Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Nebula — Nebula es un Framework C2 en la nube, que por el momento ofrece reconocimiento, enumeración, explotación, post explotación en AWS, pero aún se trabaja para permitir pruebas en otros Proveedores de Nube y Componentes de DevOps. | Kitploit
Herramientas/GitHubGitHub/gl4ssesbo1/nebula
Frameworks de Pruebas de PenetraciónReconocimientoFrameworks de ExploitsPost-ExplotaciónSeguridad en la NubeComando y Control
GitHubgl4ssesbo1/nebula

Nebula

Nebula es un Framework C2 en la nube, que por el momento ofrece reconocimiento, enumeración, explotación, post explotación en AWS, pero aún se trabaja para permitir pruebas en otros Proveedores de Nube y Componentes de DevOps.

Ver Repositorio
635108hace 1 añoRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Nebula

logo

Nebula es un marco de trabajo de Pruebas de Penetración en la Nube y (con suerte) DevOps. Está construido con módulos para cada proveedor y cada funcionalidad. A partir de abril de 2021, solo cubre AWS, pero es un proyecto en curso y con suerte seguirá creciendo para probar GCP, Azure, Kubernetes, Docker o motores de automatización como Ansible, Terraform, Chef, etc. Comencé a escribirlo mientras leía "Hands-On AWS Penetration Testing with Kali Linux" (https://www.amazon.com/Hands-Penetration-Testing-Kali-Linux/dp/1789136725) y se basó en Pacu (https://github.com/RhinoSecurityLabs/pacu)

Presentaciones:

  • BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#nebula-a-case-study-in-penetrating-something-as-soft-as-a-cloud-25174

Actualmente cubre:

  • AWS, Azure (Graph y Management API) y DigitalOcean: enumeración, explotación y post-explotación

Actualmente hay 53 módulos que cubren:

  • Reconocimiento
  • Enumeración
  • Explotación
  • Limpieza

La versión 3.0 incluye:

  • Cooperación en equipo con la arquitectura cliente-teamserver
  • Todas las solicitudes requieren autenticación (excepto la solicitud de autenticación, obviamente)
  • Toda la información se almacena en un servidor MongoDB y es accesible mediante comandos. La información, por supuesto, tendrá que haber sido enumerada antes, pero esto permite no enumerar un objeto en particular.

Instalación

Servidor

Nebula está codificado en python3.11. Utiliza la librería boto3 para acceder a AWS. Para instalar, simplemente ve al directorio teamserver y construye el contenedor:``` $ docker build -t nebula-teamserver .

root@kitploit:~
Luego, simplemente ejecútalo usando docker:```
$ docker run -it nebula-teamserver -dH <database host> -du <database user> -dp <database password> -dn <database name> --p <teamserver password>
------------------------------------------------------------
           _   _      _           _
          | \ | |    | |         | |
          |  \| | ___| |__  _   _| | __ _
          | . ` |/ _ \ '_ \| | | | |/ _` |
  _______ | |\  |  __/ |_) | |_| | | (_| |
 |__   __||_| \_|\___|_.__/ \__,_|_|\__,_|
    | | ___  __ _ _ __ ___  ___  ___ _ ____   _____ _ __
    | |/ _ \/ _` | '_ ` _ \/ __|/ _ \ '__\ \ / / _ \ '__|
    | |  __/ (_| | | | | | \__ \  __/ |   \ V /  __/ |
    |_|\___|\__,_|_| |_| |_|___/\___|_|    \_/ \___|_|
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          11 azuread
4 digitalocean
-------------------------------------------------------------
60 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager        0 postexploitation
1 misc

[*] Port is busy. Is a MongoDB instance running there? [y/N] y
------------------------------------------------------------
[*] JWT Secret Key set to: '<secret value>'
[*] Database Server set to: '<db host>:<db port>'
[*] Database set to: '<db name>'
[*] Teamserver IP address is '<teamserver host>'
[*] User 'cosmonaut' was created!
[*] API Server set to: '<api host>:<api port>'
------------------------------------------------------------

Cliente

Al igual que con el cliente cliente. Solo ve al directorio client y construye el contenedor:``` $ docker build -t nebula-client .

