Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Invoke-ATTACKAPI — MITRE ATT&CK Framework의 자체 API를 통해 상호작용하는 PowerShell 스크립트. | Kitploit
도구/GitHubGitHub/cyb3rward0g/invoke-attackapi
ReconnaissanceInformation GatheringUtilities & FrameworksThreat IntelligenceLearning & EducationCurated ResourcesArchived
GitHubcyb3rward0g/invoke-attackapi

Invoke-ATTACKAPI

MITRE ATT&CK Framework의 자체 API를 통해 상호작용하는 PowerShell 스크립트.

저장소 보기
36881237년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Invoke-ATTACKAPI [DEPRECATED]

권장 사용: https://github.com/Cyb3rWard0g/ATTACK-Python-Client

MITRE ATT&CK Framework의 API를 통해 정보(기술, 전술, 그룹, 소프트웨어 및 참조 자료)를 수집하기 위해 MITRE ATT&CK 팀 @MITREattack이 제공하는 API와 상호작용하는 PowerShell 스크립트입니다. 이 스크립트는 여전히 사용 중단된 MediaWiki API를 사용하고 있습니다. 아직 공개 TAXII 서버 API로 업데이트되지 않았습니다.

목표

  • 커뮤니티를 위해 MITRE ATT&CK Framework의 API와 PowerShell을 통해 쉽게 상호작용할 수 있는 방법을 제공합니다.
  • 헌팅 캠페인 준비 시 ATT&CK 데이터 획득을 신속하게 합니다.
  • PowerShell 동적 매개변수 배우기 :)

리소스

  • MITRE ATT&CK API
  • Semantic MediaWiki API
  • Get-ATTack
    • Walter Legowski @SadProcessor

시작하기

요구 사항

  • PowerShell 버전 3+

설치 / 가져오기```

git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1

/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]

        Adversarial Tactics, Techniques & Common Knowledge API

[*] Author: Roberto Rodriguez @Cyb3rWard0g

[++] Pulling MITRE ATT&CK Data

## 예제
### 이 쿼리는 모든 기술과 일치합니다```
Invoke-ATTACKAPI -Category -Technique

ID                  : {T1001}
Bypass              : {}
Contributor         : {}
Requires System     : {}
Data Source         : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description         : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
                      attempt to make the content more difficult to discover or decipher and to make the
                      communication less conspicuous and hide commands from being seen. This encompasses many
                      methods, such as adding junk data to protocol traffic, using steganography, commingling
                      legitimate traffic with C2 communications traffic, or using a non-standard data encoding
                      system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation          : {Network intrusion detection and prevention systems that use network signatures to
                      identify traffic for specific adversary malware can be used to mitigate activity at the
                      network level. Signatures are often for unique indicators within protocols and may be
                      based on the specific obfuscation technique used by a particular adversary or tool, and
                      will likely be different across various malware families and versions. Adversaries will
                      likely change tool C2 signatures over time or construct protocols in such a way as to
                      avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic              : Command and Control
Analytic Details    : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
                      data than it receives from a server). Processes utilizing the network that do not normally

                      have network communication or have never been seen before are suspicious. Analyze packet
                      contents to detect communications that do not follow the expected protocol behavior for
                      the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName       : {Data Obfuscation}
FullText            : Technique/T1001
Link Text           : {[[Technique/T1001|Data Obfuscation]]}
Reference           : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform            : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name                : {Data Obfuscation}
CAPEC ID            : {}
Requires Permission : {}
URL                 : https://attack.mitre.org/wiki/Technique/T1001
.............
..................
도구 다운로드