
a tool to help operate in EDRs' blind spots
Pyramid is composed of:
Pyramid is useful to perform post-exploitation task in an evasive manner, executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. This can be achieved because:
For more information please check the DEFCON30 - Adversary village talk "Python vs Modern Defenses" slide deck and this post on my blog.
This tool was created to demostrate a bypass strategy against EDRs based on some blind-spots assumptions. It is a combination of already existing techniques and tools in a (to the best of my knowledge) novel way that can help evade defenses. The sole intent of the tool is to help the community increasing awareness around this kind of usage and accelerate a resolution. It's not a 0day, it's not a full fledged shiny C2, Pyramid exploits what might be EDRs blind spots and the tool has been made public to shed some light on them. A defense paragraph has been included, hoping that experienced blue-teamers can help contribute and provide better possible resolution on the issue Pyramid aims to highlight. All information is provided for educational purposes only. Follow instructions at your own risk. Neither the author nor his employer are responsible for any direct or consequential damage or loss arising from any person or organization.
Pyramid's in-memory loading was initially inspired and expanded upon xorrior 's Empyre - Finder Class
snovvcrash built the modules mod-DonPAPI.py - mod-LaZagne.py - mod-clr.py
Pyramid modules capabilities can be executed directly from a Python interpreter and are currently:
Pyramid HTTP server main features:
Cradle main features:
Pyramid can be used with a Python Interpreter already existing on a target machine, or unpacking an official embeddable Python package and then running python.exe to execute a Python download cradle. This is a simple way to avoid creating uncommon Process tree pattern and looking like a normal Python application usage.
In Pyramid the download cradle is used to reach a Pyramid Server via HTTP/S to fetch modules and dependencies.
Modules are specific for the feature you want to use and contain:
The Python dependencies have been already fixed and modified to be imported in memory without conflicting.
There are currently 8 Pyramid modules available:
git clone https://github.com/naksyn/Pyramid
Generate SSL certificates for HTTP Server:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365
If you want to use your own signed SSL certificate be sure to:
As an example, if you want to use pythonmemorymodule with Pyramid, put your payload in the Delivery_files folder, then open pythonmemorymodule.py and configure the needed parameters in the top of the script, such as the name of the payload file and the procedure you want to call after the PE has been loaded.
Once the Pyramid server is running and the Base script is ready you can set the variable pyramid_module in Agent/cradle.py file and execute it on the target.
The cradle is built to be run with python standard libraries.
Example of running Pyramid HTTP Server using SSL certificate providing Basic Authentication, encrypting delivery files using ChaCha and auto-generating server configuration in modules and printing a pastable cradle for pythonmemorymodule: