
Strumenti sviluppati autonomamente per Movimento Laterale/Esecuzione di Codice
Questo repository è stato creato basandosi sul già esistente MiscTool, quindi un grande ringraziamento a rasta-mouse per averli rilasciati e per avermi dato la giusta motivazione per lavorarci.
Esecuzione comandi / Movimento laterale tramite funzionalità simile a PsExec. Deve essere eseguito nel contesto di un utente privilegiato. Lo strumento si basa su CsExec di rasta-mouse, ma è progettato per consentire un controllo aggiuntivo sulla creazione del servizio, in particolare:
CheeseExec.exe <targetMachine> <serviceName> <binPath> <action>
Vedi anche TikiService.
CheesePS è un framework per Esecuzione Comandi / Movimento Laterale. Si basa su System.Management.Automation.PowerShell per caricare ed eseguire codice arbitrario tramite PowerShell.
Lo strumento è nativamente in grado di bypassare le restrizioni comuni creando e utilizzando runspaces PowerShell su target locali o remoti.
Deve essere eseguito nel contesto di un utente privilegiato (se si utilizza PowerShell Remoting).
Lo strumento è stato originariamente realizzato come miglioramento di CsPosh di rasta_mouse, ma è cresciuto abbastanza da diventare un framework a sé stante e può ora essere utilizzato come iniettore PowerShell generico.
L'idea alla base di questo strumento è stata riassunta nel seguente articolo:
Le principali funzionalità implementate sono:
Il seguente screenshot è uno schema abbastanza accurato per descrivere il flusso di lavoro dello strumento:

Usage:
-t, --target=VALUE Target machine
-c, --code=VALUE Code to execute
-e, --encoded Indicates that provided code is base64 encoded
-a, --am-si-bypass=VALUE Uses the given PowerShell script to bypass A-M-S-
I (fs, smb o http[s])
--aX, --encrypted-am-si
Indicates that provided A.M.S.I. bypass is
encrypted
-i, --import=VALUE Imports additional PowerShell modules (fs, smb o
http[s])
--iX, --encrypted-imports
Indicates that provided PowerShell modules are
encrypted
-o, --outstring Append Out-String to code
-r, --redirect Redirect stderr to stdout
-d, --domain=VALUE Domain for alternate credentials
-u, --username=VALUE Username for alternate credentials
-p, --password=VALUE Password for alternate credentials
-X, --encrypt=VALUE Encrypt a script with an hardcoded key
-D, --decrypt=VALUE Test decryption of a script with an hardcoded key
-n, --skip-bypass=VALUE Skip A.M.S.I (A), WLDP (W) or ALL (*) Bypass
techniques
-l, --lockdown-escape Try to enable PowerShell FullLanguage mode using
REGINI
-w, --wldp-bypass=VALUE Uses the given PowerShell script to bypass WLDP
(fs, smb o http[s])
--wX, --encrypted-wldp Indicates that provided WLDP bypass is encrypted
-x, --executable=VALUE [Download and] Execute given executable
--xX, --encrypted-executable
Indicates that provided Exe/DLL is encrypted
--xCS, --executable-csharp
Indicates that the executable provided is C# -
(.NET)
-R, --reflective-injection Uses Invoke-ReflectivePEInjection to load the
assmebly from memory (requires Invoke-
ReflectivePEInjection to be imported!)
-P, --powershell-decrypt Force use of PowerShell-based decryption
-k, --encryption-key=VALUE Uses the provided key for encryption/decryption
--ssl Force use of SSL
-h, -?, --help Show Help
Nota: Se eseguito senza un target, lo script verrà eseguito sulla macchina locale
Vedi anche AmsiBypass.
Esecuzione comandi / Movimento laterale tramite DCOM. Deve essere eseguito nel contesto di un utente privilegiato. Questo strumento si basa su CsDCOM di rasta-mouse, ma è stato migliorato per aggiungere metodi aggiuntivi, adattandosi alle nuove ricerche condotte da Philip Tsukerman. Esiste anche un metodo sperimentale per "riparare" eventuali tentativi di disabilitare gli oggetti DCOM interessati tramite dcomcfg, ma richiede alcune precondizioni per funzionare correttamente.
