Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
nique implementation which can be executed on running agents. Abilities will include the command(s) to run, the platforms/executors the commands can run on (ex: Windows / PowerShell), payloads to include, and a reference to a module to parse the output on…
ieam5BJJZfl2sJdPGFgEsqk4fjLGIvSA5jDo6Wam5xBSi6zhFHXXnsFm6S-1oxLOGcDdHxSWYTsrHTBgHDJVofQFumH4YAwbVMQ/s16000/21.png?w=640&ssl=1

Go to debrief tab, choose the pointers to be included in the report; then download the full report as a PDF

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgniyj3nsyfRAPVMvohry2a8oH31GlknWlNXoGWkWfg_lBdYAYe66vqLnZU-KusWG1xp-yJLTPrJr7uGs14nXKmFCfPMAs3xzfiDJzOE0x4-iu4LLLt3xbvX8k2gU3Pj-Tz7MP4q-ckUpK0gE9yJp9dkj1f8nniqArNZgWJfXg0tbJEdxHNJiqPX_nKJQ/s16000/22.1.png?w=640&ssl=1

https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirqcsD1WicISDbW-oA2VeewJfMPPhVIito23X-D8NlVTLQzZ5iM89XnPYzNlsFFKT-1Z9c1K3CfzQso3dU4IWSExEwwurqjON99n5qupm60ww3BL-ZwwOvExSVgMFea83-VA7Lwm2-ffaoEZ2hIDydCDOsKisq-xhgk4ej7VG8VWROXT3o8gVVqIxnLA/s16000/22.png?w=640&ssl=1 ConclusionWe have thus been able to perform the adversary simulation with the help of Caldera. Using this framework, Red/Purple team activities can be easily performed.

Reference: https://caldera.readthedocs.io/en/latest/

Author: Ankit Sinha is a security researcher with expertise in Pentesting, Threat hunting and red teaming. Also, likes to work on a Myriad of things in the discipline of offensive security. Contact here

The post Caldera: Red Team Emulation (Part 1) appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
RSAC Startup Competition Focuses on Post-Cloud IT Infrastructure

A secure Web browser takes the top prize, and for the second year in a row malware detection is an afterthought.
Dark Reading: Attacks/Breaches
EU & US Unite to Fight Ransomware

A working group of European and US officials meet at The Hague to collaborate on ransomware operations and strategies.
Dark Reading: Attacks/Breaches
Unlocking the Cybersecurity Benefits of Digital Twins

Security pros can employ the technology to evaluate vulnerabilities and system capabilities, but they need to watch for the potential risks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Caldera: Red Team Emulation (Part 1)

This article aims to demonstrate an open-source breach & emulation framework through which red team activity can be conducted with ease. It focuses on MITRE simulation and has tons of other functions that can be used in the activity.

Table of Contents· Pre-requisite & dependenciesCampaigns· Step1: Abilities ConclusionMitre Att&ckMitre framework provides list of all the Tactics, Techniques and Procedure (TTPs) & their corresponding sub-techniques arranged in a well-structured form which can be used in red team activities.CalderaCALDERA breach & emulation tool designed to easily automate adversary emulation, assist manual red-teams, and automate incident response.The core system:This is the framework code, consisting of what is available in this repository. Included is an asynchronous command-and-control (C2) server with a REST API and a web interface.Plugins:These repositories expand the core framework capabilities and providing additional functionality. Examples include agents, reporting, collections of TTPs and more.Pre-requisite & dependenciesThese requirements are for the computer running the core framework:InstallationFollow these steps for setting up caldera:git clone https://github.com/mitre/caldera.git --recursivehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguVaqh-QQaeCGiN858M7A8pkWvV3BFyuS_E_xiSE2UQ0LXWXHXbh_SImDaDrr_T-dztmDY9guusDhaTbi10jfAxQLRfGH5fKT63MNfgc51NKgJPSuG-o85_RNzqdVM7ZFPiQuZxdjulRt7RjvA-VZqAUSRWyNRpoMgJT7aqu0b6vZ9AelZb_go1AtylA/s16000/1.png cd caldera –insecurehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAIfh3Ra6ydFJ1f1HfltbyY_HHC9yNugHIwLh-a-w7Rf2Aok45aJS3B9w2-acduxLE_PYEdqeZGpPYzly9z6iNF1yc5l6tbWll-O9pJ1-HH9a4bJtnQg9b2hERJovEedd5y1t2YnuyiuWFTGm5zKQPMth1TGj6Wtk6yIuGS6B_WU_OICGvEncD5PLxow/s16000/2.png InterfaceCaldera provides web interface which is simple to navigate and use.http://127.0.0.1:8888https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic7DYVpDLQI-0W8-JpQIt-lioSTPCd4nKRQ_l1x4guI0iw0KL7sSYz_CdLjfFMd763sAGHPlHynOFi9lMXWwR6JoA6zSUEFPX2tFvE-Db-28a1rk-1yW-yo6Te9sXB2Wr-sr3xxo0tzD8hXYR4UEgatg-PYMfGC-8rrWan1QEfqKw54JjnpkMt3_E-8A/s16000/3.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgP3STTZlSiz1H01unjLETZOAshF9WXCrE3RI5RIpiS5QvH2WmSznsuQeodXBb4yBGRZ8trCKnT3Oza6oKM8XzS8PF1dvtfytvSGrItr41dIfF1p50KENWl76JRK166jDoOReds2Ctmjr0izlEUwzfCgI8oKqzpTfXpi8Gqqw0YnyHHC6x0iC6-fepiww/s16000/4.png PluginsThe Plugins category offers a list of all current plugins and allows you to quickly and easily access their functionality. ___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Caldera: Red Team Emulation (Part 1) This article aims to demonstrate an open-source breach & emulation framework through which red team activity can be conducted with ease. It focuses on MITRE simulation and has tons of…
p

