkins server (any server that triggers the jenkins technology) that gets scanned is getting sent that credential. Would not be true for GitHub, since it always goes to GitHub... thoughts?

Just afraid people might leave real creds in there and spray them at any jenkins server that they scan.

@TheTechromancer

Copy link
Copy Markdown
Contributor

@TheTechromancer should they use self.run_process() instead of self.helpers.run()?

yes, good catch

ANY jenkins server (any server that triggers the jenkins technology) that gets scanned is getting sent that credential

fair point. Of course they would only go to in-scope servers. added a warning.

@TheTechromancer
TheTechromancer merged commit 09c4da1 into blacklanternsecurity:3.0 Mar 20, 2026
12 of 14 checks passed
@liquidsec liquidsec mentioned this pull request Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants