513 lines
19 KiB
Markdown
513 lines
19 KiB
Markdown
+++
|
|
title = "Features"
|
|
chapter = false
|
|
weight = 10
|
|
pre = "2. "
|
|
+++
|
|
|
|
# Cazalla Features Overview
|
|
|
|
This document provides detailed explanations of Cazalla's key features and capabilities.
|
|
|
|
## 📋 Table of Contents
|
|
|
|
- [Process Browser Integration](#process-browser-integration)
|
|
- [File Browser Integration](#file-browser-integration)
|
|
- [Context Tracking](#context-tracking)
|
|
- [Artifacts Support](#artifacts-support)
|
|
- [Credentials Support](#credentials-support)
|
|
- [SOCKS Proxy Support](#socks-proxy-support)
|
|
- [Reverse Port Forwarding (RPFWD) Support](#reverse-port-forwarding-rpfwd-support)
|
|
- [Token Support](#token-support)
|
|
- [Keylogging Support](#keylogging-support)
|
|
- [File Downloads Support](#file-downloads-support)
|
|
- [File Uploads Support](#file-uploads-support)
|
|
- [System Information Gathering](#system-information-gathering)
|
|
- [OPSEC Checking](#opsec-checking)
|
|
|
|
---
|
|
|
|
## Process Browser Integration
|
|
|
|
Cazalla fully integrates with Mythic's Process Browser feature, providing unified process management across multiple callbacks on the same host.
|
|
|
|
### Features
|
|
|
|
- **Unified Process Lists**: All process listings from different callbacks on the same host are aggregated
|
|
- **Process Hierarchy**: View process parent-child relationships when parent process IDs are available
|
|
- **Rich Process Data**: Includes process name, PID, PPID, architecture, user account, and session ID
|
|
- **Automatic Synchronization**: Process lists are automatically synchronized with Mythic's Process Browser UI
|
|
- **Process Actions**: Kill processes, steal tokens, and list tokens directly from the Process Browser UI
|
|
- **Cache Management**: Process lists automatically clear stale entries using `update_deleted=True` flag
|
|
|
|
### How It Works
|
|
|
|
1. **Execute `ps` command**: The agent enumerates all running processes
|
|
2. **Translator Conversion**: The translator automatically converts the process list to Mythic's Process Browser JSON format
|
|
3. **UI Update**: Processes appear in the Process Browser UI with all details
|
|
4. **Interactive Actions**: You can perform actions directly from the UI:
|
|
- **Kill**: Terminate a process (uses `kill` command)
|
|
- **Steal Token**: Steal token from a process (uses `steal_token` command)
|
|
- **List Tokens**: List tokens from a process (uses `list_tokens` command)
|
|
|
|
### Accessing Process Browser
|
|
|
|
1. Navigate to a callback in the Mythic UI
|
|
2. Click the **PROCESSES** tab (next to the **CALLBACK** tab)
|
|
3. View all processes from all callbacks on that host
|
|
4. Use UI buttons for process actions
|
|
|
|
### Implementation Details
|
|
|
|
- **`ps` Command**: Implements `process_browser:list` supported UI feature
|
|
- **`kill` Command**: Implements `process_browser:kill` supported UI feature
|
|
- **Process Data Format**: Includes PID, process name, PPID, architecture, user, session ID
|
|
- **Automatic Cache Clearing**: All processes marked with `update_deleted=True` to clear stale entries
|
|
|
|
---
|
|
|
|
## File Browser Integration
|
|
|
|
Cazalla seamlessly integrates with Mythic's File Browser, allowing visual file system navigation and operations.
|
|
|
|
### Features
|
|
|
|
- **Visual Navigation**: Browse directories and files visually through the Mythic UI
|
|
- **Drag-and-Drop Downloads**: Download files with a simple click
|
|
- **Upload Integration**: Upload files directly from the File Browser interface
|
|
- **Automatic Path Resolution**: Relative paths are automatically resolved using the current working directory
|
|
- **Real-time Updates**: File listings update automatically as you navigate
|
|
|
|
### How It Works
|
|
|
|
1. **Execute `ls` command**: The agent lists directory contents
|
|
2. **Translator Conversion**: The translator converts the listing to Mythic's File Browser format
|
|
3. **UI Display**: Files and directories appear in the File Browser UI
|
|
4. **Interactive Operations**: Perform file operations directly from the UI:
|
|
- **Download**: Click file → Download
|
|
- **Upload**: Right-click directory → Upload
|
|
- **Delete**: Right-click file → Delete (uses `rm` command)
|
|
|
|
### Accessing File Browser
|
|
|
|
1. Navigate to a callback in the Mythic UI
|
|
2. Click the **Files** icon in the top navigation
|
|
3. Browse directories and files visually
|
|
4. Perform operations directly from the UI
|
|
|
|
### Path Handling
|
|
|
|
- **Relative Paths**: Automatically resolved using the current working directory
|
|
- **Absolute Paths**: Full paths work as expected
|
|
- **Path Normalization**: Double backslashes and invalid characters are automatically handled
|
|
|
|
---
|
|
|
|
## Context Tracking
|
|
|
|
Cazalla automatically tracks and displays dynamic callback context information in the Mythic UI.
|
|
|
|
### Features
|
|
|
|
- **Current Working Directory**: Displays the agent's current directory
|
|
- **Impersonation Context**: Shows the currently impersonated user (if any)
|
|
- **Real-time Updates**: Context tabs update automatically as the agent's state changes
|
|
- **Visual Display**: Context information appears as tabs above the tasking area
|
|
|
|
### Supported Context Fields
|
|
|
|
#### Current Working Directory (`cwd`)
|
|
|
|
- **Updated by**: `cd` command
|
|
- **Initial value**: Automatically set during check-in
|
|
- **Display**: Shows the current directory path (e.g., `C:\Users\localuser\Downloads`)
|
|
|
|
#### Impersonation Context (`impersonation_context`)
|
|
|
|
- **Updated by**: `steal_token`, `make_token`, `rev2self`
|
|
- **Initial value**: Automatically set during check-in with the process's current user
|
|
- **Display**: Shows the currently impersonated user (e.g., `NT AUTHORITY\SYSTEM`)
|
|
|
|
### Commands That Update Context
|
|
|
|
- **`cd`**: Updates `cwd` when directory changes
|
|
- **`steal_token`**: Updates `impersonation_context` when token is stolen
|
|
- **`make_token`**: Updates `impersonation_context` when token is created
|
|
- **`rev2self`**: Clears `impersonation_context` when reverting to original token
|
|
|
|
---
|
|
|
|
## Artifacts Support
|
|
|
|
Cazalla automatically reports artifacts created during command execution, allowing Mythic to track forensic evidence.
|
|
|
|
### Features
|
|
|
|
- **Automatic Detection**: Artifacts are automatically reported for relevant commands
|
|
- **Multiple Artifact Types**: Supports Process Create, File Write, File Delete, File Read, Process Termination, API Call, Network Connection
|
|
- **Artifact Management**: Artifacts appear in Mythic's Artifacts page
|
|
- **Extensible**: Easy to add artifact reporting for new commands
|
|
|
|
### Supported Artifact Types
|
|
|
|
| Artifact Type | Commands | Description |
|
|
|--------------|----------|-------------|
|
|
| **Process Create** | `shell` | Command execution via cmd.exe |
|
|
| **File Write** | `cp`, `mkdir`, `upload` | File creation or modification |
|
|
| **File Delete** | `rm` | File or directory deletion |
|
|
| **File Read** | `download` | File download operations |
|
|
| **Process Termination** | `kill` | Process termination with PID |
|
|
| **API Call** | `screenshot`, `keylog_start` | API usage for screen capture/keylogging |
|
|
| **Network Connection** | `rpfwd start` | Reverse port forward listener |
|
|
|
|
### Viewing Artifacts
|
|
|
|
1. Navigate to your callback in the Mythic UI
|
|
2. Click the **Artifacts** icon (fingerprint) in the top navigation
|
|
3. View all artifacts created by commands
|
|
4. Filter by artifact type, needs cleanup, resolved status
|
|
|
|
---
|
|
|
|
## Credentials Support
|
|
|
|
Cazalla supports reporting discovered credentials to Mythic's credential store.
