Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
larac2shell — Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response | Kitploit
Tools/GitHubGitHub/akefallonitis/larac2shell
Lateral MovementScripting & AutomationPost-ExploitationPenetration TestingCommand and ControlUtilities & FrameworksAuthenticationIncident ResponseRemote Access Tool
GitHubakefallonitis/larac2shell

larac2shell

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

151205 months agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LaraC2 Shell -- MDE Live Response Interactive Shell

CI License: MIT PowerShell 7+ Platforms

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response.

FeatureDetail
PlatformPowerShell Core 7.0+ (Windows, Linux, macOS)
API modesInternal (portal, near-realtime) and Official (public, stateless)
ExecutionArbitrary commands + 25 native LR commands
Auth7 authentication methods, unified menu, auto-refresh
LicenseMIT

LaraC2 Shell connects to MDE Live Response through two independent API paths -- the internal portal API (persistent sessions, ~2-5s latency) and the official public API (per-command, ~20-60s latency). It auto-uploads executor stubs, handles rate limiting transparently, and provides a full REPL with machine management, library management, and a built-in help system.

Documentation

DocPurpose
User GuideStep-by-step setup, auth, and operation
Command ReferenceAll commands, routing, batching, tab completion
Error ReferenceHTTP codes, shell errors, auth errors, fixes
PerformanceInternal vs Official latency, throughput, limits
ArchitectureInternals, auth chains, endpoints, file layout
ContributingHow to contribute, test, submit PRs
Security PolicyHow to report a vulnerability privately
ReferencesPrior art, related research, credits
DisclaimerAuthorization, credits

Features

  • Two API modes: Internal (portal, ~2-5s/cmd, near-real-time) + Official (public, ~20-60s/cmd, CI/CD ready)
  • 7 auth methods in a unified menu: client creds, device code, credentials+TOTP, passkey/HSM, ESTS cookie, TAP, direct sccauth -- mode is derived from the auth choice
  • 25 native LR commands + arbitrary command execution via auto-uploaded B64 executor stubs
  • Cross-OS targeting: Windows, Linux, macOS endpoints (auto-selects executor + encoding)
  • Transparent rate limiting: 429 backoff, ActiveRequest smart conflict resolution (12 retries, cancel external / wait own)
  • Session lifecycle: auto-connect, auto-reconnect on 30-min inactivity, stale session pruning, cross-machine switching
  • Auth lifecycle: OAuth2 auto-refresh, XSRF auto-refresh (4-min TTL), silent re-auth for TOTP/passkey; connect command re-authenticates when session expires
  • Session reuse: transparent auto-connect, auto-reconnect, and cross-machine switching with no user intervention
  • Multi-machine execution: multi command with name pattern filtering and top-N limiting
  • Multi-command batching: up to 5 commands per Official API call, auto-split for larger sets
  • Library management: list, upload, delete, download, auto-upload executor stubs, 409 conflict override
  • Action management: list, cancel (partial ID match), status detail
  • Interactive UX: tab completion, command aliases (ls/ps/netstat), working directory tracking, help system
  • Error guidance: context-aware messages (400->syntax, 401->reauth, 403->scopes, 429->rate limit)
  • No secrets on CLI: credentials from config file or interactive prompt, never in command history

Quick Start

Prerequisites

  • PowerShell Core 7.0+ (Windows, Linux, or macOS)
  • Either a portal account with Live Response access (internal mode) or an MDE app registration with Machine.LiveResponse + Library.Manage permissions (official mode)

Launch

git clone https://github.com/akefallonitis/larac2shell.git
cd larac2shell
pwsh -File shell/Invoke-MDEShell.ps1

That's it. The shell presents a unified 7-method auth menu on first launch — pick one, authenticate, select a machine, and you're in a REPL. No config file, no flags, nothing to set up.

  Select API mode:

    Internal API  (security.microsoft.com — near real-time, ~2-5s/cmd)
    1  Credentials + MFA        username + password, TOTP/push/SMS [auto-refresh]
    2  Software passkey          FIDO2/WebAuthn JSON key file [auto-refresh]
    3  ESTS cookie               ESTSAUTHPERSISTENT from browser (~24hr)
    4  Temporary Access Pass     one-time admin-issued code
    5  Direct sccauth + XSRF     cookies from browser DevTools (~1hr)

    Official API  (api.securitycenter.microsoft.com — CI/CD ready, ~20-60s/cmd)
    6  Device code               browser login (interactive)
    7  Client credentials        app registration with client secret

  Auth method (1-7):

Choices 1-5 set internal mode, 6-7 set official. You can switch modes later without restarting — see Switching modes inline below.

Switching modes inline

[INT myhost C:\]> mode
  Current mode: Internal API
  Switch with: 'mode internal' or 'mode official'.

[INT myhost C:\]> mode official
  [Mode] Switching from Internal API to official...
  (auth menu for official mode opens)
  [Mode] Now in official mode.
  Run 'machines' to list targets or 'connect <name|id>' to select one.

mode <target> disconnects any current LR session, clears the old auth state, and re-runs the auth flow for the target mode. When it returns you're authenticated in the new mode with no machine selected — run machines to list, or connect <name|id> to jump straight to a target. No restart required.

CLI shortcuts (optional)

For scripting or when you want to skip the unified menu:

# Pre-select the mode (narrows the auth menu to 1-5 or 6-7)
pwsh -File shell/Invoke-MDEShell.ps1 -Mode internal
pwsh -File shell/Invoke-MDEShell.ps1 -Mode official

# Pre-select a machine (skips the picker)
pwsh -File shell/Invoke-MDEShell.ps1 -Machine myhost

# Software passkey path (internal mode)
pwsh -File shell/Invoke-MDEShell.ps1 -PasskeyPath ./keys/passkey.json

# Non-interactive single command (exits with remote command's exit code)
pwsh -File shell/Invoke-MDEShell.ps1 -Machine myhost -Command 'whoami'

Config file (optional)

Only used for one scenario: official mode with a client secret, non-interactively. Every other auth method prompts you interactively and stores nothing on disk. If you don't need unattended client-credentials auth, you can skip this section entirely.

Copy-Item shell/config/shell-config.example.json shell/config/shell-config.json
# Edit the file: set official.tenantId, official.clientId, official.clientSecret
pwsh -File shell/Invoke-MDEShell.ps1 -Config shell/config/shell-config.json

Config schema (all fields optional except official.tenantId + official.clientId when using client credentials):

Download Tool