Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Nebula — NebulaはクラウドC2フレームワークであり、現時点ではAWS上での偵察、列挙、エクスプロイト、ポストエクスプロイトを提供していますが、他のクラウドプロバイダーやDevOpsコンポーネントのテストを可能にするためにまだ作業中です。 | Kitploit
ツール/GitHubGitHub/gl4ssesbo1/nebula
ペネトレーションテストフレームワーク偵察エクスプロイトフレームワークポストエクスプロイトクラウドセキュリティコマンド&コントロール
GitHubgl4ssesbo1/nebula

Nebula

NebulaはクラウドC2フレームワークであり、現時点ではAWS上での偵察、列挙、エクスプロイト、ポストエクスプロイトを提供していますが、他のクラウドプロバイダーやDevOpsコンポーネントのテストを可能にするためにまだ作業中です。

リポジトリを見る
6351081年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Nebula

logo

Nebulaは、クラウドおよび(できれば)DevOpsペネトレーションテストフレームワークです。各プロバイダーと各機能に対応したモジュールで構成されています。2021年4月現在、AWSのみをカバーしていますが、現在進行中のプロジェクトであり、将来的にはGCP、Azure、Kubernetes、Docker、またはAnsible、Terraform、Chefなどの自動化エンジンをテストできるよう拡張されることを期待しています。このツールは、『Hands-On AWS Penetration Testing with Kali Linux』(https://www.amazon.com/Hands-Penetration-Testing-Kali-Linux/dp/1789136725)を読みながら書き始め、Pacu(https://github.com/RhinoSecurityLabs/pacu)をベースにしています。

プレゼンテーション:

  • BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#nebula-a-case-study-in-penetrating-something-as-soft-as-a-cloud-25174

現在カバーしている範囲:

  • AWS、Azure(Graph APIおよびManagement API)、DigitalOceanの列挙、エクスプロイト、およびポストエクスプロイト

現在、以下の分野をカバーする53のモジュールがあります:

  • 偵察
  • 列挙
  • エクスプロイト
  • クリーンアップ

バージョン3.0の新機能:

  • クライアント-チームサーバーアーキテクチャによるチーム協力
  • すべてのリクエストは認証が必要です(もちろん認証リクエストを除く)
  • すべての情報はMongoDBサーバーに保存され、コマンドを使用してアクセスできます。情報は事前に列挙されている必要がありますが、これにより特定のオブジェクトの列挙を避けることができます。

インストール

サーバー

Nebulaはpython3.11で記述されています。AWSへのアクセスにはboto3ライブラリを使用しています。インストールするには、teamserverディレクトリに移動してコンテナをビルドしてください:``` $ docker build -t nebula-teamserver .

root@kitploit:~
その後、dockerで実行するだけです:```
$ docker run -it nebula-teamserver -dH <database host> -du <database user> -dp <database password> -dn <database name> --p <teamserver password>
------------------------------------------------------------
           _   _      _           _
          | \ | |    | |         | |
          |  \| | ___| |__  _   _| | __ _
          | . ` |/ _ \ '_ \| | | | |/ _` |
  _______ | |\  |  __/ |_) | |_| | | (_| |
 |__   __||_| \_|\___|_.__/ \__,_|_|\__,_|
    | | ___  __ _ _ __ ___  ___  ___ _ ____   _____ _ __
    | |/ _ \/ _` | '_ ` _ \/ __|/ _ \ '__\ \ / / _ \ '__|
    | |  __/ (_| | | | | | \__ \  __/ |   \ V /  __/ |
    |_|\___|\__,_|_| |_| |_|___/\___|_|    \_/ \___|_|
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          11 azuread
4 digitalocean
-------------------------------------------------------------
60 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager        0 postexploitation
1 misc

[*] Port is busy. Is a MongoDB instance running there? [y/N] y
------------------------------------------------------------
[*] JWT Secret Key set to: '<secret value>'
[*] Database Server set to: '<db host>:<db port>'
[*] Database set to: '<db name>'
[*] Teamserver IP address is '<teamserver host>'
[*] User 'cosmonaut' was created!
[*] API Server set to: '<api host>:<api port>'
------------------------------------------------------------

クライアント

クライアント client についても同様です。client ディレクトリに移動して、コンテナをビルドしてください:``` $ docker build -t nebula-client .

