Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Stracciatella — 運用セキュリティ上安全な、C#内から(別名SharpPick)のPowerShell実行空間。AMSI、制約言語モード、スクリプトブロックログが起動時に無効化されています。 | Kitploit
ツール/GitHubGitHub/mgeeky/stracciatella
特権昇格エクスプロイトフレームワークIDS/IPS回避横移動スクリプトと自動化ポストエクスプロイトペネトレーションテストコマンド&コントロールレッドチーミングペイロード開発
GitHubmgeeky/stracciatella
54362914年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Stracciatella

運用セキュリティ上安全な、C#内から(別名SharpPick)のPowerShell実行空間。AMSI、制約言語モード、スクリプトブロックログが起動時に無効化されています。

リポジトリを見る

Stracciatella v0.7

C# 内からの PowerShell ランスペース(別名 SharpPick 手法)で、AMSI、ETW、スクリプトブロックログ記録を無効化した状態でお届けします。

昨今、PowerShell は以下のような技法により厳重に計装されています:

  • AMSI
  • ETW
  • スクリプトブロックログ記録
  • トランスクリプトファイル
  • モジュールログ記録
  • 制約付き言語モード (CLM)

高度な攻撃者はこれらの防御を回避する方法を見つけなければならず、洗練された敵対的シミュレーション演習を実施するためには特に重要です。そのような取り組みを支援するために、本プロジェクトが作成されました。

このプログラムは、以下の特定の技法に対するバイパスを基に構築されています:

  • Disable-Amsi.ps1
  • tandasat 氏による KillETW.ps1
  • Disable-ScriptLogging.ps1

これらのバイパスはさらに以下の研究に基づいています:

  • Matt Graeber: https://github.com/mattifestation/PSReflect
  • Matt Graeber: https://twitter.com/mattifestation/status/735261120487772160
  • Avi Gimpel: https://www.cyberark.com/threat-research-blog/amsi-bypass-redux/
  • Adam Chester: https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/
  • Ryan Cobb: https://cobbr.io/ScriptBlock-Logging-Bypass.html
  • Ryan Cobb: https://cobbr.io/ScriptBlock-Warning-Event-Logging-Bypass.html

SharpPick のアイデア、すなわち C# アセンブリ内から Runspaces を使用して PowerShell スクリプトを起動するという手法も新しいものではなく、最初に実装したのは Lee Christensen (@tifkin_) 氏の以下です:

  • UnmanagedPowerShell

また、ソースコードは CustomPSHost の実装を Lee 氏から借用しています。

本プロジェクトは上記の研究と優れたセキュリティコミュニティから継承し、起動時に防御が無効化された実効性の高い PowerShell 環境を提供することを目的としています。

.NET 4.0 で簡単にコンパイルできます。一方、.NET Framework 4.7.1+ でコンパイルすると、CLM バイパス成果物を構成する DLL をアンロードし、その後それらを削除しようとする追加機能が含まれます(正直なところ、うまく機能するとは限りません)。

最良の結果が得られるのは、.NET 4.0 でコンパイルされた Stracciatella です。

OpSec

  • このプログラムは、XOR 1バイトデコードを使用して、渡されたパラメータをその場でデコードする機能を提供します。
  • コマンドを起動する前に、2つのアプローチで AMSI を無効化し、ETW も無効化します。
  • コマンドを起動する前に、2つのアプローチでスクリプトブロックログ記録を無効化します。
  • このプログラムは、システムライブラリやシステムネイティブコード(amsi.dll など)にパッチを適用しません。
  • メモリダンプ技術(EDR や AV によって管理される)から身を守るため、デコードしたスクリプトやコマンドを過度に長く保存しないよう努めています。

使用法

いくつかのオプションが利用可能です:

PS D:\> Stracciatella -h

  :: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
  Mariusz Banach / mgeeky, '19-22 <[email protected]>
  v0.7

