
Spazio di esecuzione PowerShell sicuro per OpSec da C# (noto come SharpPick) con AMSI, Modalità Linguaggio Vincolato e Registrazione Blocchi Script disabilitati all'avvio.
Runspace di PowerShell da C# (nota come tecnica SharpPick) con AMSI, ETW e Script Block Logging disabilitati per vostro piacere.
Al giorno d'oggi, quando PowerShell è stato severamente strumentato tramite tecniche come:
Gli attaccanti avanzati devono trovare modi per aggirare questi sforzi al fine di condurre esercizi di simulazione avversaria sofisticati. Per aiutare in questi sforzi, è stato creato il seguente progetto.
Questo programma si basa su bypass per tecniche specifiche incluse in:
Le quali a loro volta si basavano sulle seguenti ricerche:
L'idea di SharpPick, cioè lanciare script PowerShell da assembly C# tramite l'uso di Runspaces, non è nuova ed è stata implementata per la prima volta da Lee Christensen (@tifkin_) nel suo:
Inoltre, il codice sorgente prende in prestito l'implementazione di CustomPSHost da Lee.
Questo progetto eredita dalle ricerche di cui sopra e dalla grande comunità della sicurezza per fornire un ambiente PowerShell quasi efficace con le difese disabilitate all'avvio.
Ora si compila facilmente con .NET 4.0 mentre se compilato con .NET Framework 4.7.1+ viene inclusa una funzionalità aggiuntiva che permette di scaricare le DLL che costituiscono gli artefatti del bypass CLM e tenta di eliminarle successivamente (a dire il vero, funziona a malapena).
I migliori risultati si ottengono con Stracciatella compilato con .NET 4.0.
Ci sono un paio di opzioni disponibili:
PS D:\> Stracciatella -h
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
Usage: stracciatella.exe [options] [command]
-s <path>, --script <path> - Path to file containing Powershell script to execute. If not options given, will enter
a pseudo-shell loop. This can be also a HTTP(S) URL to download & execute powershell script.
-v, --verbose - Prints verbose informations
-n, --nocleanup - Don't remove CLM disable leftovers (DLL files in TEMP and COM registry keys).
By default these are going to be always removed.
-C, --leaveclm - Don't attempt to disable CLM. Stealthier. Will avoid leaving CLM disable artefacts undeleted.
-f, --force - Proceed with execution even if Powershell defenses were not disabled.
By default we bail out on failure.
-c, --command - Executes the specified commands You can either use -c or append commands after
stracciatella parameters: cmd> straciatella ipconfig /all
If command and script parameters were given, executes command after running script.
-x <key>, --xor <key> - Consider input as XOR encoded, where <key> is a one byte key in decimal
(prefix with 0x for hex)
-p <name>, --pipe <name> - Read powershell commands from a specified named pipe. Command must be preceded with 4 bytes of
its length coded in little-endian (Length-Value notation).
-t <millisecs>, --timeout <millisecs>
- Specifies timeout for pipe read operation (in milliseconds). Default: 60 secs. 0 - infinite.
-e, --cmdalsoencoded - Consider input command (specified in '--command') encoded as well.
Decodes input command after decoding and running input script file.
By default we only decode input file and consider command given in plaintext
Ecco un paio di esempi che presentano casi d'uso:
PS D:\> Stracciatella.exe -v
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Powershell's version: 5.1
[.] Language Mode: FullLanguage
[+] No need to disable Constrained Language Mode. Already in FullLanguage.
[+] Script Block Logging Disabled.
[+] AMSI Disabled.
[+] ETW Disabled.
Stracciatella D:\> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.18362.1
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.18362.1
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
Innanzitutto, per preparare istruzioni codificate possiamo usare lo script encoder.py in dotazione, che può essere usato come segue:
PS D:\> python encoder.py -h
usage: encoder.py [options] <command|file>
positional arguments:
command Specifies either a command or script file's path for encoding
optional arguments:
-h, --help show this help message and exit
-x KEY, --xor KEY Specifies command/file XOR encode key (one byte)
-o PATH, --output PATH
(optional) Output file. If not given - will echo output to stdout
PS D:\> python encoder.py -x 0x31 "Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode"
ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU
Poi forniamo l'output di encoder.py come input per un comando codificato per Stracciatella:
PS D:\> Stracciatella.exe -v -x 0x31 -c "ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU" .\Test2.ps1
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Will load script file: '.\Test2.ps1'
[+] AMSI Disabled.
[+] ETW Disabled.
[+] Script Block Logging Disabled.
[.] Language Mode: FullLanguage