Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
See Benchmark (https://github.com/microsoft/CyberBattleSim/blob/main/docs/benchmark.md).
Setting up a dev environment
It is strongly recommended to work under a Linux environment, either directly or via WSL on Windows. Running Python on Windows directly should work but is not supported anymore. Start by checking out the repository: git clone https://github.com/microsoft/CyberBattleSim.git
On Linux or WSL
The instructions were tested on a Linux Ubuntu distribution (both native and via WSL). Run the following command to set-up your dev environment and install all the required dependencies (apt and pip packages): ./init.sh The script installs python3.8 if not present. If you are running a version of Ubuntu older than 20 it will automatically add an additional apt repository to install python3.8. The script will create a virtual Python environment (https://docs.python.org/3/library/venv.html) under a venv subdirectory, you can then run Python with venv/bin/python. Note: If you prefer Python from a global installation instead of a virtual environment then you can skip the creation of the virtual envrionment by running the script with ./init.sh -n. This will instead install all the Python packages on a system-wide installation of Python 3.8.
Windows Subsystem for Linux
The supported dev environment on Windows is via WSL. You first need to install an Ubuntu WSL distribution on your Windows machine, and then proceed with the Linux instructions (next section).
Git authentication from WSL
To authenticate with Git you can either use SSH-based authentication, or alternatively use the credential-helper trick to automatically generate a PAT token. The latter can be done by running the following commmand under WSL (more info here (https://docs.microsoft.com/en-us/windows/wsl/tutorials/wsl-git)): git config --global credential.helper "/mnt/c/Program\ Files/Git/mingw64/libexec/git-core/git-credential-manager.exe"
Docker on WSL
To run your environment within a docker container, we recommend running docker via Windows Subsystem on Linux (WSL) using the following instructions: Installing Docker on Windows under WSL (https://docs.docker.com/docker-for-windows/wsl-tech-preview/)).
Windows (unsupported)
This method is not maintained anymore, please prefer instead running under a WSL subsystem Linux environment. But if you insist you want to start by installing Python 3.8 (https://www.python.org/downloads/windows/) then in a Powershell prompt run the ./init.ps1 script.
Getting started quickly using Docker
The quickest method to get up and running is via the Docker container. NOTE: For licensing reasons, we do not publicly redistribute any build artifact. In particular the docker registry spinshot.azurecr.io referred to in the commands below is kept private to the project maintainers only. As a workaround, you can recreate the docker image yourself using the provided Dockerfile, publish the resulting image to your own docker registry and replace the registry name in the commands below. commit=7c1f8c80bc53353937e3c69b0f5f799ebb2b03ee
docker login spinshot.azurecr.io
docker pull spinshot.azurecr.io/cyberbattle:$commit
docker run -it spinshot.azurecr.io/cyberbattle:$commit cyberbattle/agents/baseline/run.py
Check your environment
Run the following command to run a simulation with a baseline RL agent: python cyberbattle/agents/baseline/run.py --training_episode_count 1 --eval_episode_count 1 --iteration_count 10 --rewardplot_with 80 --chain_size=20 --ownership_goal 1.0
If everything is setup correctly you should get an output that looks like this: torch cuda available=True
###### DQL
Learning with: episode_count=1,iteration_count=10,ϵ=0.9,ϵ_min=0.1, ϵ_expdecay=5000,γ=0.015, lr=0.01, replaymemory=10000,
batch=512, target_update=10
## Episode: 1/1 'DQL' ϵ=0.9000, γ=0.015, lr=0.01, replaymemory=10000,
batch=512, target_update=10

