## What changed ### Structure - Converted 4 chokepoints from freeform markdown to structured YAML under chokepoints/<tactic>/ with standardized schema (schema/chokepoint-schema.yml) - Added 12 Sigma rules (Research/Hunt/Analyst) for all 4 chokepoints under sigma-rules/<technique>/ - Moved attack chains to attack-chains/, trends to trends/, templates to templates/ - Added CONTRIBUTING.md modeled after LOLBAS contribution guide ### Slide-to-repo gaps addressed - README.md: Added military chokepoint hook (Thermopylae, Fulda Gap), thesis statement "TTPs evolve. Chokepoints don't.", chokepoint index table with Priority/Prevalence/Difficulty ratings, RaaS TTR compression context - intel/clickgrab.md: Documented ClickGrab (was referenced in slides/references but not in the repo); includes hunt query examples and integration guidance - HackTools/remote-execution: Completed all 3 sigma rule levels (slides showed only a placeholder) - Source citations: Added HudsonRock, RedCanary, Cyberint, Mandiant M-Trends 2025 attributions throughout ### New files CONTRIBUTING.md, schema/chokepoint-schema.yml, intel/clickgrab.md, templates/chokepoint-template.yml, 12 Sigma rule files, attack-chains/ransomware.md, attack-chains/infostealers.md, trends/2025-q1.md, trends/chokepoint-shifts.md https://claude.ai/code/session_01LWLhVRq5vYHXiDKn86PXhr
3.6 KiB
Example: Adding Impacket RDP Shadowing
Scenario: Impacket PR#2064 adds rdp_shadow.py for RDP session hijacking Date: 2025-01-15 Source: https://github.com/fortra/impacket/pull/2064
This document shows the complete workflow for updating the repository with a new threat capability. Total time: ~10 minutes.
Step 1: Identify Existing Chokepoint
Question: Does this require a new chokepoint or does it fit an existing one?
Analysis:
- RDP shadowing = Remote Desktop Hijacking (T1563.002)
- Prerequisites: Admin/SYSTEM, RDP running, network access, target session
- Conclusion: Fits existing "Remote Execution Tools" chokepoint
Step 2: Update the YAML Chokepoint Entry
File: chokepoints/lateral-movement/remote-execution-tools.yml
Changes:
Variations:
# ... existing entries ...
- Name: Impacket (rdp_shadow.py added)
FirstSeen: "2015" # Tool first seen; module added 2025-01
Status: Active
Notes: >
rdp_shadow.py (RDP session hijacking) added via PR#2064 in 2025-01.
Joins psexec.py, smbexec.py, wmiexec.py, atexec.py, dcomexec.py.
EvolutionTimeline:
# Add a new entry at the top (most recent first):
- Date: "2025-01"
Event: Impacket adds rdp_shadow.py (PR#2064)
Change: Native RDP session hijacking capability added to Impacket suite
DetectionImpact: Existing RDP session manipulation detection applies; no new rule needed
TheConstant: "Admin creds + network access + remote execution primitive"
Step 3: Update Trends
File: trends/2025-q1.md
Add to the "New Tool Capabilities" section:
### Q1 2025 — Impacket RDP Shadowing
**Tool:** Impacket rdp_shadow.py
**Date:** 2025-01-15
**Impact:** Low (existing chokepoint coverage)
**Details:**
- PR#2064 adds native RDP session hijacking to Impacket lateral movement suite
- Same prerequisites as existing RDP hijacking tools
- No new chokepoint created
**Chokepoint:** [remote-execution-tools.yml](../chokepoints/lateral-movement/remote-execution-tools.yml)
Step 4: Log in CHANGELOG
File: CHANGELOG.md
## [2025-01-15]
### Added
- Impacket rdp_shadow.py variant to remote-execution-tools.yml Variations table
- Evolution timeline entry for Impacket RDP shadowing (PR#2064)
- Q1 2025 trends entry for new Impacket capability
### Notes
- Existing sigma rules remain valid; no sigma update needed
Step 5: Sigma Rule Assessment
Question: Does this require a new sigma rule or update to existing?
Analysis:
- RDP hijacking detection already exists (Event ID 4624 LogonType 10 + session manipulation)
- Impacket rdp_shadow.py uses the same Windows RDP APIs
- Conclusion: No rule update needed. Existing
sigma-rules/remote-execution/analyst.ymlcovers this.
Document the decision: Add a comment in the sigma rule:
# 2025-01-15: Impacket rdp_shadow.py (PR#2064) covered by this rule.
# LogonType 10 (RemoteInteractive) + IPC$ access pattern applies.
# No rule update required.
Key Takeaway
The chokepoint remained stable.
While Impacket added a new capability, the fundamental requirements didn't change:
- Still needs admin/SYSTEM privileges
- Still needs RDP service running (port 3389)
- Still needs network access to target
- Still manipulates RDP sessions (same detection surface)
This is why chokepoint-based detection is durable — tools evolve, chokepoints don't.
Total Time: ~10 Minutes
Files Modified: 3
chokepoints/lateral-movement/remote-execution-tools.ymltrends/2025-q1.mdCHANGELOG.md
Sigma Rules Modified: 0 (existing coverage confirmed)