
運用セキュリティ上安全な、C#内から(別名SharpPick)のPowerShell実行空間。AMSI、制約言語モード、スクリプトブロックログが起動時に無効化されています。
C# 内からの PowerShell ランスペース(別名 SharpPick 手法)で、AMSI、ETW、スクリプトブロックログ記録を無効化した状態でお届けします。
昨今、PowerShell は以下のような技法により厳重に計装されています:
高度な攻撃者はこれらの防御を回避する方法を見つけなければならず、洗練された敵対的シミュレーション演習を実施するためには特に重要です。そのような取り組みを支援するために、本プロジェクトが作成されました。
このプログラムは、以下の特定の技法に対するバイパスを基に構築されています:
これらのバイパスはさらに以下の研究に基づいています:
SharpPick のアイデア、すなわち C# アセンブリ内から Runspaces を使用して PowerShell スクリプトを起動するという手法も新しいものではなく、最初に実装したのは Lee Christensen (@tifkin_) 氏の以下です:
また、ソースコードは CustomPSHost の実装を Lee 氏から借用しています。
本プロジェクトは上記の研究と優れたセキュリティコミュニティから継承し、起動時に防御が無効化された実効性の高い PowerShell 環境を提供することを目的としています。
.NET 4.0 で簡単にコンパイルできます。一方、.NET Framework 4.7.1+ でコンパイルすると、CLM バイパス成果物を構成する DLL をアンロードし、その後それらを削除しようとする追加機能が含まれます(正直なところ、うまく機能するとは限りません)。
最良の結果が得られるのは、.NET 4.0 でコンパイルされた Stracciatella です。
いくつかのオプションが利用可能です:
PS D:\> Stracciatella -h
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
Usage: stracciatella.exe [options] [command]
-s <path>, --script <path> - Path to file containing Powershell script to execute. If not options given, will enter
a pseudo-shell loop. This can be also a HTTP(S) URL to download & execute powershell script.
-v, --verbose - Prints verbose informations
-n, --nocleanup - Don't remove CLM disable leftovers (DLL files in TEMP and COM registry keys).
By default these are going to be always removed.
-C, --leaveclm - Don't attempt to disable CLM. Stealthier. Will avoid leaving CLM disable artefacts undeleted.
-f, --force - Proceed with execution even if Powershell defenses were not disabled.
By default we bail out on failure.
-c, --command - Executes the specified commands You can either use -c or append commands after
stracciatella parameters: cmd> straciatella ipconfig /all
If command and script parameters were given, executes command after running script.
-x <key>, --xor <key> - Consider input as XOR encoded, where <key> is a one byte key in decimal
(prefix with 0x for hex)
-p <name>, --pipe <name> - Read powershell commands from a specified named pipe. Command must be preceded with 4 bytes of
its length coded in little-endian (Length-Value notation).
-t <millisecs>, --timeout <millisecs>
- Specifies timeout for pipe read operation (in milliseconds). Default: 60 secs. 0 - infinite.
-e, --cmdalsoencoded - Consider input command (specified in '--command') encoded as well.
Decodes input command after decoding and running input script file.
By default we only decode input file and consider command given in plaintext
プログラムはコマンドとスクリプトファイルのパスを入力として受け入れます。両方ともオプションで、何も指定されなければ疑似シェルが起動します。 コマンドとスクリプトはどちらも、1バイト XOR(Base64 エンコード出力)を使用してさらにエンコードでき、OpSec の向上に役立ちます。
以下にいくつかの使用例を示します:
PS D:\> Stracciatella.exe -v
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Powershell's version: 5.1
[.] Language Mode: FullLanguage
[+] No need to disable Constrained Language Mode. Already in FullLanguage.
[+] Script Block Logging Disabled.
[+] AMSI Disabled.
[+] ETW Disabled.
Stracciatella D:\> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.18362.1
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.18362.1
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
まず、エンコードされたステートメントを準備するために、同梱の encoder.py スクリプトを使用できます。使用方法は次のとおりです:
PS D:\> python encoder.py -h
usage: encoder.py [options] <command|file>
positional arguments:
command Specifies either a command or script file's path for encoding
optional arguments:
-h, --help show this help message and exit
-x KEY, --xor KEY Specifies command/file XOR encode key (one byte)
-o PATH, --output PATH
(optional) Output file. If not given - will echo output to stdout
PS D:\> python encoder.py -x 0x31 "Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode"
ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU
次に、encoder.py の出力を Stracciatella のエンコードされたコマンドとして入力します:
PS D:\> Stracciatella.exe -v -x 0x31 -c "ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU" .\Test2.ps1
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Will load script file: '.\Test2.ps1'
[+] AMSI Disabled.
[+] ETW Disabled.
[+] Script Block Logging Disabled.
[.] Language Mode: FullLanguage
PS> & '.\Test2.ps1'
PS> Write-Host "It works like a charm!" ; $ExecutionContext.SessionState.LanguageMode
[+] Yeeey, it really worked.
It works like a charm!
FullLanguage
ここで:
Command は次のコマンドから構成されています:Base64Encode(XorEncode("Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode", 0x31))Test2.ps1 には以下が含まれています:"ZkNYRVQceV5CRRETahpsEWhUVFRIHRFYRRFDVFBdXUgRRl5DWlRVHxM=" (Base64(XorEncode("Write-Host \"[+] Yeeey, it really worked.\"", 0x31)))Stracciatella には Aggressor スクリプトが付属しており、これをロードすると Beacon コンソールで stracciatella コマンドが使用可能になります。使用法は powerpick と非常に似ています(事前に stracciatella-import で PowerShell スクリプトをインポート)。入力パラメータはランダムなキーで XOR され、ランダムに名前付けられたパイプを介して Stracciatella の runspace に渡されます。
以下の Cobalt Strike コマンドが利用可能です: