14 KiB
+++ title = "OPSEC" chapter = false weight = 10 pre = "3. " +++
OPSEC Guide for Cazalla
This guide covers operational security considerations when using Cazalla agent, including detection risks, best practices, and the built-in OPSEC checking system.
📋 Table of Contents
- Overview
- OPSEC Checking System
- Command Risk Assessment
- Detection Avoidance
- Best Practices
- OPSEC by Command
Overview
Operational Security (OPSEC) is critical when conducting red team operations. Cazalla includes built-in OPSEC checking to help operators make informed decisions and avoid accidental security violations.
Key Principles
- Minimize Detection: Avoid commands and behaviors that trigger security alerts
- Use Built-in Commands: Prefer Cazalla's native commands over
shellwhen possible - Monitor Artifacts: Review artifacts created by commands
- Review OPSEC Warnings: Always read and understand OPSEC popup messages
- Operational Timing: Adjust sleep intervals and jitter based on operational needs
OPSEC Checking System
Cazalla implements a two-stage OPSEC checking system:
OPSEC Pre-Check (opsec_pre)
Runs before task creation and can block execution:
- Blocking: Can set
OpsecPreBlocked=Trueto prevent task execution - Warning: Can provide detailed warnings without blocking
- Bypass Roles: Defines who can approve blocked tasks:
operator: Any operator can bypassother_operator: Requires approval from a different operatorlead: Only operation lead can approve
OPSEC Post-Check (opsec_post)
Runs after task creation but before agent execution:
- Artifact Review: Warns about artifacts that will be created
- Final Warning: Last chance to cancel before agent picks up task
- Context-Aware: Reviews artifacts generated by
create_tasking
Command Risk Assessment
🔴 CRITICAL OPSEC RISK
These commands are extremely detectable and should be used with extreme caution:
| Command | Risk Level | Detection Likelihood | Alternatives |
|---|---|---|---|
keylog_start |
CRITICAL | Minutes to hours | Credential theft, browser credential extraction, clipboard monitoring |
steal_token (LSASS) |
CRITICAL | High-priority alerts | make_token for domain credentials |
kill (critical PIDs) |
CRITICAL | System instability | Blocked for PIDs 0, 4, 8 |
🟠 HIGH OPSEC RISK
These commands are highly detectable and require careful consideration:
| Command | Risk Level | Detection Likelihood | Alternatives |
|---|---|---|---|
shell |
HIGH | High (cmd.exe spawn) | Use built-in Cazalla commands when possible |
steal_token |
HIGH | High (EDR/XDR monitoring) | make_token when credentials available |
rm (system files) |
HIGH | Blocked for safety | Never delete system files |
screenshot |
HIGH | Screen capture detection | Use sparingly, consider timing |
🟡 MEDIUM OPSEC RISK
These commands have moderate detection risk:
| Command | Risk Level | Detection Likelihood | Notes |
|---|---|---|---|
download |
MEDIUM | File access logging | Large files may trigger DLP |
upload |
MEDIUM | File write detection | Suspicious extensions monitored |
socks |
MEDIUM | Network traffic analysis | High bandwidth usage |
rpfwd |
MEDIUM | Network connection monitoring | Persistent connections |
make_token |
MEDIUM | Authentication logging | Less detectable than steal_token |
🟢 LOW OPSEC RISK
These commands have low detection risk:
| Command | Risk Level | Detection Likelihood | Notes |
|---|---|---|---|
ls, cd, pwd |
LOW | Minimal | Read-only operations |
cat |
LOW | File read logging | May detect credential extraction |
ps |
LOW | Process enumeration | May be logged but low priority |
whoami |
LOW | Minimal | No system modifications |
list_tokens |
LOW | Token enumeration | Lower risk than token theft |
Detection Avoidance
EDR/XDR Detection
Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) solutions monitor:
- Process Creation:
shellcommand spawnscmd.exe(highly monitored) - Token Manipulation:
steal_tokenandmake_tokengenerate authentication events - Memory Access: Accessing LSASS memory triggers high-priority alerts
- API Hooking: Keyloggers and screen capture use monitored APIs
- File Operations: File writes to sensitive locations trigger alerts
Mitigation Strategies:
- Use built-in Cazalla commands instead of
shellwhen possible - Prefer
make_tokenoversteal_tokenwhen credentials are available - Avoid accessing LSASS or other critical system processes
- Use keylogging only when absolutely necessary
- Limit file operations to user directories when possible
Network Monitoring
Network Intrusion Detection Systems (NIDS) and firewalls monitor:
- SOCKS Proxies: Continuous network traffic patterns
- Reverse Port Forwarding: Persistent connections and port listeners
- Large File Transfers: High bandwidth usage
- Suspicious Ports: Non-standard ports may be flagged
Mitigation Strategies:
- Use non-standard ports for SOCKS and RPFWD
- Limit bandwidth usage during file transfers
- Use appropriate sleep intervals to reduce network activity
- Consider operational timing (e.g., during business hours)
Behavioral Analysis
Behavioral analysis engines monitor:
- Timing Patterns: Predictable beacon intervals
- Command Sequences: Common attack patterns
- Anomalous Activity: Unusual system behavior
Mitigation Strategies:
- Use jitter (10-30%) to randomize sleep intervals
- Vary command execution patterns
- Avoid executing commands in rapid succession
- Use appropriate sleep intervals (30-60 seconds for stealth)
Data Loss Prevention (DLP)
DLP systems monitor:
- File Access: Reading sensitive files (SAM, configs, etc.)