|
|
|
|
### Features
|
|
|
|
- **Automatic Detection**: Commands can report discovered credentials
|
|
- **Multiple Credential Types**: Supports `plaintext`, `hash`, `certificate`, `key`, `ticket`, `cookie`
|
|
- **Credential Management**: Credentials appear in Mythic's Credentials page
|
|
- **Associated with Tasks**: Credentials are linked to the task and callback that discovered them
|
|
|
|
### Credential Detection in `cat` Command
|
|
|
|
The `cat` command automatically detects and reports credentials from file contents:
|
|
|
|
- **Format `username:password`**: `marcos:password123`
|
|
- **Format `domain\username:password`**: `test\marcos:password`
|
|
- **Format `username@domain:password`**: `marcos@tes.com:password`
|
|
- **Passwords in config files**: `password=value` or `password:value`
|
|
- **HTTP URLs with credentials**: `http://user:pass@host`
|
|
- **NTLM hashes**: Format `aad3b435b51404ee:hash` or `:32hexchars`
|
|
|
|
### Viewing Credentials
|
|
|
|
1. Navigate to your callback in the Mythic UI
|
|
2. Click the **CREDENTIALS** icon (key) in the top navigation
|
|
3. View all credentials discovered by commands
|
|
4. Filter by credential type, realm, account
|
|
|
|
---
|
|
|
|
## SOCKS Proxy Support
|
|
|
|
Cazalla includes full SOCKS5 proxy support, allowing you to route traffic through the agent to access internal network resources.
|
|
|
|
### Features
|
|
|
|
- **SOCKS5 Protocol**: Full SOCKS5 proxy server support
|
|
- **Multiple Connections**: Supports multiple simultaneous SOCKS connections
|
|
- **Dynamic Sleep**: Automatically reduces sleep interval when SOCKS is active
|
|
- **Connection Tracking**: Each connection has a unique `server_id` for tracking
|
|
|
|
### How It Works
|
|
|
|
1. **Mythic opens a SOCKS port** on the server (default: `7002`)
|
|
2. **Client connects** to Mythic's SOCKS port (e.g., via `proxychains`)
|
|
3. **Mythic forwards** SOCKS traffic to the agent with a unique `server_id` per connection
|
|
4. **Agent establishes** the actual connection to the target host
|
|
5. **Bidirectional relay** between client ↔ Mythic ↔ Agent ↔ Target
|
|
|
|
### Using the Proxy
|
|
|
|
```bash
|
|
# Start SOCKS proxy
|
|
socks {"action":"start","port":7002}
|
|
|
|
# Configure proxychains
|
|
# Edit /etc/proxychains.conf
|
|
[ProxyList]
|
|
socks5 <mythic_server_ip> 7002
|
|
|
|
# Use with any tool
|
|
proxychains curl https://internal-server.local
|
|
proxychains nmap -sT 192.168.1.0/24
|
|
```
|
|
|
|
### Performance Considerations
|
|
|
|
- **Latency**: Proxy speed depends on beacon interval. SOCKS mode automatically reduces sleep to 100ms
|
|
- **Throughput**: Suitable for interactive sessions and moderate data transfer
|
|
- **Concurrent Connections**: Supports multiple simultaneous SOCKS connections
|
|
|
|
---
|
|
|
|
## Reverse Port Forwarding (RPFWD) Support
|
|
|
|
Cazalla includes reverse port forwarding (RPFWD) support, allowing you to tunnel incoming connections from the agent to a remote destination through Mythic.
