Files
Angerona/documentation-payload/Cazalla/getting-started.md
T
marcos.luna 2fe9fa8254 wiki created
2025-11-06 12:23:49 +01:00

9.1 KiB

+++ title = "Getting started" chapter = false weight = 10 pre = "1. " +++

Getting Started with Cazalla

This guide will help you install, configure, and deploy your first Cazalla agent.

📋 Prerequisites

  • Mythic Server (v3.x or later) installed and running
  • Docker installed and running (for building the agent)
  • Access to a Windows target for testing
  • Basic understanding of Mythic C2 Framework

🚀 Installation

Step 1: Install Cazalla on Mythic

Option A: Install from GitHub (if available)

cd ~/Mythic
./mythic-cli install github https://github.com/<your-org>/Cazalla

Option B: Install from Local Directory

cd ~/Mythic
./mythic-cli install folder /path/to/Cazalla

After installation, Mythic will build the Cazalla container automatically.

Step 2: Verify Installation

Check that Cazalla is installed:

cd ~/Mythic
./mythic-cli list

You should see cazalla in the list of installed payload types.

Step 3: Build Your First Payload

  1. Navigate to Mythic UI

    • Open your browser and go to your Mythic server URL (typically https://localhost:17443)
  2. Create a New Payload

    • Click on Payloads in the left sidebar
    • Click Create Payload button
    • Select Cazalla as the payload type
  3. Configure Build Parameters

    • C2 Profile: Select your configured C2 profile (HTTP, HTTPS, etc.)
    • Callback Host: Your Mythic server's IP address or domain
    • Callback Port: Port for agent communication (default: 443)
    • Sleep: Initial beacon interval in seconds (default: 10)
    • Jitter: Random delay percentage (0-100, recommended: 10-30)
    • User Agent: HTTP User-Agent string for HTTP(S) profiles
  4. Optional: Enable Encryption

    • In the AESPSK parameter section:
      • Set crypto_type to aes256_hmac
      • Mythic will automatically generate an encryption key
    • This provides end-to-end encryption beyond HTTPS
  5. Build the Payload

    • Click the Build button
    • Wait for the build to complete (this may take a few minutes)
    • Once complete, download the generated .exe file

🎯 Deploying the Agent

Step 1: Transfer to Target

Transfer the compiled .exe file to your Windows target using any method:

  • USB drive
  • Network share
  • Email attachment
  • Web download
  • Etc.

Step 2: Execute on Target

On the Windows target, execute the agent:

C:\path\to\cazalla.exe

The agent will start beaconing to your Mythic server immediately.

Step 3: Verify Connection

  1. Check Mythic UI

    • Navigate to Callbacks in the left sidebar
    • You should see a new callback appear with:
      • Hostname: The target machine's hostname
      • User: The username running the agent
      • PID: Process ID of the agent
      • Status: Active (green indicator)
  2. Check Agent Output (if running interactively)

    • The agent will output connection status
    • Look for successful connection messages

First Commands

Once your agent is connected, try these basic commands:

1. Check Current Directory

pwd

This will show the current working directory of the agent.

2. List Files

ls

Or list a specific directory:

ls C:\Users

3. Get System Information

ps

This lists all running processes and updates the Process Browser.

whoami

This shows the current security context (username and domain).

4. Explore the File System

cd C:\Users
ls
cat desktop.ini

🔧 Configuration Options

Build Parameters

When building a payload, you can configure:

Parameter Description Default Notes
Callback Host Mythic server address Required IP or domain
Callback Port C2 port 443 Must match C2 profile
Sleep Beacon interval (seconds) 10 Lower = more responsive, higher = more stealthy
Jitter Random delay (%) 0 0-100, recommended 10-30
User Agent HTTP User-Agent Varies For HTTP(S) profiles
AESPSK Encryption settings Disabled Optional end-to-end encryption

Dynamic Configuration

After deployment, you can change certain settings:

Adjust Sleep Interval

sleep {"seconds":30,"jitter":10}

This changes the beacon interval to 30 seconds with 10% jitter.

