Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Outils/GitHubGitHub/cyb3rward0g/invoke-attackapi
ReconnaissanceCollecte d'InformationsUtilitaires et FrameworksRenseignement sur les MenacesApprentissage et ÉducationRessources OrganiséesArchived
GitHubcyb3rward0g/invoke-attackapi

Invoke-ATTACKAPI

Un script PowerShell pour interagir avec le framework MITRE ATT&CK via sa propre API

Voir le dépôt
3688123il y a 7 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Invoke-ATTACKAPI [DÉPRÉCIÉ]

NOUS RECOMMANDONS D'UTILISER : https://github.com/Cyb3rWard0g/ATTACK-Python-Client

Un script PowerShell pour interagir avec le framework MITRE ATT&CK via son propre API afin de collecter des informations sur les techniques, tactiques, groupes, logiciels et références fournis par l'équipe MITRE ATT&CK @MITREattack. CE SCRIPT UTILISE ENCORE L'API MEEDIAWIKI DÉPRÉCIÉE. IL N'A PAS ENCORE ÉTÉ MIS À JOUR POUR UTILISER L'API PUBLIQUE DES SERVEURS TAXII

Objectifs

  • Fournir un moyen simple d'interagir avec le framework MITRE ATT&CK via son propre API et PowerShell pour la communauté.
  • Accélérer l'acquisition de données d'ATT&CK lors de la préparation d'une campagne de chasse.
  • Apprendre les paramètres dynamiques de PowerShell :)

Ressources

  • API MITRE ATT&CK
  • API Semantic MediaWiki
  • Get-ATTack
    • Walter Legowski @SadProcessor

Pour commencer

Prérequis

  • PowerShell version 3+

Installation / Importation```

git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1

/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]

        Adversarial Tactics, Techniques & Common Knowledge API

[*] Author: Roberto Rodriguez @Cyb3rWard0g

[++] Pulling MITRE ATT&CK Data

## Exemples
### Cette requête correspond à toutes les techniques```
Invoke-ATTACKAPI -Category -Technique

ID                  : {T1001}
Bypass              : {}
Contributor         : {}
Requires System     : {}
Data Source         : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description         : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
                      attempt to make the content more difficult to discover or decipher and to make the
                      communication less conspicuous and hide commands from being seen. This encompasses many
                      methods, such as adding junk data to protocol traffic, using steganography, commingling
                      legitimate traffic with C2 communications traffic, or using a non-standard data encoding
                      system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation          : {Network intrusion detection and prevention systems that use network signatures to
                      identify traffic for specific adversary malware can be used to mitigate activity at the
                      network level. Signatures are often for unique indicators within protocols and may be
                      based on the specific obfuscation technique used by a particular adversary or tool, and
                      will likely be different across various malware families and versions. Adversaries will
                      likely change tool C2 signatures over time or construct protocols in such a way as to
                      avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic              : Command and Control
Analytic Details    : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
                      data than it receives from a server). Processes utilizing the network that do not normally

                      have network communication or have never been seen before are suspicious. Analyze packet
                      contents to detect communications that do not follow the expected protocol behavior for
                      the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName       : {Data Obfuscation}
FullText            : Technique/T1001
Link Text           : {[[Technique/T1001|Data Obfuscation]]}
Reference           : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform            : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name                : {Data Obfuscation}
CAPEC ID            : {}
Requires Permission : {}
URL                 : https://attack.mitre.org/wiki/Technique/T1001
.............
..................
Télécharger l’outil