
أداة التهرب من برامج مكافحة الفيروسات
AVET هي أداة تجاوز مضادات الفيروسات، تم تطويرها لتسهيل حياة مختبري الاختراق والتجربة مع تقنيات تجاوز مضادات الفيروسات، بالإضافة إلى الأساليب الأخرى التي تستخدمها البرمجيات الخبيثة. للحصول على نظرة عامة على الميزات الجديدة في v2.4، بالإضافة إلى إصدارات الإصدارات السابقة، ألق نظرة على ملف CHANGELOG.
ليست كل التقنيات ستتجاوز كل محرك مكافحة فيروسات. إذا لم تعمل تقنية أو نص بناء واحد، يرجى اختبار تقنية أخرى. لا تتردد في التجربة! بعد كل شيء، هذه مجموعة أدوات - لكن ينبغي عليك استخدام المطرقة بنفسك.
تنطبق تعليمات التثبيت على Kali 64bit و tdm-gcc!
يمكنك استخدام script الإعداد:```bash ./setup.sh
This should automatically get you started by installing/configuring wine and installing tdm-gcc.
You'll shortly have to click through the tdm-gcc installer GUI though - standard settings should be fine.
The script will also ask if you want to install AVET's dependencies, which are needed to use some of the build scripts. The fetched dependencies will be put into separate folders next to the avet folder.
Dependencies will grab the latest releases of:
- [pe_to_shellcode](https://github.com/hasherezade/pe_to_shellcode)
- [mimikatz](https://github.com/gentilkiwi/mimikatz)
- [DKMC](https://github.com/Mr-Un1k0d3r/DKMC)
If for whatever reason you want to install wine and tdm-gcc manually:
- [How to install tdm-gcc with wine](https://govolution.wordpress.com/2017/02/04/using-tdm-gcc-with-kali-2/)
## Docker
If you are not using Kali or don't want to install Metasploit on your system, you can use the Docker Container instead.
The container encapsulates Metasploit and avet and the samples will be created in your current directory.
It is also possible to use an graphical text editor like gedit.
Building the container:```bash
sudo docker build -t avet:v0.1 .
الاستخدام:```bash sudo docker run -it --net=host --env="DISPLAY" --volume="$HOME/.Xauthority:/root/.Xauthority:rw" -v $(pwd):/tools/avet/output avet:v0.1 /bin/bash
للحصول على تجربة أفضل، يُوصى بإنشاء alias لهذا.```bash
# In your .bash_profile, .bashrc or .bash_aliases
alias avet='sudo docker run -it --net=host --env="DISPLAY" --volume="$HOME/.Xauthority:/root/.Xauthority:rw" -v $(pwd):/tools/avet/output avet /bin/bash'
avet.py هي أداة بسيطة بلغة Python صُممت لمساعدتك في استخدام هذه الأداة.
تقوم بعرض كل السكريبتات الموجودة حالياً في مجلد البناء (build). بعد اختيار واحد، ستتمكن من التقدم خلال السكريبت سطراً سطراً، مع إمكانية تعديل المحتوى أثناء العمل.
الأمر الأخير مفيد بشكل خاص حيث يمكنك تعريف متغيرات LHOST و LPORT جديدة لـ msfvenom في كل مرة تقوم فيها بتشغيل سكريبت بناء عبر fabric.
يمكنك تعريف قيم افتراضية لـ LHOST و LPORT في ملف /build/global_connect_config.sh، والتي تُستخدم إذا لم تقم بإعادة تعريفها.
هذه التعديلات مؤقتة، مما يعني أن أي تغييرات قمت بها لن تستمر في سكريبت البناء على القرص. يتم تنفيذ النسخة المعدلة مرة واحدة، ويتم بناء الملف التنفيذي الخاص بك.
.| , +
* | | (( *
|'| ` ._____
+ ___ | | * |. |' .---"|
_ .-' '-. | | .--'| || | _| |
.-'| _.| | || '-__ | | | || |
|' | |. | || | | | | || |
| '-' ' "" '-' '-.' '` |_ jgs~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Welcome to the avet Assistant!
0 : build_40xshikata_revhttpsunstaged_win32.sh 1 : build_50xshikata_quiet_revhttps_win32.sh 2 : build_50xshikata_revhttps_win32.sh 3 : build_asciimsf_fromcmd_revhttps_win32.sh 4 : build_asciimsf_revhttps_win32.sh 5 : build_avetenc_dynamicfromfile_revhttps_win32.sh 6 : build_avetenc_fopen_revhttps_win32.sh 7 : build_avetenc_mtrprtrxor_revhttps_win64.sh 8 : build_calcfromcmd_50xshikata_revhttps_win32.sh 9 : build_calcfrompowersh_50xshikata_revhttps_win32.sh 10 : build_checkdomain_rc4_mimikatz.sh 11 : build_cpucores_revhttps_win32.sh 12 : build_disablewindefpsh_xorfromcmd_revhttps_win64.sh 13 : build_dkmc_downloadexecshc_revhttps_win32.sh 14 : build_downloadbitsadmin_mtrprtrxor_revhttps_win64.sh 15 : build_downloadbitsadmin_revhttps_win32.sh 16 : build_downloadcertutil_revhttps_win32.sh 17 : build_downloadcurl_mtrprtrxor_revhttps_win64.sh 18 : build_downloadiexplorer_revhttps_win32.sh 19 : build_downloadpsh_revhttps_win32.sh 20 : build_downloadsocket_mtrprtrxor_revhttps_win64.sh 21 : build_downloadsocket_revhttps_win32.sh 22 : build_dynamicfromfile_revhttps_win32.sh 23 : build_fibonacci_rc4_mimikatz.sh 24 : build_fopen_mtrprtrxor_revhttps_win64.sh 25 : build_fopen_quiet_revhttps_win32.sh 26 : build_fopen_revhttps_win32.sh 27 : build_getchar_rc4_mimikatz.sh 28 : build_gethostbyname_revhttps_win32.sh 29 : build_hasvmkey_revhttps_win32.sh 30 : build_hasvmmac_revtcp_win32.sh 31 : build_hollowing_targetfromcmd_doubleenc_doubleev_revhttps_win64.sh 32 : build_hollowing_targetfromcmd_doubleenc_doubleev_revtcp_win32.sh 33 : build_injectdll_targetfromcmd_execcalc_downloadpsh_fopen_gethostbyname_win32.sh 34 : build_injectdll_targetfromcmd_execcalc_downloadpsh_fopen_gethostbyname_win64.sh 35 : build_injectshc_targetfromcmd_fopen_gethostbyname_xor_revhttps_win64.sh 36 : build_injectshc_targetfromcmd_fopen_gethostbyname_xor_revtcp_win32.sh 37 : build_kaspersky_fopen_shellrevtcp_win32.sh 38 : build_mimikatz_pe2shc_xorfromcmd_win64.sh 39 : build_pause_rc4_mimikatz.sh 40 : build_rc4_interactive_pwsh_mimikatz_win64.sh 41 : build_rc4_interactive_with_arithmetic_pwsh_mimikatz_win64.sh 42 : build_rc4enc_mimikatz_win64.sh 43 : build_sleep_rc4_mimikatz.sh 44 : build_sleepbyping_rc4_mimikatz.sh 45 : build_timedfibonacci_rc4_mimikatz.sh 46 : buildsvc_20xshikata_bindtcp_win32.sh
Which Script would you like to configure and build? Enter the corresponding number -> 43
DESCRIPTION :