· Builder (Dynamically compile payloads)CampaignsAgents, adversaries, and operations make up the Campaigns category, which may be used to build up the numerous agents, adversaries, and operations needed for a red team operation or adversary emulation.Step1: Deploy an AgentsTo begin with initial access we need to implant an agent inside the target system. Darwin [mac OS]) (Bypass the execution policy first)___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
p · Builder (Dynamically compile payloads)CampaignsAgents, adversaries, and operations make up the Campaigns category, which may be used to build up the numerous agents, adversaries, and operations needed for a red team operation or adversary emulation.Step1:…
e victim end was successful Step2: AbilitiesAn ability is a specific ATT&CK tactic/technique implementation which can be executed on running agents. Abilities will include the command(s) to run, the platforms / executors the commands can run on (ex: Windows / PowerShell), payloads to include, and a reference to a module to parse the output on the CALDERA server.Step3: Setting up OperationsAfter setting up the agent, now it is time to run the abilities or the set of instructions as shown above. For this we need to set up an operationAdversary Profiles are collections of ATT&CK TTPs, designed to create specific effects on a host or network. Profiles can be used for offensive or defensive use cases.) https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9O_BOgV4ntEJ8vvweuS5w0YpJS479h46XGM0z5MQT3E8ngK2I15uquRyJoAS1e7drC1-jPsqua6R_1e1Aq4--LZBah2iXv-yDpKZd8s_idEB-udPfWOpCT-79jqBE10vw61tz50oegHlai9GIoofAHk-Er_YXv8swVPlXkpz9ASFQRlwVmx7Djv2CXA/s16000/18.png 6. As you can see, all set of commands running is obfuscated in base64nopaddformat (also you can select other options specified), we can also see the command and also, we can view output of the command (Also, we can see the status of the task performed) https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0SJPpWNdI6yTpXOrmSEL4rmGqsYZtzaKci3YSFXx-0SinjwY8qljYq9dvFzaJXMc79FV58-ro1ejU57INFCW8nXjVEul_XsJA29RDvyud_uLlUnOMGFCf9WcezyL-qC6TmDu7lpPY3smtWUnwuusWRLRo90kxQ51maHC7XH4I3RFiwuUhfofh5yjdgw/s16000/19.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIg-dosfSEVftrsHmZ_A4ONUMZQbg-9HlOtFrlDLHdMbaCEWhRDbJV1Jpo8b7QFIRVm0vDlwlcNVZeEqyyPL1vlptRgONH9rgE-mnkVok8q5hI0t7KSOKthgIDQbdDjfuE5EJT6O2bJE-qbBoqqfmNv-FpFzRkoMXIiYBqzvLfXHazS7-9o5Z_W5f4Bg/s16000/20.png Step4: Exporting the resultAfter the activity has been completed,[...]

___________________________
@hacking_Attack
@Hacking_Video