___________________________
@hacking_Attack
@Hacking_Video
Episode 1|Iteration 10|reward: 139.0|Elapsed Time: 0:00:00|###################################################################|
###### Random search
Learning with: episode_count=1,iteration_count=10,ϵ=1.0,ϵ_min=0.0,
## Episode: 1/1 'Random search' ϵ=1.0000,
Episode 1|Iteration 10|reward: 194.0|Elapsed Time: 0:00:00|###################################################################|
simulation ended
Episode duration -- DQN=Red, Random=Green
10.00 ┼
Cumulative rewards -- DQN=Red, Random=Green
194.00 ┼ ╭──╴
174.60 ┤ │
155.20 ┤╭─────╯
135.80 ┤│ ╭──╴
116.40 ┤│ │
97.00 ┤│ ╭╯
77.60 ┤│ │
58.20 ┤╯ ╭──╯
38.80 ┤ │
19.40 ┤ │
0.00 ┼──╯
Jupyter notebooks
To quickly get familiar with the project you can open one the the provided Juptyer notebooks to play interactively with the gym environments. Just start jupyter with jupyter notebook, or venv/bin/jupyter notebook if you are using a virtual environment setup. 'Capture The Flag' toy environment notebooks: Random agent (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/toyctf-random.ipynb) Interactive session for a human player (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/toyctf-blank.ipynb) Interactive session - fully solved (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/toyctf-solved.ipynb) Chain environment notebooks: Random agent (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/chainnetwork-random.ipynb) Other environments: Interactive session with a randomly generated environment (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/randomnetwork.ipynb) Random agent playing on randomly generated networks (https://github.com/microsoft/CyberBattleSim/blob/main/notebooks/c2_interactive_interface.ipynb) The following .py notebooks are best viewed in VSCode or in Jupyter with the Jupytext extension (https://jupytext.readthedocs.io/en/latest/install.html) and can easily be converted to .ipynb format if needed: Chain environments benchmarks: Benchmark of all baseline agents (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_all_agents_benchmark.py) All baseline agents against a basic defender (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_withdefender.py) DeepQL (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_dql.py) Epsilon greedy (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_randlookups.py) Tabular Q Learning (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_tabularq.py) Capture the Flag benchmark: DeepQL (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/agents/baseline/notebooks/notebook_ctf_dql.py)
How to instantiate the Gym environments?
The following code shows how to create an instance of the the OpenAI Gym environment CyberBattleChain-v0, an environment based on a chain-like network structure (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/samples/chainpattern/chainpattern.py), with 10 nodes (size=10) where the agent's goal is to either gain full ownership of the network (own_atleast_percent=1.0) or break the 80% network availability SLA (maintain_sla=0.80), while the netowrk is being monitored and protected by basic probalistically-modelled defender (defender_agent=ScanAndReimageCompromisedMachines): import cyberbattle._env.cyberbattle_env

cyberbattlechain_defender =
gym.make('CyberBattleChain-v0',
size=10,
attacker_goal=AttackerGoal(
own_atleast=0,
own_atleast_percent=1.0
),
defender_constraint=DefenderConstraint(
maintain_sla=0.80
),
defender_agent=ScanAndReimageCompromisedMachines(

___________________________
@hacking_Attack
@Hacking_Video
probability=0.6,
scan_capacity=2,
scan_frequency=5)) To try other network topologies, take example on chainpattern.py (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/samples/chainpattern/chainpattern.py) to define your own set of machines and vulnerabilities, then add an entry in the module initializer (https://github.com/microsoft/CyberBattleSim/blob/main/cyberbattle/__init__.py) to declare and register the Gym environment.
Contributing
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com (https://cla.opensource.microsoft.com/). When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA. This project has adopted the Microsoft Open Source Code of Conduct (https://opensource.microsoft.com/codeofconduct/). For more information see the Code of Conduct FAQ (https://opensource.microsoft.com/codeofconduct/faq/) or contact opencode@microsoft.com (mailto:opencode@microsoft.com) with any additional questions or comments.
Ideas for contributions
Here are some ideas on how to contribute: enhance the simulation (event-based, refined the simulation, …), train an RL algorithm on the existing simulation, implement benchmark to evaluate and compare novelty of agents, add more network generative modes to train RL-agent on, contribute to the doc, fix bugs. See also the wiki for more ideas (https://github.com/microsoft/CyberBattleGym/wiki/Possible-contributions).
Citing this project
@misc{msft:cyberbattlesim,
Author = {Microsoft Defender Research Team.}
Note = {Created by Christian Seifert, Michael Betser, William Blum, James Bono, Kate Farris, Emily Goren, Justin Grana, Kristian Holsheimer, Brandon Marken, Joshua Neil, Nicole Nichols, Jugal Parikh, Haoran Wei.},
Publisher = {GitHub},
Howpublished = {\url{https://github.com/microsoft/cyberbattlesim}},
Title = {CyberBattleSim},
Year = {2021}
}
Note on privacy
This project does not include any customer data. The provided models and network topologies are purely fictitious. Users of the provided code provide all the input to the simulation and must have the necessary permissions to use any provided data.
Trademarks
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines (https://www.microsoft.com/en-us/legal/intellectualproperty/trademarks/usage/general). Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.

Download CyberBattleSim (https://github.com/microsoft/CyberBattleSim)

___________________________
@hacking_Attack
@Hacking_Video
Exploiting Activity in medium android app

Hello friends I am Raju Kumar A.k.a Mrcyberwarrior. Let’s come to the story, I found vulnerabilities in the web as well as android…Continue reading on Medium »
Read more...
Unauthenticated AD password reset bug = Informational?? SINCE WHEN.

Continue reading on Medium »
Read more...