
OpSec-sicherer PowerShell-Runspace aus C# heraus (alias SharpPick) mit deaktiviertem AMSI, Constrained Language Mode und Script Block Logging beim Start
Powershell-Runspace aus C# (auch bekannt als SharpPick-Technik) mit deaktiviertem AMSI, ETW und Script Block Logging für Ihr Vergnügen.
Heutzutage, wo PowerShell durch Techniken wie:
stark überwacht wird, müssen fortgeschrittene Angreifer Wege finden, diese Bemühungen zu umgehen, um anspruchsvolle adversarial Simulationen durchzuführen. Um bei diesen Bemühungen zu helfen, wurde folgendes Projekt erstellt.
Dieses Programm baut auf Umgehungen für spezifische Techniken auf, die in folgenden enthalten sind:
Welche wiederum auf folgenden Forschungen basieren:
Die SharpPick-Idee, PowerShell-Skripte aus einer C#-Assembly mithilfe von Runspaces zu starten, ist ebenfalls nicht neu und wurde erstmals von Lee Christensen (@tifkin_) in seinem:
implementiert.
Außerdem entlehnt der Quellcode die Implementierung von CustomPSHost von Lee.
Dieses Projekt erbt von den oben genannten Forschungen und der großartigen Sicherheits-Community, um eine nahezu effektive PowerShell-Umgebung mit beim Start deaktivierten Sicherheitsvorkehrungen bereitzustellen.
Lässt sich jetzt einfach mit .NET 4.0 kompilieren, während bei Kompilierung mit .NET Framework 4.7.1+ eine zusätzliche Funktionalität enthalten ist, die das Entladen von DLLs, die CLM-Umgehungsartefakte darstellen, ermöglicht und versucht, diese anschließend zu löschen (funktioniert ehrlich gesagt kaum).
Die beste Laufleistung erzielt man mit Stracciatella, kompiliert mit .NET 4.0.
Es stehen mehrere Optionen zur Verfügung:
PS D:\> Stracciatella -h
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
Usage: stracciatella.exe [options] [command]
-s <path>, --script <path> - Path to file containing Powershell script to execute. If not options given, will enter
a pseudo-shell loop. This can be also a HTTP(S) URL to download & execute powershell script.
-v, --verbose - Prints verbose informations
-n, --nocleanup - Don't remove CLM disable leftovers (DLL files in TEMP and COM registry keys).
By default these are going to be always removed.
-C, --leaveclm - Don't attempt to disable CLM. Stealthier. Will avoid leaving CLM disable artefacts undeleted.
-f, --force - Proceed with execution even if Powershell defenses were not disabled.
By default we bail out on failure.
-c, --command - Executes the specified commands You can either use -c or append commands after
stracciatella parameters: cmd> straciatella ipconfig /all
If command and script parameters were given, executes command after running script.
-x <key>, --xor <key> - Consider input as XOR encoded, where <key> is a one byte key in decimal
(prefix with 0x for hex)
-p <name>, --pipe <name> - Read powershell commands from a specified named pipe. Command must be preceded with 4 bytes of
its length coded in little-endian (Length-Value notation).
-t <millisecs>, --timeout <millisecs>
- Specifies timeout for pipe read operation (in milliseconds). Default: 60 secs. 0 - infinite.
-e, --cmdalsoencoded - Consider input command (specified in '--command') encoded as well.
Decodes input command after decoding and running input script file.
By default we only decode input file and consider command given in plaintext
Das Programm akzeptiert einen Befehl und einen Skriptdateipfad als Eingabe. Beide sind optional; wenn keine angegeben werden, wird eine Pseudo-Shell gestartet. Sowohl Befehl als auch Skript können mit Einzelbyte-XOR (Ausgabe in Base64-codiert) für eine bessere OpSec-Erfahrung codiert werden.
Hier sind einige Beispiele für die Verwendung:
PS D:\> Stracciatella.exe -v
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Powershell's version: 5.1
[.] Language Mode: FullLanguage
[+] No need to disable Constrained Language Mode. Already in FullLanguage.
[+] Script Block Logging Disabled.
[+] AMSI Disabled.
[+] ETW Disabled.
Stracciatella D:\> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.18362.1
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.18362.1
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
Zunächst können wir zur Vorbereitung codierter Anweisungen das beigelegte Skript encoder.py verwenden, das wie folgt verwendet werden kann:
PS D:\> python encoder.py -h
usage: encoder.py [options] <command|file>
positional arguments:
command Specifies either a command or script file's path for encoding
optional arguments:
-h, --help show this help message and exit
-x KEY, --xor KEY Specifies command/file XOR encode key (one byte)
-o PATH, --output PATH
(optional) Output file. If not given - will echo output to stdout
PS D:\> python encoder.py -x 0x31 "Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode"
ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU
Dann übergeben wir die Ausgabe von encoder.py als codierten Befehl an Stracciatella:
PS D:\> Stracciatella.exe -v -x 0x31 -c "ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU" .\Test2.ps1