root@kitploit:~
Entonces, simplemente ejecútalo usando docker:```
$ docker run -it nebula-client -ah <api host> -p <teamserver password> -b
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          13 azuread
4 digitalocean
-------------------------------------------------------------
62 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager
1 misc          2 initialaccess         0 postexploitation
-------------------------------------------------------------

[*] Importing sessions found on ~/.aws
[*] No sessions found on ~/.aws
()()(Nebula) >>>

Uso```

root@kitploit:~
                                                  ...........
                                          ...''''''''''''''...
                                       ..'''''...........''''''............
                                     ..''''..             ...'''''''''''''''...
                                   ..'''..                   ..............'''''..
                                  .''''.          .;loddool:'.              ..''''..
                                 ..'''.          .;clokXWWMWNKkl;.             .''''.
                                 .'''.      .',,'..    ';dNMMMMMWKko;.           .'''..
                                .''''.   .cx0NWWNX0koc;,'cKMMMMMMMMMWXOo:.        .''''....
                                .'''.   .',',:oONMMMMMWNNNWMMMMMMWKk0WMMWXx'       .''''''''...
                               ..'''.          .,dXMMMMMMMMMMMMMNOl',oONWWd.        .......'''''..
                            ...'''''..   :o'      cXMMMMMMMMMMMMMWNXKKXNWWKxc,.             ..''''..
                          ..''''....     oNKl'. ..oXMMMMMMMMMMMMMMMMMMMMMMMMMNKOdc,..         ..''''.
                        ..''''..         ,OWWX0O0XWMMMMMMMMMMMMMMMMMMWWWWMMMMMMMMMWXOxooxk:.    ..'''.
     ..'''''''''''''''''''''.             .l0NMMMMMMMMMMMMMMMMMMMMN0dc;;;coONMMMMMMMMMMMMMK:     ..'''.
     .......................                .,dXMMMMMMMMMMMMMMMMMMWX0ko:.  .;OWMMMMMMMMMMMWx.     .'''.
                                              .oWMMMMMMMMMMMMMMWNXXXWMMWKd'  .:lccclodOXWMWd.      .'''.
         ,lc'    ..................   ',.    .,OWMMMMMMMMMMMMXx:'...:0WMMMKl.      .. .'oKO,       .'''.
        ,0MWx.  .''''''''''''''''''.  ;OKOOOO0NWMMMMMMMMMMMMNl.     .cdoox0XOl;'....... ...        .'''.
        .;ol'    ...................   ;kXWMMMMMMMMMMMMMMMMMWx.          .:0WNKkdo:.  ...         .'''.
       ....................              .:ldxk0XWMMMMMMMMMMMW0o'        .';;,.         ....     ..'''.
     ;k00000000000000000000x'                  ..;lkXWMMMMMMMMMWXkc.                            ..'''.
    .lXWWWWWWWWWWWWWWWWWWMMWKl.                     ;OWMMMMMMMMMMMWKx:.                       ..''''.
      .,,,,,,,,,,,,,,,,,:kNMMW0o,.                  'kWMMMMMMMMMMMMMMWKd,.                  ..''''..
                         .:ONMMMNKkdlc:::::::::ccldkKWMMMMMMMMMMMMMMMMMMNOl'    ...........'''''..
                           .,oOXWMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMWXkc....''''''''''...
                              .':ldkO0000000000000000000000000000000000000000Ox:.  ........
                                     ...........................................


                               _        _______  ______            _        _______
                              ( (    /|(  ____ \(  ___ \ |\     /|( \      (  ___  )
                              |  \  ( || (    \/| (   ) )| )   ( || (      | (   ) |
                              |   \ | || (__    | (__/ / | |   | || |      | (___) |
                              | (\ \) ||  __)   |  __ (  | |   | || |      |  ___  |
                              | | \   || (      | (  \ \ | |   | || |      | (   ) |
                              | )  \  || (____/\| )___) )| (___) || (____/\| )   ( |
                              |/    )_)(_______/|/ \___/ (_______)(_______/|/     \|
                                                    Because Clouds are so AWSome

                            -------------------------------------------------------------
                                                            Created by: gl4ssesbo1
                            -------------------------------------------------------------
                            48 aws          1 gcp           7 azure         0 office365
                            0 docker        0 kubernetes    6 misc          4 azuread
                            4 digitalocean
                            -------------------------------------------------------------
                            81 modules      6 cleanup               0 detection
                            19 enum         22 exploit              2 persistence
                            2 listeners     0 lateral movement      7 detection bypass
                            0 privesc       16 reconnaissance       2 stager        1 postexploitation
                            4 misc

                            Remember:
                            -------------------------------------------------------------
                            1) Only use this  tool  if  you  have  permissions  from  the
                            infrastructure's owner. Don't be a dick. Don't  choose  jail.
                            And if you have some scruples, don't hack others just because
                            you can (or cannot, in which case that's why you  chose  this
                            tool to do it).

