LSTAR - Aggressor
Yi Ge Cha Jian Cong Shang Xian Dao Yu Kong Shi Xian Nei Wang Man You
Ben Zhao Jian Hua CS You Jian He Fang Bian Zi Ji Ji Cheng De Mu De ,Can Kao Da Liang Hou Shen Tou Cha Jian
Zhong Gou He Feng Fu Liao Zhu Ji Xiang Guan Ping Ju Huo Qu , Duo Ji Nei Wang Chuan Tou , Yin Bi Ji Hua Ren Wu , Mian Sha De Mimikatz He Ke Long Tian Jia Yong Hu Deng Gong Neng
Gong Neng Te Xing :
- Tong Guo Pei He CobaltStrike De TCP, SMB, Proxy Deng Bu Chu Wang Zhu Ji Shang Xian Fang Shi ,Chuan Tou Fu Za Wang Luo Huan Jing
- Zhen Dui RDP Xiang Guan , AddUser, LsassDump Deng Gong Neng Ti Gong Duo Chong Mian Sha Zhi Xing Fang Shi ,Ying Dui Leng Men Huan Jing
- Ji Cheng Duo Ge Shi Yong WinAPI Huo Assembly Nei Cun Jia Zai Fang Shi Yun Xing De Ying Zi Yong Hu , Yin Bi Ji Hua Ren Wu Deng Mian Sha Gong Neng
Zhu Yao Bao Han Yi Xia Gong Neng Mo Kuai :
Mei Ge Mo Kuai Jun Zai Yun Xing Qian Tian Jia Liao Lu Se Fen Ge Xian ,Fang Bian Ding Wei Hui Xian Xin Xi ,Ti Gao Xie Zuo Xiao Lu
CobaltStrike Zhu Ji Shang Xian Wei Xin Tong Zhi Cha Jian :
- Ru Guo Xiang Shi Yong Mian Fei Qie Zhi Chi Wei Xin Mo Ban Xiao Xi Tui Song De Fang Shi Ke Yi Yi Bu :https://github.com/lintstar/CS-PushPlus
- Ru Guo You Ding Yue ServerChan De Qi Ye Wei Xin Tui Song Tong Dao Ke Yi Yi Bu :https://github.com/lintstar/CS-ServerChan
Mian Ze Shen Ming
Ben Xiang Mu Jin Gua Yong Yu An Quan Yan Jiu Ji He Fa De Qi Ye An Quan Jian She Xing Wei Yi Qie Hou Guo Ji Ze Ren Jun You Shi Yong Zhe Ben Ren Cheng Dan
2022.1.15 Geng Xin
- Tian Jia Mian Sha De Ke Long Yong Hu , Tian Jia Yong Hu , Ji Hua Ren Wu Gong Neng
- Huo Qu Zui Xin Ban Xiang Ri Kui Shi Bie Ma He Yan Zheng Ma
- Ji Cheng Ladon 9.1.1 Ban Ben Duo Xie Yi Cun Huo Tan Ce Deng Gong Neng
- Jiang Gong Neng Jin Xing Fen Lei Jian Hua Cha Jian De Er Ji Cai Dan
InfoCollect
Jiang Chang Yong Ming Ling An Zhao Chang Jing Jin Xing Liao Fen Lei
SharpGetInfo
Ji Cheng Liao Ladon Gong Kai Zui Xin De 9.1.1 Ban Ben
AntiVirusCheck
Sha Ruan Xin Xi Ben Di Hui Xian Beacon Zhuang Tai Lan
Shi Xian Yuan Li :https://blog.csdn.net/weixin_42282189/article/details/121090055
IntrScan
Xin Zeng Liao Ladon De Duo Xie Yi Cun Huo Tan Ce (SMB, WMI, SNMP, HTTP, DNS, MAC, MSSQL)
Zai Yi Ding Cheng Du Shang Ke Yi Tan Ce Dao Fang Huo Qiang Hou De Nei Wang Zi Chan :Li Yong MACRao Guo Fang Huo Qiang Tan Ce Cun Huo Zhu Ji
Cun Huo IP Tan Ce
AuthPromote
BadPotato (BeichenDream)
Xiu Fu Liao Zhi Neng Zhi Xing whoami De bug,Ke Yi Tong Guo Can Shu Yun Xing Shang Xian System Quan Xian Liao
Badpotato (Ladon)
Xin Zeng Liao Ladon De Badpotato
SweetPatato (Ladon)
Zhu Yi :Ce Shi Fa Xian Shang Shu Liang Chong Quan Xian Ti Sheng Xing Wei Hui Bei Shu Zi Sha Ruan Lan Jie Cha Sha
AuthMaintain
SharpSchTask
[(Jin Shen Shi Yong )] Li Yong Windows API,Gong Ju Hua Chuang Jian Yin Cang De Ji Hua Ren Wu ,Tong Shi Rao Guo An Quan Ruan Jian De Zu Duan ,Da Dao Chi Jiu Kong Zhi .