|
|
|
|
### Features
|
|
|
|
- **Reverse Tunneling**: Connections originate from external clients to the agent
|
|
- **Remote Destination**: Forwards connections to configured remote destinations
|
|
- **Multiple Connections**: Supports multiple simultaneous RPFWD connections
|
|
- **Automatic Cleanup**: Closed connections are automatically cleaned up
|
|
|
|
### How It Works
|
|
|
|
1. **Agent opens a listener** on a local port (e.g., `8080` on the agent host)
|
|
2. **External client connects** to the agent's listener port
|
|
3. **Agent sends connection data** to Mythic via RPFWD protocol
|
|
4. **Mythic connects** to the configured remote destination (`remote_host:remote_port`)
|
|
5. **Bidirectional relay** between client ↔ Agent ↔ Mythic ↔ Remote destination
|
|
|
|
### Use Cases
|
|
|
|
- **Access internal services**: Expose internal services (e.g., database, web server)
|
|
- **Bypass firewall restrictions**: When you can't connect from Mythic but can connect to the agent
|
|
- **Service tunneling**: Tunnel arbitrary TCP services through the agent
|
|
|
|
### Example
|
|
|
|
```bash
|
|
# Start reverse port forward
|
|
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
|
|
|
|
# Connect to agent:8080 will forward to 192.168.1.100:80
|
|
curl http://<agent_ip>:8080
|
|
```
|
|
|
|
---
|
|
|
|
## Token Support
|
|
|
|
Cazalla supports Windows token manipulation and impersonation, following Mythic's Token specification.
|
|
|
|
### Features
|
|
|
|
- **Token Listing**: Enumerate all viewable tokens from running processes
|
|
- **Token Theft**: Steal tokens from processes to impersonate different users
|
|
- **Token Creation**: Create new tokens using credentials (domain, username, password)
|
|
- **Token Impersonation**: Impersonate tokens for subsequent tasking
|
|
- **Token Revert**: Revert to original token when done impersonating
|
|
- **SeDebugPrivilege**: Automatically enables `SeDebugPrivilege` for accessing system processes
|
|
- **Mythic Integration**: Tokens are tracked in Mythic's Token UI and can be selected for tasking
|
|
|
|
### Token Commands
|
|
|
|
- **`list_tokens`**: Enumerate all available tokens
|
|
- **`steal_token <pid>`**: Steal token from a process
|
|
- **`make_token domain username password`**: Create token from credentials
|
|
- **`rev2self`**: Revert to original token
|
|
- **`whoami`**: Display current security context
|
|
|
|
### Using Tokens for Tasking
|
|
|
|
1. Execute `list_tokens` to see available tokens
|
|
2. Execute `steal_token <pid>` to steal a token (or use `make_token` to create one)
|
|
3. In the Mythic UI, a dropdown appears next to the tasking bar
|
|
4. Select a token from the dropdown before issuing commands
|
|
5. Commands will execute with the selected token's security context
|
|
|
|
---
|
|
|
|
## Keylogging Support
|
|
|
|
Cazalla supports capturing keystrokes from the target system and reporting them to Mythic's Keylogs feature.
|
|
|
|
### Features
|
|
|
|
- **Window-Aware Keylogging**: Captures keystrokes along with the active window title
|
|
- **User Context**: Includes the username in each keylog entry
|
|
- **Process-Agnostic**: Works with any application (Notepad, browsers, terminals, etc.)