L'idea alla base di questo strumento è stata riassunta nel seguente articolo:
Metodi attuali: MMC20.Application, ShellWindows, ShellBrowserWindow, ExcelDDE, VisioAddonEx,
OutlookShellEx, ExcelXLL, VisioExecLine, OfficeMacro.
Usage:
-t, --target=VALUE Target Machine
-b, --binary=VALUE Binary: powershell.exe
-a, --args=VALUE Arguments: -enc <blah>
-m, --method=VALUE Methods: MMC20Application, ShellWindows,
ShellBrowserWindow, ExcelDDE, VisioAddonEx,
OutlookShellEx, ExcelXLL, VisioExecLine,
OfficeMacro
-r, --reg, --registry Enable registry manipulation
-h, -?, --help Show Help
Nota: Se eseguito con -t ., lo script verrà eseguito sulla macchina locale
Vedi anche Movimento Laterale Utilizzando Oggetti DCOM e C#
Furto di credenziali RDP tramite RDI (reflective DLL injection). Deve essere eseguito nel contesto di un utente privilegiato o di un utente con SeImpersonatePrivilege.
Questo strumento è costruito sopra RdpThief di MDSec, ma è stato completamente incapsulato in un singolo C# per consentirne l'esecuzione tramite .NET Reflection (Assembly.Load e simili). In questo modo, è possibile eseguirlo tramite Covenant, senza la difficoltà di caricare una DLL sul sistema di destinazione.
Usage:
CheeseRDP [actions]
Actions:
wait: keep listening for any new mstsc.exe process indefinitely (stop with ctrl-C)
clean: delete the credentials dump file if present
dump: dump the content of the file if present, parsing the credentials in a compact format
Nota: Se eseguito senza opzioni, il programma tenterà di iniettarsi in un processo mstsc.exe attivo (il tempo di attesa predefinito è di 10 secondi)
Esecuzione comandi / Movimento laterale tramite Trust MSSQL. Questo strumento è stato sviluppato per superare alcune delle limitazioni degli strumenti esistenti come esc, soprattutto per quanto riguarda l'impersonificazione MSSQL. Inoltre, CheeseSQL è stato specificamente modificato per essere eseguito da Covenant (tramite caricamento riflessivo) e per automatizzare le fasi più importanti dell'abuso del trust MSSQL. Particolarmente divertente è l'implementazione dell'abuso CLR, che consente a un utente di compilare e caricare un'estensione MSSQL al volo con Roslyn per ottenere l'esecuzione di comandi. Una piccola demo è mostrata di seguito, il comando eseguito è un downloader PowerShell codificato di Covenant):

Seguendo la mia regola di "dare sempre credito quando è dovuto", questo strumento è stato sviluppato a partire da un progetto già esistente di Jb05s, chiamato SharpSQL, quindi un grande ringraziamento a Jeremy per il suo lavoro.
Inoltre, consiglio vivamente di vedere tutti gli strumenti di NetSPI riguardanti l'auditing e lo sfruttamento di MSSQL, poiché sono davvero fantastici:
[*] List of available commands:
- findspn : Find MSSQL Instances, using Domain SPNs
- listdb : List available Databases on the server
- gethash : Send Service Account Net-NTLM Hash to an Arbitrary IP
- getlogin : Retrieve SQL Logins Available for Impersonation
- getdbuser : Retrieve Information on the SQL Login, Currently Mapped User, and Available User Roles
- getlinked : Retrieve Information about Linked Servers
- getserverinfo : Retrieve current values of 'xp_cmdshell', 'ole automation procedures' and 'clr enabled'
- xp : Execute Encoded PowerShell Command via 'xp_cmdshell'
- ole : Execute Encoded PowerShell Command via 'sp_OACreate' and 'sp_OAMethod'
- clr : Execute Encoded PowerShell Command via custom .NET assemblies
- rpc : Configure Linked SQL Server to Allow RPC connections
- linkedquery : Execute Encoded PowerShell Command on Linked SQL Server via 'OPENQUERY'
- openquery : Execute an arbitrary query using 'OPENQUERY'
[*] For detailed usage, type:
- CheeseSQL <command> /help