APT-Sac à dos
CVE les plus couramment utilisés par les APT, RAT légitimes et autres outils utilisés par les adversaires
CVE
- CVE-2019-11510 (Pulse Connect Secure 8.2 8.3 9.0) Lecture de fichier non autorisée
- CVE-2019-19781 (Citrix ADC & Gateway) Traversée de répertoire
- CVE-2020-5902 (F5 Big IP) RCE
- CVE-2021-1497 (Cisco HyperFlex HX) Injection de commande non autorisée
- CVE-2021-20090 (Buffalo WSR-2533DHP2 WSR-2533DHP3) RCE non autorisée
- CVE-2021-22006 (Vmware vCenter Server) Contournement d'authentification
- CVE-2021-22205 (GitLab CE/EE) RCE
- CVE-2021-26084 (Atlassian Confluence) RCE non autorisée
- CVE-2021-26855 (Microsoft Exchange Server) RCE
- CVE-2021-26857 (Microsoft Exchange Server) RCE
- CVE-2021-26858 (Microsoft Exchange Server) RCE
- CVE-2021-26865 (Microsoft Exchange Server) RCE
- CVE-2021-36260 (Hikvision) Injection de commande
- CVE-2021-40539 (ManageEngine ADSelfService Plus) Contournement d'authentification API -> RCE
- CVE-2021-41773 (Apache HTTP Server 2.4.49) Traversée de chemin
- CVE-2021-42237 (Sitecore XP 7.5) Désérialisation -> RCE
- CVE-2021-44228 (Apache Log4j) RCE
- CVE-2021-40444 (Microsoft Office) RCE
- CVE-2022-1388 (F5 BIG-IP) RCE
- CVE-2022-24112 (Apache APISIX 2.12.1) RCE
- CVE-2022-26134 (Atlassian Confluence) RCE
RAT légitimes (Outils d'administration à distance) & Sockets de serveurs
- Client d'administration Ammyy v3 (windows) (Ceci est détecté par de nombreuses défenses)
- Client Ngrok (windows/linux)
Exploitation
- Suite Sysinternals
- PSTools
Exfiltration
Phishing
- Document Office avec avertissements (activer le contenu)
Reverse shell
Utilisez-le correctement, je ne suis pas responsable de toute mauvaise utilisation de ce pack