
Nebula est un framework C2 cloud, qui offre actuellement des fonctionnalités de reconnaissance, d'énumération, d'exploitation et de post-exploitation sur AWS, mais travaille encore pour permettre de tester d'autres fournisseurs cloud et composants DevOps.
Nebula est un framework de test de pénétration Cloud et (espérons-le) DevOps. Il est construit avec des modules pour chaque fournisseur et chaque fonctionnalité. En avril 2021, il ne couvre que AWS, mais c'est un projet en cours et il devrait continuer à s'étendre pour tester GCP, Azure, Kubernetes, Docker, ou des moteurs d'automatisation comme Ansible, Terraform, Chef, etc. J'ai commencé à l'écrire en lisant "Hands-On AWS Penetration Testing with Kali Linux" (https://www.amazon.com/Hands-Penetration-Testing-Kali-Linux/dp/1789136725) et il s'inspirait de Pacu (https://github.com/RhinoSecurityLabs/pacu)
Présentations :
Couverture actuelle :
Il y a actuellement 53 modules couvrant :
Version 3.0 inclut :
Nebula est codé en python3.11. Il utilise la bibliothèque boto3 pour accéder à AWS.
Pour installer, allez simplement dans le répertoire teamserver et construisez le conteneur :```
$ docker build -t nebula-teamserver .
Ensuite, exécutez-le simplement en utilisant docker :```
$ docker run -it nebula-teamserver -dH <database host> -du <database user> -dp <database password> -dn <database name> --p <teamserver password>
------------------------------------------------------------
_ _ _ _
| \ | | | | | |
| \| | ___| |__ _ _| | __ _
| . ` |/ _ \ '_ \| | | | |/ _` |
_______ | |\ | __/ |_) | |_| | | (_| |
|__ __||_| \_|\___|_.__/ \__,_|_|\__,_|
| | ___ __ _ _ __ ___ ___ ___ _ ____ _____ _ __
| |/ _ \/ _` | '_ ` _ \/ __|/ _ \ '__\ \ / / _ \ '__|
| | __/ (_| | | | | | \__ \ __/ | \ V / __/ |
|_|\___|\__,_|_| |_| |_|___/\___|_| \_/ \___|_|
-------------------------------------------------------------
37 aws 0 gcp 4 azure 0 office365
0 docker 0 kubernetes 4 misc 11 azuread
4 digitalocean
-------------------------------------------------------------
60 modules 6 cleanup 0 detection
19 enum 5 exploit 2 persistence
1 listeners 0 lateral movement 7 detection bypass
7 privesc 10 reconnaissance 2 stager 0 postexploitation
1 misc
[*] Port is busy. Is a MongoDB instance running there? [y/N] y
------------------------------------------------------------
[*] JWT Secret Key set to: '<secret value>'
[*] Database Server set to: '<db host>:<db port>'
[*] Database set to: '<db name>'
[*] Teamserver IP address is '<teamserver host>'
[*] User 'cosmonaut' was created!
[*] API Server set to: '<api host>:<api port>'
------------------------------------------------------------
Idem pour le client client. Allez simplement dans le répertoire client et construisez le conteneur :```
$ docker build -t nebula-client .
Ensuite, exécutez-le simplement en utilisant docker :```
$ docker run -it nebula-client -ah <api host> -p <teamserver password> -b
-------------------------------------------------------------
37 aws 0 gcp 4 azure 0 office365
0 docker 0 kubernetes 4 misc 13 azuread
4 digitalocean
-------------------------------------------------------------
62 modules 6 cleanup 0 detection
19 enum 5 exploit 2 persistence
1 listeners 0 lateral movement 7 detection bypass
7 privesc 10 reconnaissance 2 stager
1 misc 2 initialaccess 0 postexploitation
-------------------------------------------------------------
[*] Importing sessions found on ~/.aws
[*] No sessions found on ~/.aws
()()(Nebula) >>>
...........
...''''''''''''''...
..'''''...........''''''............
..''''.. ...'''''''''''''''...
..'''.. ..............'''''..
.''''. .;loddool:'. ..''''..
..'''. .;clokXWWMWNKkl;. .''''.
.'''. .',,'.. ';dNMMMMMWKko;. .'''..
.''''. .cx0NWWNX0koc;,'cKMMMMMMMMMWXOo:. .''''....
.'''. .',',:oONMMMMMWNNNWMMMMMMWKk0WMMWXx' .''''''''...
..'''. .,dXMMMMMMMMMMMMMNOl',oONWWd. .......'''''..
...'''''.. :o' cXMMMMMMMMMMMMMWNXKKXNWWKxc,. ..''''..
..''''.... oNKl'. ..oXMMMMMMMMMMMMMMMMMMMMMMMMMNKOdc,.. ..''''.
..''''.. ,OWWX0O0XWMMMMMMMMMMMMMMMMMMWWWWMMMMMMMMMWXOxooxk:. ..'''.
..'''''''''''''''''''''. .l0NMMMMMMMMMMMMMMMMMMMMN0dc;;;coONMMMMMMMMMMMMMK: ..'''.
....................... .,dXMMMMMMMMMMMMMMMMMMWX0ko:. .;OWMMMMMMMMMMMWx. .'''.
.oWMMMMMMMMMMMMMMWNXXXWMMWKd' .:lccclodOXWMWd. .'''.
,lc' .................. ',. .,OWMMMMMMMMMMMMXx:'...:0WMMMKl. .. .'oKO, .'''.
,0MWx. .''''''''''''''''''. ;OKOOOO0NWMMMMMMMMMMMMNl. .cdoox0XOl;'....... ... .'''.
.;ol' ................... ;kXWMMMMMMMMMMMMMMMMMWx. .:0WNKkdo:. ... .'''.
.................... .:ldxk0XWMMMMMMMMMMMW0o' .';;,. .... ..'''.
;k00000000000000000000x' ..;lkXWMMMMMMMMMWXkc. ..'''.
.lXWWWWWWWWWWWWWWWWWWMMWKl. ;OWMMMMMMMMMMMWKx:. ..''''.
.,,,,,,,,,,,,,,,,,:kNMMW0o,. 'kWMMMMMMMMMMMMMMWKd,. ..''''..
.:ONMMMNKkdlc:::::::::ccldkKWMMMMMMMMMMMMMMMMMMNOl' ...........'''''..
.,oOXWMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMWXkc....''''''''''...
.':ldkO0000000000000000000000000000000000000000Ox:. ........
...........................................