                            2) There is a template file on module directory that you  can
                            use if you want to  develop  new  modules.  If  you  want  to
                            contribute on this tool, be my guest.

                            3) Thank you for using this tool and Hack the Planet Legally!
                            -------------------------------------------------------------

[] Importing sessions found on ~/.aws [] Imported sessions found on ~/.aws. Enter 'show credentials' to get the credentials. (test)()(Nebula)

root@kitploit:~
### Help
Ejecutar el comando *help* le mostrará una lista de los comandos que se pueden usar:```
()()(AWS) >>> help

    Help Command:               Description:
    -------------               ------------

    help                        Show help for all the commands
    help credentials            Show help for credentials
    help module                 Show help for modules
    help workspace              Show help for credentials
    help user-agent             Show help for credentials
    help shell                  Show help for shell connections


    Module Commands             Description
    ---------------             -----------

    show modules                List all the modules
    show enum                   List all Enumeration modules
    show exploit                List all Exploit modules
    show persistence            List all Persistence modules
    show privesc                List all Privilege Escalation modules
    show reconnaissance         List all Reconnaissance modules
    show listener               List all Reconnaissance modules
    show cleanup                List all Enumeration modules
    show detection              List all Exploit modules
    show detectionbypass        List all Persistence modules
    show lateralmovement        List all Privilege Escalation modules
    show stager                 List all Reconnaissance modules

    use module <module>         Use a module.
    options                     Show options of a module you have selected.
    run                         Run a module you have selected. Eg: 'run <module name>'
    search                      Search for a module via pattern. Eg: 'search s3'
    back                        Unselect a module
    set <option>                Set option of a module. Need to have the module used first.
    unset <option>              Unset option of a module. Need to have the module used first.


    User-Agent commands         Description
    -------------------         -----------

    set user-agent windows      Set a windows client user agent
    set user-agent linux        Set a linux client user agent
    set user-agent custom       Set a custom client user agent
    show user-agent             Show the current user-agent
    unset user-agent            Use the user agent that boto3 produces


    Workspace Commands          Description
    ------------------          -----------

    create workspace <wp>       Create a workspace
    use workspace <wp>          Use one of the workspaces
    remove workspace <wp>       Remove a workspace


    Shell commands              Description
    -------------------         -----------

    shell check_env             Check the environment you are in, get data and meta-data
    shell exit                  Kill a connection
    shell <command>             Run a command on a system. You don't need " on the command, just shell <command1> <command2>

Enum Privs

Cuando tengas un conjunto de credenciales, puedes ingresar getuid para obtener el usuario o enum_user_privs para verificar el permiso de lectura de un conjunto de credenciales.

GetUID```

(test)()(AWS) >>> getuid

UserId: A******************Q

root@kitploit:~
    UserID: A******************Q
    Arn: arn:aws:iam::012345678912:user/user_user
    Account: 012345678912

[*] Output is saved to './workspaces/test/12_07_2021_02_22_54_getuid_dev_brian'

root@kitploit:~
Si los creds no tienen los siguientes privs sobre sí mismo,```
STS:GetUserIdentity
IAM:GetUser
IAM:ListAttachedUserPolicies
IAM:GetPolicy (for all policies)

obtendrás un error:``` [*] An error occurred (AccessDenied) when calling the GetUser operation: User: arn:aws:iam::012345678912:user/user_user is not authorized to perform: iam:GetUser on resource: user user_user

