Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Invoke-ATTACKAPI — سكريبت PowerShell للتفاعل مع إطار عمل MITRE ATT&CK عبر واجهة برمجة التطبيقات الخاصة به. | Kitploit
أدوات/GitHubGitHub/cyb3rward0g/invoke-attackapi
الاستطلاعجمع المعلوماتالأدوات والمكوناتاستخبارات التهديداتالتعلم والتعليمموارد منسقةArchived
GitHubcyb3rward0g/invoke-attackapi

Invoke-ATTACKAPI

سكريبت PowerShell للتفاعل مع إطار عمل MITRE ATT&CK عبر واجهة برمجة التطبيقات الخاصة به.

عرض المستودع
3688123منذ 7 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

Invoke-ATTACKAPI [مهمل]

نوصي باستخدام: https://github.com/Cyb3rWard0g/ATTACK-Python-Client

نص برمجي PowerShell للتفاعل مع إطار MITRE ATT&CK عبر واجهة برمجة التطبيقات الخاصة به لجمع معلومات حول التقنيات والتكتيكات والمجموعات والبرامج والمراجع المقدمة من فريق MITRE ATT&CK @MITREattack. لا يزال هذا النص البرمجي يستخدم واجهة برمجة التطبيقات MediaWiki القديمة. لم يتم تحديثه بعد لاستخدام خوادم TAXII العامة

الأهداف

  • توفير طريقة سهلة للتفاعل مع إطار MITRE ATT&CK عبر واجهة برمجة التطبيقات الخاصة به و PowerShell للمجتمع.
  • تسريع الحصول على البيانات من ATT&CK عند التحضير لحملة صيد.
  • تعلم المعاملات الديناميكية في PowerShell :)

الموارد

  • MITRE ATT&CK API
  • Semantic MediaWiki API
  • Get-ATTack
    • Walter Legowski @SadProcessor

البدء

المتطلبات

  • إصدار PowerShell 3+

التثبيت / الاستيراد```

git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1

/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]

        Adversarial Tactics, Techniques & Common Knowledge API

[*] Author: Roberto Rodriguez @Cyb3rWard0g

[++] Pulling MITRE ATT&CK Data

## أمثلة
### هذا الاستعلام يطابق جميع التقنيات```
Invoke-ATTACKAPI -Category -Technique

ID                  : {T1001}
Bypass              : {}
Contributor         : {}
Requires System     : {}
Data Source         : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description         : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
                      attempt to make the content more difficult to discover or decipher and to make the
                      communication less conspicuous and hide commands from being seen. This encompasses many
                      methods, such as adding junk data to protocol traffic, using steganography, commingling
                      legitimate traffic with C2 communications traffic, or using a non-standard data encoding
                      system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation          : {Network intrusion detection and prevention systems that use network signatures to
                      identify traffic for specific adversary malware can be used to mitigate activity at the
                      network level. Signatures are often for unique indicators within protocols and may be
                      based on the specific obfuscation technique used by a particular adversary or tool, and
                      will likely be different across various malware families and versions. Adversaries will
                      likely change tool C2 signatures over time or construct protocols in such a way as to
                      avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic              : Command and Control
Analytic Details    : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
                      data than it receives from a server). Processes utilizing the network that do not normally

                      have network communication or have never been seen before are suspicious. Analyze packet
                      contents to detect communications that do not follow the expected protocol behavior for
                      the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName       : {Data Obfuscation}
FullText            : Technique/T1001
Link Text           : {[[Technique/T1001|Data Obfuscation]]}
Reference           : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform            : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name                : {Data Obfuscation}
CAPEC ID            : {}
Requires Permission : {}
URL                 : https://attack.mitre.org/wiki/Technique/T1001
.............
..................
تنزيل الأداة