/** * Network service banner patterns for protocol-level fingerprinting. * * Many network services announce themselves with distinctive banners upon connection. * By matching these banners against known patterns we can identify the service software, * extract version numbers, and infer OS/platform information without active scanning. * * Additional lookup tables map protocol-specific identifiers (SMB dialects, NTLM * challenge versions, MySQL auth plugins) to OS and software versions. * * References: * - Nmap service detection probes (nmap-service-probes) * - https://svn.nmap.org/nmap/nmap-service-probes * - MySQL protocol documentation * - MS-SMB2 specification */ /** A known service banner pattern entry. */ export interface ServiceBanner { /** The network service / protocol name */ service: string; /** Regex string to match against the raw banner bytes (as UTF-8 string) */ pattern: string; /** Human-readable name for the identified software */ name: string; /** Description of how to extract the version from the regex capture groups */ version_extract?: string; } export declare const SERVICE_BANNERS: ServiceBanner[]; /** * Maps SMB dialect version strings to the Windows OS version that introduced them. * * During SMB2 negotiation, the server and client agree on the highest mutually supported * dialect. The selected dialect reveals the minimum Windows version running on the server. * * Reference: MS-SMB2 Section 2.2.3 (NEGOTIATE Request) */ export declare const SMB_DIALECT_MAP: Record; /** * Maps the "MajorVersion.MinorVersion" extracted from an NTLM Type 2 challenge * message (NTLMSSP_CHALLENGE) to a Windows OS version. * * The NTLM Type 2 message contains an 8-byte OS version structure at offset 48: * - Byte 0: Major version * - Byte 1: Minor version * - Bytes 2-3: Build number (little-endian) * - Bytes 4-7: NTLM revision * * Reference: MS-NLMP Section 2.2.2.1 (VERSION structure) */ export declare const NTLM_OS_MAP: Record; /** * Maps MySQL authentication plugin names (from the initial handshake packet) to * the MySQL major version that uses them by default. * * Reference: MySQL Connection Phase documentation * - https://dev.mysql.com/doc/dev/mysql-server/latest/page_protocol_connection_phase.html */ export declare const MYSQL_AUTH_PLUGIN_MAP: Record; //# sourceMappingURL=service-banners.d.ts.map