Xiang Mu Di Zhi :https://github.com/0x727/SchTask_0x727
SharpShadowUser
[(Jin Shen Shi Yong )] Bypass Yuan Cheng Nei Cun Jia Zai Ke Long Yin Bi Ying Zi Yong Hu
Xiang Mu Di Zhi :https://github.com/An0nySec/ShadowUser
EasyPersistent
Xiu Fu PE Wen Jian Lu Jing Wen Ti Ke Yi Zheng Chang Shi Yong API Fang Shi Shan Chu Tian Jia De Yong Hu
PassCapture
Dui Gong Neng An Zhao Chang Jing Jin Xing Fen Lei
SunFlower
Huo Qu Zui Xin Ban Xiang Ri Kui Shi Bie Ma He Yan Zheng Ma
Zui Xin Ban Xiang Ri Kui De base_encry_pwd Can Shu Cong config.ini Geng Gai Dao Liao Zhu Ce Biao Zhong
RemoteLogin
Jian Hua Liao Er Ji Cai Dan
BypassCXK
SharpAddUser
Bypass AV Li Yong DirectoryService Ming Ming Kong Jian Jiang Yong Hu Tian Jia Dao Guan Li Yuan Yu Yuan Cheng Zhuo Mian Zu
Xiang Mu Di Zhi :https://github.com/An0nySec/UserAdd
CloneX
Zai Ming Ling Xing Xia Jin Xing Tian Jia Yong Hu , Ke Long Yong Hu Cao Zuo De An Quan Jian Ce Gong Ju
Xiang Mu Di Zhi :https://github.com/0x727/CloneX_0x727
2021.10.18 Geng Xin
- Dui Zheng Ti Gong Neng Mo Kuai Jin Xing Liao Zhong Xin Zheng He Yi Ji You Hua Wan Shan
- Heng Xiang Yi Dong Mo Kuai Xin Zeng ZeroLogon Lou Dong De BOF Shi Xian
- Zeng Jia Liao Yi Xie Assembly Fang Shi Yun Xing Wu Wen Jian Luo Di De Gong Neng
InfoCollect
SharpGetInfo(Yi Jian Shou Ji Zhu Ji Xin Xi )
Shi Yong Ladon Jin Xing Yi Jian Shou Ji Bao Gua Zhu Ji Ji Chu Xin Xi , Wang Luo Xin Xi , Yong Hu Xin Xi , Jin Cheng Xin Xi , Shi Fou Zai Yu Nei Deng Deng
SharpListRDP(RDPJi Lu Cha Xun )
Shou Ji RDP Nei Lian He Wai Lian Ji Lu ,Fang Bian Ding Wei Yun Wei Ji Yi Ji Heng Xiang Yi Dong
IntrScan
Cube(Mo Kuai Hua Tan Ce )
Xin Zeng Cube Lai Dai Ti Jiu Ban Ben De Bao Po ,Tong Shi Zhi Chi Nei Wang Xin Xi Shou Ji He MSSQL Ming Ling Zhi Xing ,Xiang Xi Yong Fa Can Kao Yun Xing Shuo Ming
Allin(Fu Zhu Ling Huo Sao Miao )
Xin Zeng Allin Lai Fu Zhu Ling Huo Sao Miao ,Yi Yuan Cheng Huo Qu Wang Qia IP Wei Li :
SharpOXID-Find (OXID Tan Ce )
Huo Zhe Bu Xiang Luo Di EXE Shi ,Ke Yi Shi Yong Assembly Fang Shi Jin Xing OXID De Kuai Su Tan Ce
IntrAgent
Stowaway (Chuan Tou Duo Ji Nei Wang )
Shang Chuan agent Hou Yun Xing
admin Duan Shou Dao Lian Jie Ji Ke Gou Jian Socks5 Sui Dao
Shan Chu agent
PassCapture
LsassDump(WinAPI)
Xiu Gai Liao LsassDump De Yun Xing Fang Shi Shan Chu LsassDump De Tong Shi Hui Yi Qi Shan Chu Zhuan Chu De C:\Windows\Temp\1.dmp
Mimidump(Yuan Cheng Du Qu .dmp)
Xin Zeng Pei He LsassDump(WinAPI)Gong Neng ,Yuan Cheng Du Qu Mu Biao Ji Qi Zhuan Chu De C:\Windows\Temp\1.tmp(.net 4.5)
RemoteLogin
Xin Zeng Liao Shi Yong Powershell Kai Qi Guan Bi Yi Ji Cha Xun RDP Xiang Guan Xin Xi De Fang Fa
PS Jiao Ben Lai Yuan Yu Reference Zhong De Hei Mo Gui Cha Jian RDP Mo Kuai
Cha Xun RDP Zhuang Tai
Kai Qi RDP Fu Wu
Huo Qu RDP Duan Kou
Cha Kan RDP Li Shi Deng Lu Ping Ju
Huo Qu RDP Li Shi Deng Lu Ping Ju
LateMovement
IPC Lian Jie
Piao Ju Chuan Di
ZeroLogonBOF
Xin Zeng Liao ZeroLogon Lou Dong De BOF Shi Xian
2021.09.05 Geng Xin