Usage: stracciatella.exe [options] [command]
  -s <path>, --script <path> - Path to file containing Powershell script to execute. If not options given, will enter
                               a pseudo-shell loop. This can be also a HTTP(S) URL to download & execute powershell script.
  -v, --verbose              - Prints verbose informations
  -n, --nocleanup            - Don't remove CLM disable leftovers (DLL files in TEMP and COM registry keys).
                               By default these are going to be always removed.
  -C, --leaveclm             - Don't attempt to disable CLM. Stealthier. Will avoid leaving CLM disable artefacts undeleted.
  -f, --force                - Proceed with execution even if Powershell defenses were not disabled.
                               By default we bail out on failure.
  -c, --command              - Executes the specified commands You can either use -c or append commands after
                               stracciatella parameters: cmd> straciatella ipconfig /all
                               If command and script parameters were given, executes command after running script.
  -x <key>, --xor <key>      - Consider input as XOR encoded, where <key> is a one byte key in decimal
                               (prefix with 0x for hex)
  -p <name>, --pipe <name>   - Read powershell commands from a specified named pipe. Command must be preceded with 4 bytes of
                               its length coded in little-endian (Length-Value notation).
  -t <millisecs>, --timeout <millisecs>
                             - Specifies timeout for pipe read operation (in milliseconds). Default: 60 secs. 0 - infinite.
  -e, --cmdalsoencoded       - Consider input command (specified in '--command') encoded as well.
                               Decodes input command after decoding and running input script file.
                               By default we only decode input file and consider command given in plaintext

プログラムはコマンドとスクリプトファイルのパスを入力として受け入れます。両方ともオプションで、何も指定されなければ疑似シェルが起動します。 コマンドとスクリプトはどちらも、1バイト XOR(Base64 エンコード出力)を使用してさらにエンコードでき、OpSec の向上に役立ちます。

以下にいくつかの使用例を示します:

  1. 疑似シェル - コマンドもスクリプトパスも指定されなかった場合に起動します:
PS D:\> Stracciatella.exe -v

  :: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
  Mariusz Banach / mgeeky, '19-22 <[email protected]>
  v0.7

[.] Powershell's version: 5.1
[.] Language Mode: FullLanguage
[+] No need to disable Constrained Language Mode. Already in FullLanguage.
[+] Script Block Logging Disabled.
[+] AMSI Disabled.
[+] ETW Disabled.

Stracciatella D:\> $PSVersionTable

Name                           Value
----                           -----
PSVersion                      5.1.18362.1
PSEdition                      Desktop
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0...}
BuildVersion                   10.0.18362.1
CLRVersion                     4.0.30319.42000
WSManStackVersion              3.0
PSRemotingProtocolVersion      2.3
SerializationVersion           1.1.0.1
  1. XOR エンコード(キー = 0x31)されたコマンドとスクリプトファイルのパス

まず、エンコードされたステートメントを準備するために、同梱の encoder.py スクリプトを使用できます。使用方法は次のとおりです:

PS D:\> python encoder.py -h
usage: encoder.py [options] <command|file>

positional arguments:
  command               Specifies either a command or script file's path for encoding

optional arguments:
  -h, --help            show this help message and exit
  -x KEY, --xor KEY     Specifies command/file XOR encode key (one byte)
  -o PATH, --output PATH
                        (optional) Output file. If not given - will echo output to stdout

PS D:\> python encoder.py -x 0x31 "Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode"
ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU

次に、encoder.py の出力を Stracciatella のエンコードされたコマンドとして入力します:

PS D:\> Stracciatella.exe -v -x 0x31 -c "ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU" .\Test2.ps1

  :: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
  Mariusz Banach / mgeeky, '19-22 <[email protected]>
  v0.7

[.] Will load script file: '.\Test2.ps1'
[+] AMSI Disabled.
[+] ETW Disabled.
[+] Script Block Logging Disabled.
[.] Language Mode: FullLanguage

PS> & '.\Test2.ps1'
PS> Write-Host "It works like a charm!" ; $ExecutionContext.SessionState.LanguageMode
[+] Yeeey, it really worked.
It works like a charm!
FullLanguage

ここで:

  • Command は次のコマンドから構成されています:Base64Encode(XorEncode("Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode", 0x31))
  • Test2.ps1 には以下が含まれています:"ZkNYRVQceV5CRRETahpsEWhUVFRIHRFYRRFDVFBdXUgRRl5DWlRVHxM=" (Base64(XorEncode("Write-Host \"[+] Yeeey, it really worked.\"", 0x31)))

Cobalt Strike サポート

Stracciatella には Aggressor スクリプトが付属しており、これをロードすると Beacon コンソールで stracciatella コマンドが使用可能になります。使用法は powerpick と非常に似ています(事前に stracciatella-import で PowerShell スクリプトをインポート)。入力パラメータはランダムなキーで XOR され、ランダムに名前付けられたパイプを介して Stracciatella の runspace に渡されます。

以下の Cobalt Strike コマンドが利用可能です:

ツールをダウンロード