View Current Settings

The agent tracks and reports:

  • Current working directory (via pwd or in UI context tabs)
  • Active token impersonation (via whoami or in UI context tabs)
  • Sleep interval (shown in callback details)

🎨 Using the Mythic UI

Process Browser

  1. Access Process Browser

    • Click Process Browser in the left sidebar
    • Or use the process icon in the callback view
  2. View Processes

    • All processes from all callbacks are displayed
    • Use ps command to refresh the process list
    • Click on processes to view details
  3. Interact with Processes

    • Kill: Right-click → Kill Process
    • Steal Token: Right-click → Steal Token
    • List Tokens: Right-click → List Tokens

File Browser

  1. Access File Browser

    • Click File Browser in the left sidebar
    • Or use the file icon in the callback view
  2. Navigate Files

    • Browse directories visually
    • Click on files to download
    • Right-click to upload files
  3. File Operations

    • Download: Click file → Download
    • Upload: Right-click directory → Upload
    • Delete: Right-click file → Delete (uses rm command)

Context Tracking

The Mythic UI automatically displays:

  • Current Directory: Shows in callback context tabs
  • Impersonation Context: Shows active token impersonation
  • Process Context: Shows active process information

🔒 Security Considerations

OPSEC Checking

Cazalla includes built-in OPSEC checking for high-risk operations:

  • Pre-execution blocking: Commands like steal_token, shell, keylog_start require approval
  • Post-execution warnings: Artifacts are automatically tracked
  • Bypass roles: Configured operators can bypass warnings

When executing a risky command:

  1. You'll see an OPSEC warning popup
  2. Review the warning message
  3. Approve or cancel the operation
  4. Another operator may need to approve (if configured)

See OPSEC Guide for detailed information.

Best Practices

  1. Start with High Sleep Values

    • Use 30-60 seconds initially
    • Reduce only when needed for interactive operations
  2. Use Jitter

    • Add 10-30% jitter to avoid predictable patterns
    • Helps evade timing-based detection
  3. Monitor Artifacts

    • Check the Artifacts tab regularly
    • Review what the agent is creating/accessing
  4. Use Built-in Commands

    • Prefer Cazalla commands (ps, ls, cat) over shell when possible
    • Built-in commands have better OPSEC
  5. Review OPSEC Warnings

    • Always read OPSEC popup messages
    • Understand risks before approving

🐛 Troubleshooting

Agent Not Connecting

  1. Check Network Connectivity

    • Verify target can reach Mythic server
    • Test: ping <mythic_server_ip>
    • Test: curl https://<mythic_server>:443
  2. Check C2 Profile

    • Verify C2 profile is active
    • Check that port matches callback configuration
    • Review C2 profile logs
  3. Check Agent Execution

    • Verify agent is running: tasklist | findstr cazalla
    • Check for error messages in console
    • Review Windows Event Logs
  4. Check Mythic Logs

    sudo docker logs mythic_server
    sudo docker logs cazalla_translator
    

Commands Not Working

  1. Verify Agent is Active

    • Check callback status (should be green)
    • Verify last check-in time
  2. Check Command Syntax

    • Review command documentation in Commands Reference
    • Verify parameter format (JSON vs string)
  3. Review Task Output

    • Check task output for error messages
    • Look for specific error codes
  4. Check Permissions

    • Some commands require specific permissions
    • Use whoami to verify current context

Build Issues

  1. Check Docker

    sudo docker ps
    sudo docker logs cazalla_translator
    
  2. Rebuild Container

    cd ~/Mythic
    sudo ./mythic-cli build cazalla
    
  3. Check Build Parameters

    • Verify all required parameters are set
    • Check parameter format (JSON vs string)

For more troubleshooting help, see Troubleshooting Guide.

📚 Next Steps

Now that you have a working agent:

  1. Explore Commands: See Commands Reference for all available commands
  2. Learn Features: Read Features Overview for advanced capabilities
  3. Understand OPSEC: Review OPSEC Guide for security best practices
  4. Try Examples: Check Usage Examples for practical scenarios

🔗 Additional Resources


Ready to use Cazalla? Start with the Commands Reference to learn all available commands!