- Zhen Dui Bu Fen Gong Neng Jin Xing Liao x86 Jia Gou Ji Qi De Gua Pei
- Zeng Jia Liao Yi Xie Shi Yong WindowsAPI De Mian Sha Xiao Gong Ju
- Nei Wang Sao Miao Mo Kuai Zai Yun Xing Dui Ying Gong Neng Shi Tian Jia Liao Can Shu Ti Shi Shu Chu
IntrScan
Fscan
Xin Zeng Gen Ju Mu Biao Ji Qi Jia Gou Shang Chuan Dui Ying EXE Wen Jian
Tian Jia Liao Can Shu Ti Shi Shu Chu Fang Bian Zhen Dui Xing Zhi Ding Yun Xing Dan Ge Mo Kuai
Crack
Xin Zeng Crack Nei Wang Bao Po Gong Ju
TailorScan
Xin Zeng Gen Ju Mu Biao Ji Qi Jia Gou Shang Chuan Dui Ying EXE Wen Jian
PassCapture
LaZagne
Xiu Fu Liao V1.2 Ban Ben Zhong You Yu Wang Luo Wen Ti Dao Zhi De LaZagne Huan Wei Yun Xing Jie Shu
Jiu Bei Sha Diao Jin Cheng Qie Shan Chu Luo Di Wen Jian De BUG Gai Yong Shou Dong Fang Shi Yun Xing
LsassDump
Xin Zeng Liao Shi Yong WindowsAPI Jin Xing Nei Cun Zhuan Chu De LsassDump Qie Zhi Chi x86 He x64Ji Qi
Zhuan Chu Cheng Gong Hou Sheng Cheng De 1.dmp Hui Bao Cun Zai C:\Windows\Temp\ Mu Lu
Zhi Jie Ben Di Du Qu Ji Ke :
LateMovement
Xin Zeng Liao RDP Xiang Guan Gong Neng :
Shi Yong WindowsAPI Kai Qi RDP Fu Wu
2021.08.12 Geng Xin
InfoCollect
Xin Zeng CheckVM Jian Ce Mu Biao Shi Fou Wei Xu Ni Ji
AVSearch
You Yu Zhi Qian De Jiao Ben You Yi Ding Gai Lu Shi Bai :
Geng Xin Liao Xin De Jian Ce Sha Ruan Fang Shi
AuthPromote
Xiu Fu Liao Zhi Qian Ti Quan Mo Kuai De BUG
AuthMaintain
EasyPersistent:https://github.com/yanghaoi/CobaltStrike_CNA
Xin Zeng Yi Ge Yong Yu Windows Xi Tong Shang Quan Xian Wei Chi De Cobalt Strike CNA Jiao Ben
Shi Yong Fan She DLL Mo Kuai Tong Guo API Dui Xi Tong Fu Wu , Ji Hua Ren Wu Deng Chang Jian Quan Xian Wei Chi Fang Fa Jin Xing Ke Shi Hua Cao Zuo ,Fei Chang Hao Yong . (Zuo Zhe Yuan Hua )
Shuo Ming Wen Dang :https://github.com/yanghaoi/CobaltStrike_CNA/blob/main/EasyCNA/README.md
PassCapture
Mimikatz Xiang Guan
Lazagne
Shi Zhan Ce Shi Bi Jiao Hao Yong De Jian Suo Zhu Ji Mi Ma Gong Ju (Shang Chuan Yun Xing Hou Hui Zi Dong Shan Chu exe Wen Jian )
Liu Lan Qi Mi Ma
Navicat Xshell Deng Ben Ji Ruan Jian
FakeTheScreen
You Hua Liao Zhen Dui Windows10He Windows7Bu Tong De Diao Yu Mi Ma Qie Qu
You Yu Wei Zao Ye Mian Xiao Guo Yi Yan Nan Jin ,Zhi Jian Yi Zai Zhun Bei Yu Si Wang Po Shi Shi Yong :
Reference
EasyPersistent Windows Quan Xian Wei Chi
InfoCollect
Tian Jia Liao Netview He Powerview Gong Neng
AvSearch
Tong Guo Wmic Jin Xing Jin Cheng Cha Xun
IntrScan
Bao Han Ge Lei Nei Wang Da Bao Jian
Zi Ding Yi Zhi Ling Yun Xing
fscan Mo Ren Shang Chuan Zhi C:\\Windows\\Temp\\
Kong Zhi Tai Fan Hui
Shan Chu fscan Ji Jie Guo Wen Ben
IntrAgent
Bi Jiao Hao Yong De Nei Wang Chuan Tou Gong Ju Qie Jun Wu Pei Zhi Wen Jian Luo Di Jiang Di Bei Su Yuan Feng Xian
AuthMaintain
Zai Tao Wu De Ji Chu Shang Tian Jia Liao Bai Yin Piao Ju He Huang Jin Piao Ju
LateMovement
Bao Han Ji Yu 135Duan Kou De sharpwmi Deng Heng Xiang Yi Dong Tao Jian
TraceClean
Feng He Jiu Shi De Hen Ji Qing Li Dai Wan Shan
BypassCxk
cxk Xian Shi Mian Sha Ban adduser He mimikatz
HavingFun
Gao Zhan De Ri Zi Li Tu Yi Le