root@kitploit:~
その後、dockerを使って実行するだけです:```
$ docker run -it nebula-client -ah <api host> -p <teamserver password> -b
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          13 azuread
4 digitalocean
-------------------------------------------------------------
62 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager
1 misc          2 initialaccess         0 postexploitation
-------------------------------------------------------------

[*] Importing sessions found on ~/.aws
[*] No sessions found on ~/.aws
()()(Nebula) >>>

使用方法```

root@kitploit:~
                                                  ...........
                                          ...''''''''''''''...
                                       ..'''''...........''''''............
                                     ..''''..             ...'''''''''''''''...
                                   ..'''..                   ..............'''''..
                                  .''''.          .;loddool:'.              ..''''..
                                 ..'''.          .;clokXWWMWNKkl;.             .''''.
                                 .'''.      .',,'..    ';dNMMMMMWKko;.           .'''..
                                .''''.   .cx0NWWNX0koc;,'cKMMMMMMMMMWXOo:.        .''''....
                                .'''.   .',',:oONMMMMMWNNNWMMMMMMWKk0WMMWXx'       .''''''''...
                               ..'''.          .,dXMMMMMMMMMMMMMNOl',oONWWd.        .......'''''..
                            ...'''''..   :o'      cXMMMMMMMMMMMMMWNXKKXNWWKxc,.             ..''''..
                          ..''''....     oNKl'. ..oXMMMMMMMMMMMMMMMMMMMMMMMMMNKOdc,..         ..''''.
                        ..''''..         ,OWWX0O0XWMMMMMMMMMMMMMMMMMMWWWWMMMMMMMMMWXOxooxk:.    ..'''.
     ..'''''''''''''''''''''.             .l0NMMMMMMMMMMMMMMMMMMMMN0dc;;;coONMMMMMMMMMMMMMK:     ..'''.
     .......................                .,dXMMMMMMMMMMMMMMMMMMWX0ko:.  .;OWMMMMMMMMMMMWx.     .'''.
                                              .oWMMMMMMMMMMMMMMWNXXXWMMWKd'  .:lccclodOXWMWd.      .'''.
         ,lc'    ..................   ',.    .,OWMMMMMMMMMMMMXx:'...:0WMMMKl.      .. .'oKO,       .'''.
        ,0MWx.  .''''''''''''''''''.  ;OKOOOO0NWMMMMMMMMMMMMNl.     .cdoox0XOl;'....... ...        .'''.
        .;ol'    ...................   ;kXWMMMMMMMMMMMMMMMMMWx.          .:0WNKkdo:.  ...         .'''.
       ....................              .:ldxk0XWMMMMMMMMMMMW0o'        .';;,.         ....     ..'''.
     ;k00000000000000000000x'                  ..;lkXWMMMMMMMMMWXkc.                            ..'''.
    .lXWWWWWWWWWWWWWWWWWWMMWKl.                     ;OWMMMMMMMMMMMWKx:.                       ..''''.
      .,,,,,,,,,,,,,,,,,:kNMMW0o,.                  'kWMMMMMMMMMMMMMMWKd,.                  ..''''..
                         .:ONMMMNKkdlc:::::::::ccldkKWMMMMMMMMMMMMMMMMMMNOl'    ...........'''''..
                           .,oOXWMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMWXkc....''''''''''...
                              .':ldkO0000000000000000000000000000000000000000Ox:.  ........
                                     ...........................................


                               _        _______  ______            _        _______
                              ( (    /|(  ____ \(  ___ \ |\     /|( \      (  ___  )
                              |  \  ( || (    \/| (   ) )| )   ( || (      | (   ) |
                              |   \ | || (__    | (__/ / | |   | || |      | (___) |
                              | (\ \) ||  __)   |  __ (  | |   | || |      |  ___  |
                              | | \   || (      | (  \ \ | |   | || |      | (   ) |
                              | )  \  || (____/\| )___) )| (___) || (____/\| )   ( |
                              |/    )_)(_______/|/ \___/ (_______)(_______/|/     \|
                                                    Because Clouds are so AWSome

