daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

initial-access.md (6816B)


      1 ---
      2 title: "Initial Access"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/access/initial-access.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/initial-access.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Initial Access
     12 
     13 > Initial Access Files in the context of a Red Team exercise refer to the set of files, scripts, executables, or documents used by the Red Team to initially infiltrate the target system or network. These files often contain malicious payloads or are designed to exploit specific vulnerabilities in order to establish a foothold in the target environment.
     14 
     15 ## Summary
     16 
     17 * [Complex Chains](#complex-chains)
     18 * [Container](#container)
     19 * [Payload](#payload)
     20     * [Binary Files](#binary-files)
     21     * [Code Execution Files](#code-execution-files)
     22     * [Embedded Files](#embedded-files)
     23 * [Code Signing](#code-signing)
     24 
     25 ## Complex Chains
     26 
     27 > DELIVERY(CONTAINER(TRIGGER + PAYLOAD + DECOY))
     28 
     29 * **DELIVERY**: means to deliver a pack full of files
     30     * HTML Smuggling, SVG Smuggling, Attachments
     31 * **CONTAINER**: archive bundling all infection dependencies
     32     * ISO/IMG, ZIP, WIM
     33 * **TRIGGER**: some way to run the payload
     34     * LNK, CHM, ClickOnce applications
     35 * **PAYLOAD**: the malware
     36     * Binary Files
     37     * Code Execution Files
     38     * Embedded Files
     39 * **DECOY**: used to continue pretext narration after detonating malware
     40     * Typically open PDF files
     41 
     42 Examples:
     43 
     44 * HTML SMUGGLING(PASSWORD PROTECTED ZIP + ISO(LNK + IcedID  + PNG)) used by [TA551/Storm-0303](https://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/)
     45 
     46 ## Container
     47 
     48 * **ISO/IMG** - can contain hidden files, gets **automounted** giving easy access to contained files (`powershell –c .\malware.exe`)
     49 * **ZIP** - can contain hidden files (locate ZIP + unpack it + change dir + run Malware)
     50 * **WIM** - Windows Image, builtin format used to deploy system features
     51 
     52     ```ps1
     53     # Mount/Unmount .WIM
     54     PS> Mount-WindowsImage -ImagePath myarchive.wim -Path "C:\output\path\to\extract" -Index 1
     55     PS> Dismount-WindowsImage -Path "C:\output\path\to\extract" -Discard
     56     ```
     57 
     58 * **7-zip, RAR, GZ** - should get a native support on Windows 11
     59 
     60 ## Trigger
     61 
     62 * **LNK**
     63 * **CHM**
     64 * **ClickOnce**
     65 
     66 ## Payload
     67 
     68 ### Binary Files
     69 
     70 These files can be executed directly on the system without any third party.
     71 
     72 * **.exe** file, executable file can be run with a click
     73 * **.dll** file, execute with `rundll32 main.dll,DllMain`
     74 
     75     ```c
     76     #define WIN32_LEAN_AND_MEAN
     77     #include <windows.h>
     78 
     79     extern "C" __declspec(dllexport)
     80     DWORD WINAPI MessageBoxThread(LPVOID lpParam) {
     81     MessageBox(NULL, "Hello world!", "Hello World!", NULL);
     82     return 0;
     83     }
     84 
     85     extern "C" __declspec(dllexport)
     86     BOOL APIENTRY DllMain(HMODULE hModule,
     87                         DWORD ul_reason_for_call,
     88                         LPVOID lpReserved) {
     89     switch (ul_reason_for_call) {
     90         case DLL_PROCESS_ATTACH:
     91         CreateThread(NULL, NULL, MessageBoxThread, NULL, NULL, NULL);
     92         break;
     93         case DLL_THREAD_ATTACH:
     94         case DLL_THREAD_DETACH:
     95         case DLL_PROCESS_DETACH:
     96         break;
     97     }
     98     return TRUE;
     99     }
    100     ```
    101 
    102 * **.cpl** file, same as a .dll file with Cplapplet export
    103 
    104     ```c
    105     #include "stdafx.h"
    106     #include <Windows.h>
    107 
    108     extern "C" __declspec(dllexport) LONG Cplapplet(
