Skip to content
KitploitKITPLOIT
ИнструментыБлог
Log in
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Invoke-ATTACKAPI — Сценарий PowerShell для взаимодействия с фреймворком MITRE ATT&CK через его собственный API | Kitploit
Инструменты/GitHubGitHub/cyb3rward0g/invoke-attackapi
РазведкаСбор информацииУтилиты и фреймворкиРазведка угрозОбучение и ОбразованиеПодобранные РесурсыArchived
GitHubcyb3rward0g/invoke-attackapi

Invoke-ATTACKAPI

Сценарий PowerShell для взаимодействия с фреймворком MITRE ATT&CK через его собственный API

Репозиторий
36881237 лет назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

Invoke-ATTACKAPI [УСТАРЕВШЕЕ]

МЫ РЕКОМЕНДУЕМ ИСПОЛЬЗОВАТЬ: https://github.com/Cyb3rWard0g/ATTACK-Python-Client

Скрипт PowerShell для взаимодействия с MITRE ATT&CK Framework через его собственный API с целью сбора информации о техниках, тактиках, группах, программном обеспечении и ссылках, предоставленных командой MITRE ATT&CK @MITREattack. ЭТОТ СКРИПТ ВСЕ ЕЩЕ ИСПОЛЬЗУЕТ УСТАРЕВШИЙ MEEDIAWIKI API. ОН ЕЩЕ НЕ ОБНОВЛЕН ДЛЯ ИСПОЛЬЗОВАНИЯ ПУБЛИЧНЫХ TAXII SERVERS API

Цели

  • Обеспечить простой способ взаимодействия с MITRE ATT&CK Framework через его собственный API и PowerShell для сообщества.
  • Ускорить получение данных из ATT&CK при подготовке к охотничьей кампании.
  • Изучить динамические параметры PowerShell :)

Ресурсы

  • MITRE ATT&CK API
  • Semantic MediaWiki API
  • Get-ATTack
    • Walter Legowski @SadProcessor

Начало работы

Требования

  • PowerShell версии 3+

Установка / Импорт```

git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1

/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]

        Adversarial Tactics, Techniques & Common Knowledge API

[*] Author: Roberto Rodriguez @Cyb3rWard0g

[++] Pulling MITRE ATT&CK Data

## Примеры
### Этот запрос соответствует всем техникам```
Invoke-ATTACKAPI -Category -Technique

ID                  : {T1001}
Bypass              : {}
Contributor         : {}
Requires System     : {}
Data Source         : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description         : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
                      attempt to make the content more difficult to discover or decipher and to make the
                      communication less conspicuous and hide commands from being seen. This encompasses many
                      methods, such as adding junk data to protocol traffic, using steganography, commingling
                      legitimate traffic with C2 communications traffic, or using a non-standard data encoding
                      system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation          : {Network intrusion detection and prevention systems that use network signatures to
                      identify traffic for specific adversary malware can be used to mitigate activity at the
                      network level. Signatures are often for unique indicators within protocols and may be
                      based on the specific obfuscation technique used by a particular adversary or tool, and
                      will likely be different across various malware families and versions. Adversaries will
                      likely change tool C2 signatures over time or construct protocols in such a way as to
                      avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic              : Command and Control
Analytic Details    : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
                      data than it receives from a server). Processes utilizing the network that do not normally

                      have network communication or have never been seen before are suspicious. Analyze packet
                      contents to detect communications that do not follow the expected protocol behavior for
                      the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName       : {Data Obfuscation}
FullText            : Technique/T1001
Link Text           : {[[Technique/T1001|Data Obfuscation]]}
Reference           : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform            : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name                : {Data Obfuscation}
CAPEC ID            : {}
Requires Permission : {}
URL                 : https://attack.mitre.org/wiki/Technique/T1001
.............
..................
Скачать инструмент