Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Invoke-ATTACKAPI — Ein PowerShell-Skript zur Interaktion mit dem MITRE ATT&CK Framework über seine eigene API. | Kitploit
Tools/GitHubGitHub/cyb3rward0g/invoke-attackapi
AufklärungInformationsbeschaffungDienstprogramme & FrameworksBedrohungsanalyseLernen & BildungKuratierte RessourcenArchived
GitHubcyb3rward0g/invoke-attackapi

Invoke-ATTACKAPI

Ein PowerShell-Skript zur Interaktion mit dem MITRE ATT&CK Framework über seine eigene API.

Repository anzeigen
3688123vor 7 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Invoke-ATTACKAPI [DEPRECATED]

WIR EMPFEHLEN ZU VERWENDEN: https://github.com/Cyb3rWard0g/ATTACK-Python-Client

Ein PowerShell-Skript zur Interaktion mit dem MITRE ATT&CK Framework über dessen eigene API, um Informationen über Techniken, Taktiken, Gruppen, Software und Referenzen zu sammeln, die vom MITRE ATT&CK Team @MITREattack bereitgestellt werden. DIESES SKRIPT VERWENDET NOCH DIE VERALTETE MEEDIAWIKI-API. ES WURDE NOCH NICHT AKTUALISIERT, UM DIE ÖFFENTLICHEN TAXII-SERVER-APIS ZU NUTZEN

Ziele

  • Bereitstellung einer einfachen Möglichkeit zur Interaktion mit dem MITRE ATT&CK Framework über dessen eigene API und PowerShell für die Community.
  • Beschleunigung der Datenerfassung von ATT&CK bei der Vorbereitung einer Jagdkampagne.
  • Erlernen von PowerShell Dynamischen Parametern :)

Ressourcen

  • MITRE ATT&CK API
  • Semantic MediaWiki API
  • Get-ATTack
    • Walter Legowski @SadProcessor

Erste Schritte

Voraussetzungen

  • PowerShell Version 3+

Installation/Importieren```

git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1

/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]

        Adversarial Tactics, Techniques & Common Knowledge API

[*] Author: Roberto Rodriguez @Cyb3rWard0g

[++] Pulling MITRE ATT&CK Data

## Beispiele
### Diese Abfrage entspricht allen Techniken```
Invoke-ATTACKAPI -Category -Technique

ID                  : {T1001}
Bypass              : {}
Contributor         : {}
Requires System     : {}
Data Source         : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description         : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
                      attempt to make the content more difficult to discover or decipher and to make the
                      communication less conspicuous and hide commands from being seen. This encompasses many
                      methods, such as adding junk data to protocol traffic, using steganography, commingling
                      legitimate traffic with C2 communications traffic, or using a non-standard data encoding
                      system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation          : {Network intrusion detection and prevention systems that use network signatures to
                      identify traffic for specific adversary malware can be used to mitigate activity at the
                      network level. Signatures are often for unique indicators within protocols and may be
                      based on the specific obfuscation technique used by a particular adversary or tool, and
                      will likely be different across various malware families and versions. Adversaries will
                      likely change tool C2 signatures over time or construct protocols in such a way as to
                      avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic              : Command and Control
Analytic Details    : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
                      data than it receives from a server). Processes utilizing the network that do not normally

                      have network communication or have never been seen before are suspicious. Analyze packet
                      contents to detect communications that do not follow the expected protocol behavior for
                      the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName       : {Data Obfuscation}
FullText            : Technique/T1001
Link Text           : {[[Technique/T1001|Data Obfuscation]]}
Reference           : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform            : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name                : {Data Obfuscation}
CAPEC ID            : {}
Requires Permission : {}
URL                 : https://attack.mitre.org/wiki/Technique/T1001
.............
..................
Tool herunterladen