                            -------------------------------------------------------------
                                                            Created by: gl4ssesbo1
                            -------------------------------------------------------------
                            48 aws          1 gcp           7 azure         0 office365
                            0 docker        0 kubernetes    6 misc          4 azuread
                            4 digitalocean
                            -------------------------------------------------------------
                            81 modules      6 cleanup               0 detection
                            19 enum         22 exploit              2 persistence
                            2 listeners     0 lateral movement      7 detection bypass
                            0 privesc       16 reconnaissance       2 stager        1 postexploitation
                            4 misc

                            Remember:
                            -------------------------------------------------------------
                            1) Only use this  tool  if  you  have  permissions  from  the
                            infrastructure's owner. Don't be a dick. Don't  choose  jail.
                            And if you have some scruples, don't hack others just because
                            you can (or cannot, in which case that's why you  chose  this
                            tool to do it).

                            2) There is a template file on module directory that you  can
                            use if you want to  develop  new  modules.  If  you  want  to
                            contribute on this tool, be my guest.

                            3) Thank you for using this tool and Hack the Planet Legally!
                            -------------------------------------------------------------

[] Importing sessions found on ~/.aws [] Imported sessions found on ~/.aws. Enter 'show credentials' to get the credentials. (test)()(Nebula)

root@kitploit:~
### ヘルプ
*help* コマンドを実行すると、使用可能なコマンドの一覧が表示されます:```
()()(AWS) >>> help

    Help Command:               Description:
    -------------               ------------

    help                        Show help for all the commands
    help credentials            Show help for credentials
    help module                 Show help for modules
    help workspace              Show help for credentials
    help user-agent             Show help for credentials
    help shell                  Show help for shell connections


    Module Commands             Description
    ---------------             -----------

    show modules                List all the modules
    show enum                   List all Enumeration modules
    show exploit                List all Exploit modules
    show persistence            List all Persistence modules
    show privesc                List all Privilege Escalation modules
    show reconnaissance         List all Reconnaissance modules
    show listener               List all Reconnaissance modules
    show cleanup                List all Enumeration modules
    show detection              List all Exploit modules
    show detectionbypass        List all Persistence modules
    show lateralmovement        List all Privilege Escalation modules
    show stager                 List all Reconnaissance modules

    use module <module>         Use a module.
    options                     Show options of a module you have selected.
    run                         Run a module you have selected. Eg: 'run <module name>'
    search                      Search for a module via pattern. Eg: 'search s3'
    back                        Unselect a module
    set <option>                Set option of a module. Need to have the module used first.
    unset <option>              Unset option of a module. Need to have the module used first.


    User-Agent commands         Description
    -------------------         -----------

    set user-agent windows      Set a windows client user agent
    set user-agent linux        Set a linux client user agent
    set user-agent custom       Set a custom client user agent
    show user-agent             Show the current user-agent
    unset user-agent            Use the user agent that boto3 produces


    Workspace Commands          Description
    ------------------          -----------

    create workspace <wp>       Create a workspace
    use workspace <wp>          Use one of the workspaces
    remove workspace <wp>       Remove a workspace


    Shell commands              Description
    -------------------         -----------

    shell check_env             Check the environment you are in, get data and meta-data
    shell exit                  Kill a connection
    shell <command>             Run a command on a system. You don't need " on the command, just shell <command1> <command2>

権限の列挙

一連の資格情報がある場合、getuid を入力してユーザーを取得するか、enum_user_privs を入力して資格情報セットの読み取り権限を確認できます。

GetUID```

(test)()(AWS) >>> getuid

UserId: A******************Q

root@kitploit:~
    UserID: A******************Q
    Arn: arn:aws:iam::012345678912:user/user_user
    Account: 012345678912

[*] Output is saved to './workspaces/test/12_07_2021_02_22_54_getuid_dev_brian'

root@kitploit:~
自身が以下の権限を持っていない場合、```
STS:GetUserIdentity
IAM:GetUser
IAM:ListAttachedUserPolicies
IAM:GetPolicy (for all policies)