|
|
- **Automatic Buffering**: Buffers keystrokes and sends them periodically (every 3 seconds or 128 bytes)
|
|
- **Background Thread**: Runs as a separate thread, allowing other commands to execute while keylogging
|
|
|
|
### How It Works
|
|
|
|
1. **Start Keylogging**: Execute `keylog_start`
|
|
2. **Background Thread**: Agent creates a background thread that monitors keyboard input
|
|
3. **Keystroke Capture**: Uses `GetAsyncKeyState` to detect key presses
|
|
4. **Window Detection**: Captures the active window title
|
|
5. **Periodic Transmission**: Sends keystrokes every 3 seconds or when buffer reaches 128 bytes
|
|
6. **Stop Keylogging**: Execute `keylog_stop` to terminate the keylogger
|
|
|
|
### Universal Process Support
|
|
|
|
The keylogger works with **any Windows application** because it:
|
|
- Uses `GetForegroundWindow()` to get the currently active window
|
|
- Captures keystrokes system-wide using `GetAsyncKeyState`
|
|
- Doesn't require injection into specific processes
|
|
|
|
### Viewing Keylogs
|
|
|
|
1. Navigate to your callback in the Mythic UI
|
|
2. Click the **KEYLOGS** tab in the top navigation
|
|
3. View all captured keystrokes grouped by task, user, window, and timestamp
|
|
|
|
---
|
|
|
|
## File Downloads Support
|
|
|
|
Cazalla supports downloading files from the target to the Mythic server using chunked transfers.
|
|
|
|
### Features
|
|
|
|
- **Chunked File Transfers**: Large files are automatically split into chunks (512KB default)
|
|
- **Automatic Registration**: Files are automatically registered with Mythic before transfer
|
|
- **Progress Tracking**: Mythic tracks download progress (chunks received/total chunks)
|
|
- **File Read Artifacts**: Automatically reports File Read artifacts when files are downloaded
|
|
- **Full Path Tracking**: Reports full file paths for proper tracking
|
|
|
|
### How It Works
|
|
|
|
1. **Command Execution**: Execute `download C:\path\to\file.txt`
|
|
2. **File Registration**: Agent sends file metadata to Mythic
|
|
3. **Chunk Transfer**: Agent sends file data in chunks (base64-encoded)
|
|
4. **Completion**: File appears in Mythic's file browser once all chunks are received
|
|
|
|
### Download Process
|
|
|
|
- **Chunk Size**: 512KB per chunk (configurable)
|
|
- **File Size Limit**: Supports files up to 2GB (can be extended)
|
|
- **Base64 Encoding**: Chunk data is base64-encoded before transmission
|
|
- **Artifact Reporting**: Automatically reports "File Read" artifact
|
|
|
|
---
|
|
|
|
## File Uploads Support
|
|
|
|
Cazalla supports uploading files from the Mythic server to the target using chunked transfers.
|
|
|
|
### Features
|
|
|
|
- **Chunked File Transfers**: Large files are automatically split into chunks (512KB default)
|
|
- **Automatic Path Normalization**: Automatically handles path formatting
|
|
- **Smart Path Handling**: Automatically appends filename when path is a directory
|
|
- **File Browser Integration**: Fully integrated with Mythic's File Browser UI
|
|
- **Progress Tracking**: Mythic tracks upload progress (chunks sent/total chunks)
|
|
- **File Write Artifacts**: Automatically reports File Write artifacts
|
|
|
|
### How It Works
|
|
|
|
1. **Command Execution**: Execute `upload <file_id> C:\path\to\destination.txt`
|
|
2. **Path Normalization**: Agent normalizes the destination path
|
|
3. **Chunk Requests**: Agent requests file chunks from Mythic sequentially
|
|
4. **Chunk Writing**: Agent decodes and writes chunks to the destination file
|
|
5. **Completion**: File Write artifact is reported when complete
|
|
|
|
### Path Handling
|
|
|
|
- **Normalization**: Automatically normalizes double backslashes
|
|
- **Directory Detection**: Automatically detects directories and appends filename
|
|
- **Parent Directory Creation**: Automatically creates parent directories if they don't exist
|
|
- **Error Handling**: Clear error messages for invalid paths, access denied, etc.