root@kitploit:~
#### Enum_User_Privs
Este comando verifica Listar y Describir Privilegios en un conjunto de credenciales.```
(test)()(AWS) >>> enum_user_privs
User: user_user
        UserID: A******************Q
        Arn: arn:aws:iam::012345678912:user/user_user
        Account: 012345678912
--------------------------
Service: ec2
--------------------------
[*] Trying the 'Describe' functions:
[*] 'describe_account_attributes' worked!
[*] 'describe_addresses' worked!
[*] 'describe_aggregate_id_format' worked!
[*] 'describe_availability_zones' worked!
[*] 'describe_bundle_tasks' worked!
[*] 'describe_capacity_reservations' worked!
[*] 'describe_client_vpn_endpoints' worked!
[*] 'describe_coip_pools' worked!
[*] 'describe_customer_gateways' worked!
[*] 'describe_dhcp_options' worked!
[*] 'describe_egress_only_internet_gateways' worked!
^C[*] Stopping. It might take a while. Please wait.
[*] Output of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_enum_user_privs'
[*] The list of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_allowed_functions'

Módulos

Listado de módulos

Puedes listar todos los módulos o un módulo específico:``` ()()(AWS) >>> show modules cleanup/aws_iam_delete_access_key Delete access key of a user by providing it.

root@kitploit:~
    cleanup/aws_iam_delete_login_profile                                  Delete access of a user to the Management
                                                                            Console

    enum/aws_ec2_enum_elastic_ips                                         Lists User data of an Instance provided.
                                                                            Requires Secret Key and Access Key of an IAM that has access
                                                                            to it.

    enum/aws_ec2_enum_images                                              List all ec2 images. Needs credentials of an
                                                                            IAM with DescribeImages right. Output is dumpled on a file.
                                                                            It takes a sh*tload of time, unfortunately. And boy, is it a
                                                                            huge output.

    enum/aws_ec2_enum_instances                                           Describes instances attribues: Instances, VCP,
                                                                            Zones, Images, Security Groups, Snapshots, Subnets, Tags,
                                                                            Volumes. Requires Secret Key and Access Key of an IAM that
                                                                            has access to all or any of the API calls:
                                                                            DescribeAvailabilityZones, DescribeImages,
                                                                            DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups,
                                                                            DescribeSnapshots, DescribeSubnets, DescribeTags,
                                                                            DescribeVolumes, DescribeVpcs
root@kitploit:~
Y así puedes usar:```
     show module
     show enum
     show exploit
     show persistence
     show privesc
     show reconnaissance
     show listener
     show cleanup
     show detection
     show detectionbypass
     show lateralmovement
     show stager

Búsqueda de módulos

Use el comando search para buscar módulos con una palabra específica:``` ()()(AWS) >>> search instance enum/aws_ec2_enum_instances Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

root@kitploit:~
    enum/aws_iam_list_instance_profiles                                   List all the instance profiles.

    exploit/aws_ec2_create_instance_with_user_data                        You must provide policies in JSON format in
                                                                            IAM. However, for AWS CloudFormation templates formatted in
                                                                            YAML, you can provide the policy in JSON or YAML format. AWS
                                                                            CloudFormation always converts a YAML policy to JSON format
                                                                            before submitting it to IAM.

()()(AWS) >>>

root@kitploit:~
#### Usando Módulos
Para usar un módulo, simplemente escribe *use* y el nombre del módulo. Los 3 corchetes tendrán el nombre del módulo.```
(work1)()(enum/aws_ec2_enum_instances) >>> use module enum/aws_iam_get_group
(work1)()(enum/aws_ec2_enum_instances) >>>

Opciones

Usando opciones, podemos listar la información del módulo:``` (work1)()(enum/aws_ec2_enum_instances) >>> options Desctiption:

root@kitploit:~
    Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

AWSCLI Command:

root@kitploit:~
    aws ec2 describe-instances --region {} --profile {}

Needs Credentials: True

Options:

root@kitploit:~
    SERVICE:        ec2
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    INSTANCE-ID:
            Required: false
            Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
Para establecer opciones, usa *set* y el nombre de la opción:```
(work1)()(enum/aws_ec2_enum_instances) >>> set INSTANCE-ID 1234
(work1)()(enum/aws_ec2_enum_instances) >>> options
Desctiption:
-----------------------------
        Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: True
-----------------------------

AWSCLI Command:
-----------------------------
        aws ec2 describe-instances --region {} --profile {}

