82 Commits

Author SHA1 Message Date
Kevin 09a8c119ff Updated SOCKS proxy for Python agent
- Matches new version of AlmondRocks (v1.0.0)
- Breaks compatibility with previous versions of AlmondRocks
2018-05-16 13:39:33 -06:00
xorrior d040e2eef1 Resolved conflict 2018-04-21 13:44:03 -04:00
johneiser 8ee1e66e29 Removed unnecessary call to launchctl 2018-04-11 23:40:34 +00:00
xorrior 79ae0f4ca6 Fix for #1059. Fixed launcher string, which caused macho to crash. Removed unnecessary call to launchctl. Plist will be loaded automatically during the boot process 2018-04-08 14:23:06 -04:00
Justin 1df043104f Added lower privilege osx launch agent persistence 2018-04-06 18:32:59 -04:00
xorrior 1957c28368 Merge branch 'master' of https://github.com/import-au/Empire into import-au-master 2018-03-14 13:43:02 -04:00
xorrior e65e15c982 Removed ls_m and shellb modules for python 2018-03-11 15:23:37 -04:00
import-au 1f2c9324d2 Modified verbiage for Version. Added exception handling. 2018-03-08 10:36:20 -05:00
import-au 81cbcf890e Renamed new keychain module 2018-03-08 10:36:20 -05:00
import-au 2999dbbf13 Keychain dump fixed. 2018-03-08 10:36:20 -05:00
import-au bc310d9c0e Fixed osx/situationalawareness
osx/macro now properly supports older and newer variants of Office
Working on keychaindump_sandbox
2018-03-08 10:36:20 -05:00
Adam Gold c17f06251c Fixed SA for OSX 2018-03-08 10:36:20 -05:00
Adam Gold 496806824e Macro changes 2018-03-08 10:35:56 -05:00
Adam Gold ec2e453de1 Added Wireless Info 2018-03-08 10:34:36 -05:00
Adam Gold 691882a84f Dump decrypted keychain 2018-03-08 10:34:36 -05:00
xorrior 927fb957ca Update comments 2018-02-27 18:00:32 -05:00
jarrodcoulter 8c99cb4c07 Updated based on Feedback
Removed variable names starting with a capital and added remove.lower() to match on lowercase true as well as True.
2018-02-23 06:48:12 -06:00
jarrodcoulter d73f62a22d Update Comments
Re-added comments for references.
2018-02-20 09:42:50 -06:00
jarrodcoulter 20222d9b5d Update desktopfile to add Remove capability
Added a section to improve the Desktop file persistence by letting the use remove previous persistence mechanisms. Checks to see if the FileName exists and if so removes it.
2018-02-20 09:22:48 -06:00
jarrodcoulter 1f58041d45 Add Linux Persistence through Autostart
Creating persistence by adding the python launcher to the ~/.config/autostart directory. This is based on the CrossRat analysis (https://digitasecurity.com/blog/2018/01/23/crossrat/) and the other links in the comments.
Tested in Ubuntu 16 and Oracle Linux 7.
2018-02-09 11:15:04 -06:00
xorrior df0d1927a2 Change Background to True for both modules 2018-01-27 18:56:08 -05:00
xorrior 184208c964 Merge branch 'dev' of https://github.com/retro-engineer/Empire into retro-engineer-dev 2018-01-27 18:38:51 -05:00
Chris Ross e2ea55835a Merge pull request #893 from s0lst1c3/dev
Module Added: osx_mic_record (resolves #865)
2018-01-07 19:05:31 -05:00
Peter Toth e6ea80e18e More robust password prompt handler
Some SSH clients used a more verbose password prompt: "Password for user@pfSense.domain.local:". This patch makes the parent process wait for any string starting with "Password" and ending with ":"
2018-01-04 16:13:51 +01:00
Gabriel Ryan 94f371fbc2 Module now uses pyobjc script instead of stand-alone binary for microphone capture. 2018-01-04 06:34:12 -06:00
xorrior 8895e13a6c Merge branch 'dev' into kerberoast-fix
Conflicts:
	.circleci/config.yml
	changelog
	empire
	lib/common/stagers.py
2018-01-02 15:42:08 -05:00
Gabriel Ryan 10e3370f26 Module Added: osx_mic_record (resolves #865)
Adds a module that records audio through the MacOS webcam mic. Audio is recorded using a custom binary that interacts directly with the Apple AVFoundation API (source: https://github.com/s0lst1c3/osx_mic_record). Resolves #865.
2017-12-31 15:55:46 -06:00
xorrior 0ed51ae1c4 Removed print statements from screensaver_alleyoop module 2017-12-13 20:02:18 -05:00
Chris Ross 8ddeb63137 Merge pull request #844 from kost/fixemptybomutils
Fix empty bomutils folder
2017-12-03 01:21:34 -05:00
xorrior 6ddba3f0ee Fixed ls_m module generate function sig 2017-11-30 18:26:47 -08:00
xorrior 99a9a4a6fa Renamed osx ls module 2017-11-30 18:24:34 -08:00
xorrior 5c69be36c1 Fixed ls_m module generate function sig 2017-11-30 06:09:26 -08:00
xorrior e39f8d423a Renamed osx ls module 2017-11-30 06:05:14 -08:00
xorrior 16e4467557 Added background shell exec 2017-11-29 19:06:55 -05:00
xorrior eea19fced5 Added native_screenshot_mss module 2017-11-29 14:52:32 -05:00
xorrior 87ec0ff9aa Added native_screenshot_mss module 2017-11-29 14:51:48 -05:00
xorrior 3558acba42 Swapped native_screenshot module. Now uses python-mss and drops image to disk 2017-11-29 14:10:14 -05:00
xorrior d615e99352 Swapped native_screenshot module. Now uses python-mss and drops image to disk 2017-11-29 14:08:12 -05:00
xorrior 95d8142b39 Remove debug message from xkeylogger module 2017-10-23 21:17:08 -04:00
Chris Ross 06f87cc6ee Merge pull request #762 from elitest/Empyre-Empire
Code cleanup from Empyre merge
2017-10-18 18:47:55 -04:00
Chris Ross 544a0ee282 Merge pull request #718 from nikaiw/dev
Fix PR (generate function signature, opsec value)
2017-10-18 14:46:10 -04:00
Jim Shaver 20519e45be Migrated from Empyre to Empire in the code. 2017-10-17 18:30:13 -05:00
xorrior 4aea7272f0 Merged with master 2017-10-12 12:15:44 -04:00
Nikaiw 00b8427f9b Fix PR (generate function signature, opsec value) 2017-09-24 19:17:26 +02:00
xorrior de03f902ec Repaired function definition for generate() 2017-09-21 22:59:08 -04:00
jarrodcoulter 14efafd5a1 Update Crontab.py
Updated the crontab persistence so that the Hour option sets the Hour rather than the minute option. This make the crontab execute every 24 hours rather than ever x minutes.
2017-08-30 14:59:50 -04:00
xorrior be117d4ca3 Update generate function for all python modules 2017-08-28 11:14:44 -04:00
Drew Varner 332b78d07c Fix shebangs
Move shebangs to /usr/bin/env foo
2017-08-16 01:41:22 -04:00
rvrsh3ll 8c834a9e5b Changed Needs admin to true 2017-08-15 10:48:07 -04:00
checkyfuntime 28fa1905ff Create dyld_print_to_file.py
Empire module for exploitation of Mac OSX's CVE-2015-3760 (DYLD_PRINT_TO_FILE) exploit.
2017-08-06 13:04:21 -04:00