    109         HWND hwndCpl,
    110         UINT msg,
    111         LPARAM lParam1,
    112         LPARAM lParam2
    113     )
    114     {
    115         MessageBoxA(NULL, "Hey there, I am now your control panel item you know.", "Control Panel", 0);
    116         return 1;
    117     }
    118 
    119     BOOL APIENTRY DllMain( HMODULE hModule,
    120                         DWORD  ul_reason_for_call,
    121                         LPVOID lpReserved
    122                         )
    123     {
    124         switch (ul_reason_for_call)
    125         {
    126         case DLL_PROCESS_ATTACH:
    127         {
    128             Cplapplet(NULL, NULL, NULL, NULL);
    129         }
    130         case DLL_THREAD_ATTACH:
    131         case DLL_THREAD_DETACH:
    132         case DLL_PROCESS_DETACH:
    133             break;
    134         }
    135         return TRUE;
    136     }
    137     ```
    138 
    139 ### Code Execution Files
    140 
    141 * Word with Macro (.doc, .docm)
    142 * Excel library (.xll)
    143 * Excel macro-enabled add-in file (.xlam)
    144 
    145     ```ps1
    146     xcopy /Q/R/S/Y/H/G/I evil.ini %APPDATA%\Microsoft\Excel\XLSTART
    147     ```
    148 
    149 * WSF files (.wsf)
    150 * MSI installers (.msi)
    151 
    152     ```ps1
    153     powershell Unblock-File evil.msi; msiexec /q /i .\evil.msi 
    154     ```
    155 
    156 * MSIX/APPX app package (.msix, .appx)
    157 * ClickOnce (.application, .vsto, .appref-ms)
    158 * Powershell scripts (.ps1)
    159 * Windows Script Host scripts (.wsh, .vbs)
    160 
    161     ```ps1
    162     cscript.exe payload.vbs
    163     wscript payload.vbs
    164     wscript /e:VBScript payload.txt
    165     ```
    166 
    167 ### Embedded Files
    168 
    169 * ICS Calendar Invites with Embedded Files
    170 
    171 ## Code Signing
    172 
    173 Certificate can be **Expired**, **Revoked**, **Valid**.
    174 
    175 Many certificates leaked on the Internet and got re-used by Threat Actor.
    176 Some of them can be found on VirusTotal, with the query :  `content:{02 01 03 30}@4 AND NOT tag:peexe`
    177 
    178 In 2022, LAPSUS$ claimed responsibility for a cyberattack on NVIDIA, a major graphics card and AI technology manufacturer. As part of this attack, LAPSUS$ allegedly stole proprietary data from NVIDIA and threatened to leak it. The leak contained
    179 
    180 * Certificates can be password protected. Use [pfx2john.py](https://gist.github.com/tijme/86edd06c636ad06c306111fcec4125ba)
    181 
    182     ```ps1
    183     john --wordlist=/opt/wordlists/rockyou.txt --format=pfx pfx.hashes
    184     ```
    185 
    186 * Sign a binary with a certificate.
    187 
    188     ```ps1
    189     osslsigncode sign -pkcs12 certs/nvidia-2014.pfx -in mimikatz.exe -out generated/signed-mimikatz.exe -pass nv1d1aRules
    190     ```
    191 
    192 * The following files can be signed with a certificate
    193     * executables: .exe, .dll, .ocx, .xll, .wll
    194     * scripts: .vbs, .js, .ps1
    195     * installers: .msi, .msix, .appx, .msixbundle, .appxbundle
    196     * drivers: .sys
    197     * cabinets: .cab
    198     * ClickOnce: .application, .manifest, .vsto
    199 
    200 ## References
    201 
    202 * [Top 10 Payloads: Highlighting Notable and Trending Techniques - delivr.to](https://blog.delivr.to/delivr-tos-top-10-payloads-highlighting-notable-and-trending-techniques-fb5e9fdd9356)
    203 * [Executing Code as a Control Panel Item through an Exported Cplapplet Function - @spotheplanet](https://www.ired.team/offensive-security/code-execution/executing-code-in-control-panel-item-through-an-exported-cplapplet-function)
    204 * [Desperate Infection Chains - Multi-Step Initial Access Strategies by Mariusz Banach - x33fcon Youtube](https://youtu.be/CwNPP_Xfrts)
    205 * [Desperate Infection Chains - Multi-Step Initial Access Strategies by Mariusz Banach - x33fcon PDF](https://binary-offensive.com/files/x33fcon%20-%20Desperate%20Infection%20Chains.pdf)
    206 * [Red Macros Factory - https://binary-offensive.com/](https://binary-offensive.com/initial-access-framework)