エラーが発生します:``` [*] An error occurred (AccessDenied) when calling the GetUser operation: User: arn:aws:iam::012345678912:user/user_user is not authorized to perform: iam:GetUser on resource: user user_user

root@kitploit:~
#### Enum_User_Privs
このコマンドは、一連の資格情報に対する特権の一覧表示と説明を確認します。```
(test)()(AWS) >>> enum_user_privs
User: user_user
        UserID: A******************Q
        Arn: arn:aws:iam::012345678912:user/user_user
        Account: 012345678912
--------------------------
Service: ec2
--------------------------
[*] Trying the 'Describe' functions:
[*] 'describe_account_attributes' worked!
[*] 'describe_addresses' worked!
[*] 'describe_aggregate_id_format' worked!
[*] 'describe_availability_zones' worked!
[*] 'describe_bundle_tasks' worked!
[*] 'describe_capacity_reservations' worked!
[*] 'describe_client_vpn_endpoints' worked!
[*] 'describe_coip_pools' worked!
[*] 'describe_customer_gateways' worked!
[*] 'describe_dhcp_options' worked!
[*] 'describe_egress_only_internet_gateways' worked!
^C[*] Stopping. It might take a while. Please wait.
[*] Output of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_enum_user_privs'
[*] The list of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_allowed_functions'

モジュール

モジュールの一覧表示

すべてのモジュールまたは特定のモジュールを一覧表示できます:``` ()()(AWS) >>> show modules cleanup/aws_iam_delete_access_key Delete access key of a user by providing it.

root@kitploit:~
    cleanup/aws_iam_delete_login_profile                                  Delete access of a user to the Management
                                                                            Console

    enum/aws_ec2_enum_elastic_ips                                         Lists User data of an Instance provided.
                                                                            Requires Secret Key and Access Key of an IAM that has access
                                                                            to it.

    enum/aws_ec2_enum_images                                              List all ec2 images. Needs credentials of an
                                                                            IAM with DescribeImages right. Output is dumpled on a file.
                                                                            It takes a sh*tload of time, unfortunately. And boy, is it a
                                                                            huge output.

    enum/aws_ec2_enum_instances                                           Describes instances attribues: Instances, VCP,
                                                                            Zones, Images, Security Groups, Snapshots, Subnets, Tags,
                                                                            Volumes. Requires Secret Key and Access Key of an IAM that
                                                                            has access to all or any of the API calls:
                                                                            DescribeAvailabilityZones, DescribeImages,
                                                                            DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups,
                                                                            DescribeSnapshots, DescribeSubnets, DescribeTags,
                                                                            DescribeVolumes, DescribeVpcs
root@kitploit:~
そして、次のように使用できます:```
     show module
     show enum
     show exploit
     show persistence
     show privesc
     show reconnaissance
     show listener
     show cleanup
     show detection
     show detectionbypass
     show lateralmovement
     show stager

モジュールの検索

特定の単語でモジュールを検索するには、search コマンドを使用します:``` ()()(AWS) >>> search instance enum/aws_ec2_enum_instances Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

root@kitploit:~
    enum/aws_iam_list_instance_profiles                                   List all the instance profiles.

    exploit/aws_ec2_create_instance_with_user_data                        You must provide policies in JSON format in
                                                                            IAM. However, for AWS CloudFormation templates formatted in
                                                                            YAML, you can provide the policy in JSON or YAML format. AWS
                                                                            CloudFormation always converts a YAML policy to JSON format
                                                                            before submitting it to IAM.

()()(AWS) >>>

root@kitploit:~
#### モジュールの使用
モジュールを使用するには、*use* とモジュール名を入力するだけです。3つの括弧にモジュール名が表示されます。```
(work1)()(enum/aws_ec2_enum_instances) >>> use module enum/aws_iam_get_group
(work1)()(enum/aws_ec2_enum_instances) >>>

オプション

オプションを使用して、モジュールの情報を一覧表示できます:``` (work1)()(enum/aws_ec2_enum_instances) >>> options Desctiption:

root@kitploit:~
    Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

AWSCLI Command:

root@kitploit:~
    aws ec2 describe-instances --region {} --profile {}

Needs Credentials: True

Options:

root@kitploit:~
    SERVICE:        ec2
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    INSTANCE-ID:
            Required: false
            Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
オプションを設定するには、*set* とオプション名を使用します:```
(work1)()(enum/aws_ec2_enum_instances) >>> set INSTANCE-ID 1234
(work1)()(enum/aws_ec2_enum_instances) >>> options
Desctiption:
-----------------------------
        Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: True
-----------------------------

AWSCLI Command:
-----------------------------
        aws ec2 describe-instances --region {} --profile {}