Options:
-----------------------------
        SERVICE:        ec2
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        INSTANCE-ID:    1234
                Required: false
                Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

También desactivándolos, usando unset.``` (work1)()(enum/aws_ec2_enum_instances) >>> unset INSTANCE-ID (work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### Ejecutando el módulo
Para ejecutar el módulo, si requiere credenciales, necesitará haber importado un conjunto de credenciales con el permiso necesario para ejecutarlo. Esto se muestra en las opciones de un módulo como:```
Needs Credentials: True
-----------------------------

Para ejecutarlo, solo ingrese run. Dependiendo de la salida, mostrará una vista paginada o simplemente la imprimirá. La paginación utiliza el binario less, que para Windows usa el binario de https://github.com/jftuga/less-Windows. Una copia del ejecutable está en el directorio less_binary. La salida también se guarda en archivos en el directorio de trabajo:``` (work1)()(enum/aws_ec2_enum_instances) >>> run [*] Content dumped on file './workspaces/work1/16_04_2021_18_16_48_ec2_enum_instances'.

root@kitploit:~
### Credenciales
####Ingresando Credenciales
Nebula puede usar tanto la combinación de AccessKeyID + SecretKey como la combinación de AccessKeyID + SecretKey + SessionKey para autenticarse en la infraestructura. Para insertar un conjunto de credenciales, use:```
()()(AWS) >>> set credentials test1
Profile Name: test1
Access Key ID: A*********2
Secret Key ID: a****************************7
Region: us-west-3

Do you also have a session token?[y/N]
[*] Credentials set. Use 'show credentials' to check them.
[*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

Y obtendrás algunas entradas que te permitirán configurarlos. El token de sesión se puede añadir al ingresar las credenciales, respondiendo y cuando se pregunte ¿También tienes un token de sesión?[y/N].

####Usando credenciales Para usar otra credencial, solo ingresa:``` ()()(AWS) >>> use credentials test1 [*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

root@kitploit:~
####Credenciales actuales
Cuando introduces las credenciales, se convierten automáticamente en las credenciales actuales, es decir, aquellas con las que te autenticarás. Para verificar las credenciales actuales, utiliza:```
()()(AWS) >>> show current-creds
{
    "profile": "test1",
    "access_key_id": "A*********2",
    "secret_key": "a****************************7",
    "region": "us-west-3"
}

####Eliminar credenciales En caso de que no quieras tus credenciales, puedes eliminarlas usando:``` ()()(AWS) >>> remove credentials test1 You are about to remove credential 'test1'. Are you sure? [y/N] y

root@kitploit:~
####Volcado e importación de credenciales
En caso de que quieras que tus credenciales se guarden en la máquina, puedes usar:```
()()(AWS) >>> dump credentials
[*] Credentials dumped on file './credentials/16_04_2021_17_37_59'.

Y se guardarán en un archivo que contiene la fecha y hora del volcado en el directorio credentials dentro del directorio de Nebula. Para importarlos, solo ingresa:``` ()()(AWS) >>> import credentials 16_04_2021_17_37_59 ()()(AWS) >>> show credentials [ { "profile": "test1", "access_key_id": "A*******2", "secret_key": "a**************************7", "region": "us-west-3" } ]

root@kitploit:~
### Workspaces
Nebula utiliza workspaces para guardar la salida de cada comando. La salida se guarda como datos json (excepto s3_name_fuzzer que lo guarda como XML) en una carpeta creada en el directorio *workspaces*.
#### Crear Workspaces
Para crear uno, ingresa:```
()()(AWS) >>> create workspace work1
[*] Workspace 'work1' created.
[*] Current workspace set at 'work1'.
(work1)()(AWS) >>> ls ./workspaces


    Directory: C:\Users\***\Desktop\Nebula\workspaces


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         4/16/2021   5:42 PM                work1
-a----         4/16/2021   4:40 PM              0 __init__.py