- File Transfers: Large downloads/uploads
- Screen Capture: Screenshot detection
- Credential Extraction: Detecting credential theft patterns
Mitigation Strategies:
- Limit access to sensitive files
- Use chunked transfers for large files
- Use screenshots sparingly
- Consider operational timing for sensitive operations
Best Practices
1. Use Built-in Commands
❌ Avoid:
shell whoami
shell tasklist
shell dir
✅ Prefer:
whoami
ps
ls
Built-in Cazalla commands:
- Don't spawn
cmd.exe(highly monitored) - Have better OPSEC characteristics
- Provide structured output
- Integrate with Mythic UI features
2. Adjust Sleep Intervals
Initial Deployment:
- Use 30-60 seconds with 10-30% jitter
- Provides good balance between responsiveness and stealth
Interactive Operations:
- Reduce to 5-10 seconds with 10-20% jitter
- Only when needed for responsive interaction
Stealth Mode:
- Increase to 60-120 seconds with 20-40% jitter
- Minimizes network activity and detection risk
3. Review OPSEC Warnings
Always:
- Read OPSEC popup messages carefully
- Understand the risks before approving
- Consider alternatives when suggested
- Consult with team lead for critical operations
Never:
- Ignore OPSEC warnings
- Bypass warnings without understanding risks
- Execute critical commands without approval
4. Monitor Artifacts
Regularly:
- Review artifacts created by commands
- Check the Artifacts page in Mythic UI
- Identify patterns that might trigger alerts
- Clean up artifacts when possible
5. Limit High-Risk Operations
Critical Operations:
keylog_start: Use only when absolutely necessarysteal_token(LSASS): Prefermake_tokenwhen possibleshell: Use only when no alternative existsscreenshot: Use sparingly and consider timing
Timing Considerations:
- Execute high-risk operations during low-activity periods
- Avoid simultaneous high-risk operations
- Space out operations to reduce detection correlation
6. Use Token Operations Wisely
Best Practices:
- Prefer
make_tokenoversteal_tokenwhen credentials are available - Use
rev2selfafter completing privileged operations - Limit token impersonation duration
- Verify token context with
whoamibefore operations
7. File Operations
Best Practices:
- Use user directories for staging files
- Avoid writing to System32, Windows, Program Files
- Use relative paths when possible
- Clean up temporary files after operations
OPSEC by Command
File System Commands
ls, cd, pwd
- Risk: LOW
- Detection: Minimal, read-only operations
- Best Practice: Use freely for navigation
cat
- Risk: LOW (operation), MEDIUM (credential detection)
- Detection: File read logging, credential extraction detection
- Best Practice: Use for reading files, be aware of credential detection
download
- Risk: MEDIUM
- Detection: File access logging, DLP for large files
- Best Practice: Use chunked transfers, limit file sizes, avoid sensitive files
upload
- Risk: MEDIUM
- Detection: File write detection, suspicious extensions monitored
- Best Practice: Avoid sensitive locations, use non-suspicious extensions when possible
cp, mkdir, rm
- Risk: LOW (user directories), HIGH (system files)
- Detection: File write/delete logging, blocked for system files
- Best Practice: Use in user directories, never delete system files
Process Management Commands
ps
- Risk: LOW
- Detection: Process enumeration may be logged
- Best Practice: Use freely for reconnaissance
kill
- Risk: HIGH (critical PIDs), MEDIUM (user processes)
- Detection: Process termination logging, blocked for critical PIDs
- Best Practice: Never kill critical system processes
Token Operations
list_tokens
- Risk: LOW
- Detection: Token enumeration may be logged
- Best Practice: Use for reconnaissance before token theft
steal_token
- Risk: CRITICAL (LSASS), HIGH (other processes)
