2019-08-31 15:23:11 +01:00
2019-08-31 11:45:41 +01:00
2019-08-31 14:58:04 +01:00
2019-08-31 15:23:11 +01:00
2019-08-31 14:58:51 +01:00
2019-08-31 14:07:14 +01:00
2019-08-31 14:07:14 +01:00
2019-08-31 14:07:14 +01:00
2019-08-31 14:07:14 +01:00
2019-06-15 11:11:57 +01:00
2019-02-19 14:49:04 +00:00
2019-02-19 14:49:04 +00:00
2019-02-19 14:49:04 +00:00
2019-08-31 14:23:00 +01:00
2019-08-28 17:56:27 +01:00

  *   )           )         *   )                        )  
` )  /(   (    ( /(   (   ` )  /(         (           ( /(  
 ( )(_))  )\   )\())  )\   ( )(_))   (    )(     (    )\()) 
(_(_())  ((_) ((_)\  ((_) (_(_())    )\  (()\    )\  ((_)\  
|_   _|   (_) | |(_)  (_) |_   _|   ((_)  ((_)  ((_) | |(_) 
  | |     | | | / /   | |   | |    / _ \ | '_| / _|  | ' \  
  |_|     |_| |_\_\   |_|   |_|    \___/ |_|   \__|  |_||_| 

Intro

TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process, then uses CreateRemoteThread to run the desired shellcode within that target process. Both the process and shellcode are specified by the user.

This is pretty flexible as it allows an operator to run an HTTP agent in a process such as iexplore.exe, rather than something more arbitrary like rundll32.exe.

TikiTorch follows the same concept but has multiple types of process injection available, which can be specified by the user at compile time.

Usage

TikiTorch is a Visual Basic solution, split into 8 projects.

  • TikiLoader
  • TikiSpawn
  • TikiSpawnAs
  • TikiSpawnElevated
  • TikiCpl
  • TikiService
  • TikiThings
  • TikiVader

TikiLoader

A .NET Library that contains all the process injection code, used as a reference by the other Tiki projects.

TikiSpawn

A .NET Library designed to bootstrap an agent via some initial delivery, can be used with DotNetToJScript in conjunction with lolbins.

TikiSpawnAs

A .NET exe used to spawn agents with alternate creds.

> TikiSpawnAs.exe
  -d, --domain=VALUE         Domain (defaults to local machine)
  -u, --username=VALUE       Username
  -p, --password=VALUE       Password
  -b, --binary=VALUE         Binary to spawn & hollow
  -h, -?, --help             Show this help

TikiSpawnElevated

A .NET exe used to spawn a high integrity agent using the UAC Token Duplication bypass. Defunct in 1809 and above.

> TikiSpawnElevated.exe
  -b, --binary=VALUE         Binary to spawn & hollow
  -p, --pid=VALUE            Elevated PID to impersonate (optional)
  -h, -?, --help             Show this help

TikiService

A .NET Service Binary, allowing one to execute TikiTorch payloads remotely via the Service Control Manager (à la PsExec).

TikiCpl

Generates a Control Panel (.cpl) formatted DLL that executes gzipped base64 encoded shellcode from a resource file. Follow the instructions here to generate shellcode in the correct format.

TikiThings

A DLL that integrates AppLocker bypasses from AllTheThings.

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U TikiThings.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\regasm.exe /U TikiThings.dll
regsvr32 /s /u TikiThings.dll
regsvr32 /s TikiThings.dll
rundll32 TikiThings.dll,EntryPoint
odbcconf /s /a { REGSVR TikiThings.dll }
regsvr32 /s /n /i:"blah" TikiThings.dll

TikiVader

Like TikiLoader, a .NET Library that can be used as a reference by the other Tiki projects. It contains pre-canned functions for enumerating environmental variables such as current domain name and computer hostname, as a means of ensuring the TikiLoader only executes in your desired target environment. It's not an evasion tactic, but a safety one.

Aggressor

For Cobalt Strike users, the Aggressor directory contains TikiTorch.cna which provides various beacon commands to automate some TikiTorch tasks. These also require tools from my MiscTools repo.

Credits

Further Reading

S
Description
Automated archival mirror of github.com/rasta-mouse/TikiTorch
Readme GPL-3.0 424 KiB
Languages
C# 100%