Options:
-----------------------------
        SERVICE:        ec2
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        INSTANCE-ID:    1234
                Required: false
                Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

また、それらの設定を解除するには、unsetを使用します。``` (work1)()(enum/aws_ec2_enum_instances) >>> unset INSTANCE-ID (work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### モジュールの実行
モジュールを実行するには、認証情報が必要な場合、それを実行するために必要な権限を持つ認証情報のセットをインポートしておく必要があります。これはモジュールのオプションに次のように表示されます:```
Needs Credentials: True
-----------------------------

実行するには、runと入力してください。出力に応じて、ページ分割されたビューが表示されるか、単に印刷されます。ページネーションにはlessバイナリを使用し、Windowsでは**https://github.com/jftuga/less-Windows**のバイナリを使用します。exeのコピーはless_binaryディレクトリにあります。 出力はワークスペースディレクトリのファイルにも保存されます:``` (work1)()(enum/aws_ec2_enum_instances) >>> run [*] Content dumped on file './workspaces/work1/16_04_2021_18_16_48_ec2_enum_instances'.

root@kitploit:~
### 認証情報
####認証情報の入力
Nebulaは、AccessKeyID + SecretKeyの組み合わせと、AccessKeyID + SecretKey + SessionKeyの組み合わせの両方を使用してインフラストラクチャに認証できます。
認証情報のセットを挿入するには、次のようにします:```
()()(AWS) >>> set credentials test1
Profile Name: test1
Access Key ID: A*********2
Secret Key ID: a****************************7
Region: us-west-3

Do you also have a session token?[y/N]
[*] Credentials set. Use 'show credentials' to check them.
[*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

そして、それらを設定するためのいくつかの入力が表示されます。認証情報を入力する際に、セッショントークンを追加できます。セッショントークンもお持ちですか?[y/N] と尋ねられたら y と入力します。

####認証情報を使用する 別の認証情報を使用するには、次のように入力します:``` ()()(AWS) >>> use credentials test1 [*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

root@kitploit:~
####現在の認証情報
認証情報を入力すると、自動的に現在の認証情報(認証に使用するもの)になります。現在の認証情報を確認するには、次のように使用します:```
()()(AWS) >>> show current-creds
{
    "profile": "test1",
    "access_key_id": "A*********2",
    "secret_key": "a****************************7",
    "region": "us-west-3"
}

####資格情報の削除 資格情報を保持したくない場合は、以下のコマンドを使用して削除できます:``` ()()(AWS) >>> remove credentials test1 You are about to remove credential 'test1'. Are you sure? [y/N] y

root@kitploit:~
####認証情報のダンプとインポート
マシンに認証情報を保存したい場合は、次を使用できます:```
()()(AWS) >>> dump credentials
[*] Credentials dumped on file './credentials/16_04_2021_17_37_59'.

そして、それらはNebulaディレクトリ内のcredentialsディレクトリに、ダンプの日時を含むファイル名で保存されます。インポートするには、次のように入力します:``` ()()(AWS) >>> import credentials 16_04_2021_17_37_59 ()()(AWS) >>> show credentials [ { "profile": "test1", "access_key_id": "A*******2", "secret_key": "a**************************7", "region": "us-west-3" } ]

root@kitploit:~
### ワークスペース
Nebulaは、すべてのコマンドの出力を保存するためにワークスペースを使用します。出力は (s3_name_fuzzer は XML として保存されますが) json データとして、*workspaces* ディレクトリに作成されたフォルダに保存されます。
#### ワークスペースの作成
作成するには、次のように入力します:```
()()(AWS) >>> create workspace work1
[*] Workspace 'work1' created.
[*] Current workspace set at 'work1'.
(work1)()(AWS) >>> ls ./workspaces


    Directory: C:\Users\***\Desktop\Nebula\workspaces


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         4/16/2021   5:42 PM                work1
-a----         4/16/2021   4:40 PM              0 __init__.py