- Detection: High-priority alerts, especially for LSASS
- Best Practice: Always requires approval, prefer
make_tokenwhen possible
make_token
- Risk: MEDIUM
- Detection: Authentication event logging
- Best Practice: Less detectable than
steal_token, use when credentials available
rev2self
- Risk: LOW
- Detection: Minimal
- Best Practice: Use after completing privileged operations
Network Tunneling
socks
- Risk: MEDIUM
- Detection: Continuous network traffic, flow analysis
- Best Practice: Use non-standard ports, limit bandwidth, be aware of high traffic
rpfwd
- Risk: MEDIUM
- Detection: Persistent connections, port listeners
- Best Practice: Avoid privileged ports, consider operational timing
System Operations
shell
- Risk: HIGH
- Detection: cmd.exe spawn is highly monitored
- Best Practice: Use only when no alternative exists, always requires approval
browser_info
- Risk: LOW
- Detection: Registry reads may be logged if auditing enabled
- Best Practice: Read-only operation, safe for information gathering
browser_dump
- Risk: HIGH
- Detection: Browser credential access is heavily monitored by EDR/XDR
- Best Practice: Use only when necessary, always requires approval, consider timing
screenshot
- Risk: HIGH
- Detection: Screen capture detection, behavioral analysis
- Best Practice: Use sparingly, consider timing, large screenshots may trigger alerts
keylog_start
- Risk: CRITICAL
- Detection: Extremely detectable, likely within minutes or hours
- Best Practice: Use only when absolutely necessary, always requires lead approval
Control Commands
sleep
- Risk: LOW
- Detection: Timing analysis for predictable patterns
- Best Practice: Use jitter (10-30%) to randomize intervals
exit
- Risk: LOW
- Detection: Minimal
- Best Practice: Use when agent removal is required
OPSEC Warning Examples
Blocking Message (shell whoami)
🚨 OPSEC BLOCKED - Command Has Safer Alternative
This command contains operations that have safer built-in alternatives in Cazalla:
🚨 whoami: Use Cazalla's 'whoami' command instead (no cmd.exe spawn)
⚠️ cmd.exe spawn: This command would spawn cmd.exe (highly detectable)
💡 SAFER ALTERNATIVES:
→ Use: 'whoami' (Cazalla built-in, no cmd.exe)
⚠️ TO PROCEED: You need approval from another operator.
Blocking Message (steal_token)
🚨 HIGH OPSEC RISK - Token Theft Operation
Token theft operations are EXTREMELY monitored by:
• EDR/XDR solutions (high-priority alerts)
• Security Information and Event Management (SIEM)
• Behavioral analysis engines
• Process monitoring tools
⚠️ WARNING: Stealing tokens from critical processes (LSASS, System) will trigger
immediate high-priority security alerts.
💡 ALTERNATIVES:
→ Use 'make_token' if you have domain credentials (less detectable)
→ Use 'list_tokens' first to identify high-value tokens
→ Consider alternative privilege escalation methods
⚠️ TO PROCEED: You need approval from another operator.
Blocking Message (keylog_start)
🚨 CRITICAL OPSEC RISK - Keylogger Operation
Keyloggers are EXTREMELY detectable by:
• EDR/XDR solutions
• Anti-malware engines
• Behavioral analysis
• API hooking detection
⚠️ WARNING: Detection is likely within MINUTES or HOURS.
💡 ALTERNATIVES:
→ Credential theft (LSASS dumping, token theft)
→ Browser credential extraction
→ Clipboard monitoring
→ Network credential interception
⚠️ TO PROCEED: You need approval from a lead operator.
Related Documentation
- Commands Reference - Detailed command documentation with OPSEC notes
- Features Overview - OPSEC checking system details
- Getting Started - Security best practices
- Usage Examples - OPSEC-aware examples
Remember: OPSEC is a shared responsibility. Always review warnings, understand risks, and consult with your team before executing high-risk operations.
Last Updated: 2024