211 Commits

Author SHA1 Message Date
Kevin b114f4327c Added a new module for SOCKSv5 proxying
When executed, this module connects back to a designated AlmondRocks server under SSL. The AlmondRocks server acts as a SOCKSv5 proxy, and multiplexes all SOCKS communications over the single SSL connection to/through the target, enabling any SOCKSv5 client (e.g. curl, proxychains) to extend past NAT devices into the target network.

This is based on the following work:
- https://github.com/klustic/AlmondRocks
2017-04-04 17:19:56 -06:00
xorrior b5697fc66b Fixed Hijacker scanner. Fixed template Hijackers 2016-10-03 21:33:05 -04:00
xorrior 7e6dc31fe6 Merge branch 'dev' of https://github.com/adaptivethreat/EmPyre into dev 2016-10-03 13:04:32 -04:00
xorrior ee2bf516d3 Removed standalone hijacker creation 2016-10-03 13:03:31 -04:00
xorrior 7424e42f94 Updated hijackers 2016-10-03 12:20:03 -04:00
HarmJ0y 9661c3a022 patched "skywalker 2.0" thanks to @zeroSteiner 2016-09-29 13:17:37 -04:00
xorrior 2b7bb42652 Added in memory imports to agent. Still testing 2016-09-27 21:09:02 -04:00
chris 50166c4374 Added Jar stager 2016-09-13 01:18:00 -04:00
chris 2ab95076be Update package launcher 2016-08-27 22:43:23 -04:00
chris 5c4e62d31f Updated the install script and dylib, pkg, application stagers 2016-08-27 22:09:33 -04:00
chris cfb5ac84fa Remove comment in stagers.py 2016-08-21 13:16:43 -04:00
chris 1dc3d6f13e Added more customization for Installer Pkg's 2016-08-21 13:08:08 -04:00
chris 4e767c528e Add pkg installer stager.
Added pkg installer stager. Not very customizable at the moment.
Added AppName option to application stager.
Updated install bash script to include depencies for creating pkg files (mkbom, xar archiver).
2016-08-17 11:24:03 -04:00
xorrior 56c77d210b replaced SafeChecks options w/ LittleSnitch 2016-08-14 17:45:26 -04:00
xorrior 2f4cbbac53 Merge branch 'dev' of https://github.com/adaptivethreat/EmPyre into dev 2016-08-14 17:20:18 -04:00
xorrior b494b09809 Added application launcher 2016-08-14 17:19:20 -04:00
@424f424f 21e9959665 Merge branch 'dev' of https://github.com/AdaptiveThreat/EmPyre into dev 2016-08-13 19:45:14 -04:00
@424f424f 9c7bbe65c7 dscl search modules 2016-08-13 19:43:57 -04:00
@424f424f 7946042d2f Merge branch 'dev' of https://github.com/AdaptiveThreat/EmPyre into dev 2016-08-12 18:50:21 -04:00
@424f424f 3b473a867d Revert "Updated SafeChecks for little snitch and sandboxes"
This reverts commit 012c3a4218.
2016-08-12 18:49:02 -04:00
xorrior 5ff26b5b51 Added duckyscript stager 2016-08-11 21:11:11 -04:00
@424f424f 4ced4a3311 Add Modules 2016-08-10 22:14:17 -04:00
@424f424f 012c3a4218 Updated SafeChecks for little snitch and sandboxes 2016-08-08 11:12:38 -04:00
@424f424f 2436b00a8d Crontab fix 2016-08-06 20:27:26 -04:00
@424f424f 62429da488 Merge branch 'master' into dev
DC/OS, Mesos DNS, Mesos Master, Marathon, Chronos modules from BSidesLV 2016 @TweekFawkes talk.
2016-08-05 17:24:04 -04:00
root c58c3c02be DC/OS modules from BSidesLV 2016 @TweekFawkes talk 2016-08-05 14:02:20 -04:00
@424f424f fede159b76 Update version number 2016-07-28 10:12:23 -04:00
Killswitch-GUI b4091e23f3 add monitoring 2016-07-24 10:42:27 -04:00
Alexander Rymdeko-Harvey 5cc2615ef9 Merge pull request #27 from adaptivethreat/dev-compress
Dev compress
2016-06-28 13:07:00 -04:00
Alexander Rymdeko-Harvey 9c42adbe88 Merge pull request #26 from adaptivethreat/dev-chainbreaker
Dev chainbreaker
2016-06-28 13:01:45 -04:00
Alexander Rymdeko-Harvey 324ff6db39 Update keychaindump_chainbreaker.py 2016-06-28 13:01:33 -04:00
Alexander Rymdeko-Harvey eb65c6583d Update keychaindump_chainbreaker.py 2016-06-28 09:28:53 -04:00
Alexander Rymdeko-Harvey e1d2ec1d87 Update keychaindump_chainbreaker.py 2016-06-28 09:28:28 -04:00
Alexander Rymdeko-Harvey ee8bcad874 Update keychaindump_chainbreaker.py 2016-06-26 23:18:28 -04:00
Alexander Rymdeko-Harvey cd97588c52 Update keychaindump_chainbreaker.py 2016-06-26 23:18:16 -04:00
Killswitch-GUI 20afb3cf87 chainbreaker 2016-06-26 23:14:27 -04:00
Killswitch-GUI 93449bba45 module outpu 2016-06-26 00:13:49 -04:00
Killswitch-GUI aa56d39622 upload/download 2016-06-25 11:45:59 -04:00
rvrsh3ll 602e0025a9 Merge pull request #24 from imaibou/binder
Allow the possibility to separate between socket address and listener's public IP address
2016-06-20 22:07:53 -04:00
imaibou b56f11adaf Update http.py 2016-06-19 17:23:17 +02:00
rvrsh3ll 8a7297aac8 Update version 2016-06-17 10:26:11 -04:00
Alexander Rymdeko-Harvey 4446d3c96c Update screensaver_alleyoop.py 2016-06-16 22:00:09 -04:00
Alexander Rymdeko-Harvey 761d16bd99 Update sniffer.py 2016-06-16 21:59:49 -04:00
Alexander Rymdeko-Harvey 0449f64c31 Update sniffer.py 2016-06-16 21:56:19 -04:00
Alexander Rymdeko-Harvey 12509c09f2 Fix Sniffer 2016-06-16 21:45:00 -04:00
Harmj0y a6e4d6b5f6 bug fix for module description display bug 2016-06-03 13:41:07 -04:00
Harmj0y e119c40722 bug fix for searchmodule 2016-06-03 13:19:38 -04:00
rvrsh3ll 9c94191fe2 Removed opsec safe 2016-05-31 22:25:16 -04:00
rvrsh3ll 95d3671f05 Added Kerberos_Inject 2016-05-29 23:32:06 -04:00
imaibou bc31358bd4 Update http.py
Sometimes, we need to listen on the public server and redirect the traffic into our empire listener on the internal server using DNAT, we would like to set the listeners "Host" to the public IP address while listening on the internal server. This way, all the stager payloads would contain the public IP address while the EmPyre instance turns on the local machine. This pull request would allow us to implement this scenario.
On the empire powershell project, the listener listens by default to the 0.0.0.0 IP address (https://github.com/PowerShellEmpire/Empire/blob/e43fb9463410dfa804e0aa507a5842c1a0504c0d/lib/common/http.py#L150).
2016-05-27 17:11:50 +02:00