|
|
|
|
---
|
|
|
|
## System Information Gathering
|
|
|
|
Cazalla includes commands for gathering system information with low detection risk.
|
|
|
|
### Features
|
|
|
|
- **Browser Detection**: Identify installed web browsers and default browser
|
|
- **Read-Only Operations**: No system modifications, minimal detection risk
|
|
- **Version Information**: Extract version details from browser executables
|
|
- **Registry Queries**: Query Windows registry for browser associations
|
|
|
|
### Commands
|
|
|
|
#### `browser_info`
|
|
|
|
Identifies all installed web browsers on the target system and determines the default browser.
|
|
|
|
**Supported Browsers:**
|
|
- Google Chrome
|
|
- Microsoft Edge
|
|
- Mozilla Firefox
|
|
- Opera
|
|
- Brave
|
|
|
|
**Output Includes:**
|
|
- Installation paths for each detected browser
|
|
- Version information (when available)
|
|
- Default browser identification
|
|
|
|
**OPSEC Considerations:**
|
|
- Low detection risk - read-only operations
|
|
- Registry reads may be logged if auditing enabled
|
|
- No process creation or network activity
|
|
- No file modifications
|
|
|
|
**Example:**
|
|
```
|
|
browser_info
|
|
```
|
|
|
|
**Output:**
|
|
```
|
|
=== Installed Browsers ===
|
|
|
|
[1] Microsoft Edge
|
|
Path: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
|
|
Version: 142.0.3595.94
|
|
|
|
[2] Mozilla Firefox
|
|
Path: C:\Program Files\Mozilla Firefox\firefox.exe
|
|
Version: 145.0.1.627
|
|
|
|
=== Default Browser ===
|
|
|
|
Name: Microsoft Edge
|
|
Path: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
|
|
```
|
|
|
|
For detailed information, see [browser_info command documentation](commands/browser_info.md).
|
|
|
|
---
|
|
|
|
## OPSEC Checking
|
|
|
|
Cazalla includes comprehensive OPSEC Checking functionality that provides operational security warnings and blocking for commands based on their detection risks.
|
|
|
|
### Features
|
|
|
|
- **Pre-execution Blocking**: Commands can be blocked before execution
|
|
- **Post-execution Warnings**: Artifacts are automatically tracked and warned about
|
|
- **Customizable Bypass Roles**: Configure who can approve blocked tasks
|
|
- **Detailed Warnings**: Comprehensive explanations of OPSEC risks
|
|
|
|
### How It Works
|
|
|
|
1. **OPSEC Pre-Check (`opsec_pre`)**: Runs before task creation, can block execution
|
|
2. **OPSEC Post-Check (`opsec_post`)**: Runs after task creation, warns about artifacts
|
|
|
|
### Commands with OPSEC Checking
|
|
|
|
- **High-Risk Commands (Blocking)**: `shell`, `steal_token`, `kill`, `keylog_start`, `rm` (system files)
|
|
- **Warning-Only Commands**: `screenshot`, `rpfwd`, `socks`, `download`, `upload`, `make_token`, `browser_info`, etc.
|
|
|
|
### Bypass Roles
|
|
|
|
- **`operator`**: Any operator can bypass
|
|
- **`other_operator`**: Requires approval from a different operator
|
|
- **`lead`**: Only operation lead can approve
|
|
|
|
For detailed information, see [OPSEC Guide](opsec.md).
|
|
|
|
---
|
|
|
|
## Related Documentation
|
|
|
|
- [Commands Reference](commands.md) - Detailed command documentation
|
|
- [OPSEC Guide](opsec.md) - Operational security considerations
|
|
- [Usage Examples](examples.md) - Practical examples
|
|
- [Getting Started](getting-started.md) - Installation and setup
|
|
|
|
---
|
|
|
|
**Last Updated:** 2024
|
|
|