Cuando se crea, los primeros corchetes contendrán el nombre del espacio de trabajo en el que estás trabajando. Si quieres usar un espacio de trabajo existente, solo escribe:``` ()()(AWS) >>> use workspace work1 (work1)()(AWS) >>>

root@kitploit:~
Los espacios de trabajo son obligatorios, por lo que aunque no estés usando ninguno en ese momento, al ejecutar un módulo, te pedirá que crees uno con un nombre aleatorio o que simplemente crees uno con un nombre personalizado tú mismo.```
()()(enum/aws_ec2_enum_instances) >>> run
A workspace is not configured. Workstation 'qxryiuct' will be created. Are you sure? [y/N] n
[*] Create a workstation first using 'create workstation <workstation name>'.
()()(enum/aws_ec2_enum_instances) >>>

Listar espacios de trabajo

Para obtener una lista de espacios de trabajo, use:``` (work1)()(enum/aws_ec2_enum_instances) >>> show workspaces

Workspaces:

root@kitploit:~
    work1

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### Eliminar espacios de trabajo
Para eliminar un espacio de trabajo, ingrese:```
()()(AWS) >>> remove workspace work1
[*] Are you sure you want to delete the workspace? [y/N] y
()()(AWS) >>> show workspaces
-----------------------------------
Workspaces:
-----------------------------------

()()(AWS) >>>

Shell inversa

Para crear una Reverse Shell, necesitas crear un stager y ejecutar un listener. Para usar esta funcionalidad, necesitas que Nebula se ejecute como root (para abrir puertos).

Stager

Para generar un stager, usa los módulos en stagers:``` ()()(AWS) >>> use module stager/aws_python_tcp ()()(stager/aws_python_tcp) >>> options Desctiption:

root@kitploit:~
    The TCP Reverse Shell that is used by listeners/aws_python_tcp_listener

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

Needs Credentials: False

AWSCLI Command:

root@kitploit:~
    None

Options:

root@kitploit:~
    SERVICE:        none
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    HOST:
            Required: true
            Description: The Host/IP of the C2 Server.

    PORT:
            Required: true
            Description: The C2 Server Port.

    FORMAT:
            Required: true
            Description: The format of the stager. Currently only allows 'py' for Python and 'elf' for ELF Binary.

    CALLBACK-TIME:  None
            Required: true
            Description: The time in seconds between callbacks from Stager. The Stager calls back even if the server crashes or is stoped in a loop.

    OUTPUT-FILE-NAME:
            Required: true
            Description: The name of the stager output file.
root@kitploit:~
Las opciones a completar son:
   - **HOST**: La IP o dominio del servidor C2
   - **Port**: El puerto del servidor C2
   - **Format**: Actualmente solo soporta archivo raw de python y binario elf
   - **Callback-Time**: El tiempo en segundos durante el cual las sesiones deben llamar de vuelta. Llama de vuelta incluso si hay una sesión activa, e incluso si el servidor se bloquea o se cierra, para que no pierdas acceso a la máquina.
   - **Output File Name**: El nombre del archivo de salida.

Ejecutar el módulo generará un stager guardado en **./workspaces/workspacename/stagername**

#### Listener
El listener es simple. Solo configura Host (por defecto establecido a 0.0.0.0) y Port y crea el servidor. Para ejecutar el listener, necesitas tener Nebula ejecutándose como root.```
()()(stager/aws_python_tcp) >>> use module listeners/aws_python_tcp_listener
()()(listeners/aws_python_tcp_listener) >>> options
Desctiption:
-----------------------------
        TCP Listener for Reverse Shell stagers/aws_python_tcp

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: False
-----------------------------

AWSCLI Command:
-----------------------------
        None

Options:
-----------------------------
        SERVICE:        none
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        HOST:   0.0.0.0
                Required: true
                Description: The Host/IP of the C2 Server.

        PORT:
                Required: true
                Description: The C2 Server Port.

Agentes de usuario

Los agentes de usuario se pueden configurar como los de Linux, los de Windows o personalizados. Para mostrarlos, solo usa show.``` ()()(AWS) >>> set user-agent linux User Agent: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic ()()(AWS) >>> set user-agent windows User Agent: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 ()()(AWS) >>> set user-agent custom Enter the User-Agent you want: sth User Agent: sth was set ()()(AWS) >>> show user-agent [*] User Agent is: sth ()()(AWS) >>>

root@kitploit:~
Para desactivar un agente de usuario, ingrese:```
()()(AWS) >>> unset user-agent
[*] User Agent set to empty.

Que tendrá el agente de usuario del sistema.

Descargar herramienta