作成時、最初の括弧には作業中のワークスペース名が含まれます。 既存のワークスペースを使用したい場合は、次のように入力してください:``` ()()(AWS) >>> use workspace work1 (work1)()(AWS) >>>

root@kitploit:~
ワークスペースの使用が必須です。そのため、現時点で使用していなくても、モジュールを実行すると、ランダムな名前で作成するか、自分でカスタム名を付けて作成するよう求められます。```
()()(enum/aws_ec2_enum_instances) >>> run
A workspace is not configured. Workstation 'qxryiuct' will be created. Are you sure? [y/N] n
[*] Create a workstation first using 'create workstation <workstation name>'.
()()(enum/aws_ec2_enum_instances) >>>

ワークスペースの一覧表示

ワークスペースの一覧を取得するには、次を使用します:``` (work1)()(enum/aws_ec2_enum_instances) >>> show workspaces

Workspaces:

root@kitploit:~
    work1

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### ワークスペースの削除
ワークスペースを削除するには、次のように入力します。```
()()(AWS) >>> remove workspace work1
[*] Are you sure you want to delete the workspace? [y/N] y
()()(AWS) >>> show workspaces
-----------------------------------
Workspaces:
-----------------------------------

()()(AWS) >>>

リバースシェル

リバースシェルを作成するには、ステイガーを作成し、リスナーを実行する必要があります。この機能を使用するには、Nebulaをrootとして実行する必要があります(ポートを開くため)。

ステイガー

ステイガーを生成するには、ステイガー上のモジュールを使用してください。``` ()()(AWS) >>> use module stager/aws_python_tcp ()()(stager/aws_python_tcp) >>> options Desctiption:

root@kitploit:~
    The TCP Reverse Shell that is used by listeners/aws_python_tcp_listener

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

Needs Credentials: False

AWSCLI Command:

root@kitploit:~
    None

Options:

root@kitploit:~
    SERVICE:        none
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    HOST:
            Required: true
            Description: The Host/IP of the C2 Server.

    PORT:
            Required: true
            Description: The C2 Server Port.

    FORMAT:
            Required: true
            Description: The format of the stager. Currently only allows 'py' for Python and 'elf' for ELF Binary.

    CALLBACK-TIME:  None
            Required: true
            Description: The time in seconds between callbacks from Stager. The Stager calls back even if the server crashes or is stoped in a loop.

    OUTPUT-FILE-NAME:
            Required: true
            Description: The name of the stager output file.
root@kitploit:~
記入するオプションは次のとおりです。
   - **HOST**: C2サーバーのIPまたはドメイン
   - **Port**: C2サーバーのポート
   - **Format**: 現時点では、python rawファイルとelfバイナリのみをサポートしています
   - **Callback-Time**: セッションがコールバックする時間(秒単位)。現在のセッションがアクティブな場合でも、サーバーがクラッシュまたは閉じられた場合でもコールバックするため、マシンへのアクセスを失うことはありません。
   - **Output File Name**: 出力ファイルの名前。

モジュールを実行すると、**./workspaces/workspacename/stagername** に保存されたステイガーが生成されます。

#### リスナー
リスナーはシンプルです。ホスト(デフォルトでは0.0.0.0に設定)とポートを設定するだけでサーバーが作成されます。リスナーを実行するには、Nebulaをrootとして実行する必要があります。```
()()(stager/aws_python_tcp) >>> use module listeners/aws_python_tcp_listener
()()(listeners/aws_python_tcp_listener) >>> options
Desctiption:
-----------------------------
        TCP Listener for Reverse Shell stagers/aws_python_tcp

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: False
-----------------------------

AWSCLI Command:
-----------------------------
        None

Options:
-----------------------------
        SERVICE:        none
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        HOST:   0.0.0.0
                Required: true
                Description: The Host/IP of the C2 Server.

        PORT:
                Required: true
                Description: The C2 Server Port.

ユーザーエージェント

ユーザーエージェントは、Linux用、Windows用、またはカスタムとして設定できます。表示するには、show を使用してください。``` ()()(AWS) >>> set user-agent linux User Agent: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic ()()(AWS) >>> set user-agent windows User Agent: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 ()()(AWS) >>> set user-agent custom Enter the User-Agent you want: sth User Agent: sth was set ()()(AWS) >>> show user-agent [*] User Agent is: sth ()()(AWS) >>>

root@kitploit:~
ユーザーエージェントを設定解除するには、次のように入力してください。```
()()(AWS) >>> unset user-agent
[*] User Agent set to empty.

システムのユーザーエージェントを持つもの。

ツールをダウンロード