Commit Graph

6120 Commits

Author SHA1 Message Date
Shreya Malviya 739a017e91 island: Remove API endpoints for standard environment 2021-09-01 16:19:32 +05:30
Shreya Malviya e4d75e25bd island: Remove standard environment 2021-09-01 16:16:32 +05:30
Shreya Malviya 7fe9d752fa cc: Remove StandardConfig in frontend 2021-09-01 16:06:36 +05:30
Shreya Malviya 6937a6b81a cc: Remove setNoAuth() fron RegisterPage.js 2021-09-01 16:04:05 +05:30
Shreya Malviya 3e453e8b2c cc: Remove 'I want anyone to access the island' button 2021-09-01 16:03:12 +05:30
Shreya Malviya 13b1904cf7
Merge pull request #1427 from guardicore/1246/powershell-documentation
Documentation for PowerShell exploiter
2021-09-01 15:11:39 +05:30
Mike Salvatore c83a0b4668 Docs: Reword PowerShell exploiter documentation 2021-08-31 12:21:08 -04:00
Mike Salvatore b96a0e74d9 Docs: Fix formatting of PowerShell exploit markdown 2021-08-31 11:36:58 -04:00
Shreya Malviya 24b6c751cb
Merge pull request #1436 from guardicore/1410/ut-autowindowsuser
Add unit test for deactivate and delete new auto windows user
2021-08-31 20:23:48 +05:30
Mike Salvatore e133baea09 Test: Skip test_new_user_delete_windows on Linux 2021-08-31 10:41:38 -04:00
Shreya Malviya 2f5e6b516a tests: Modify unit tests for AutoNewWindowsUser based on previous commit
changes
2021-08-31 19:35:06 +05:30
Shreya Malviya 8d14ff6385 agent: Move windows-only imports to the top of the file in
utils/windows/users.py
2021-08-31 19:31:04 +05:30
Mike Salvatore 86fd7351ad Island: Remove unused loggers 2021-08-31 09:57:32 -04:00
Mike Salvatore 96dee616df Agent: Remove unused loggers 2021-08-31 09:57:19 -04:00
VakarisZ d2e5828c3b Replace "LOG" naming convention with "logger" naming convention. 2021-08-31 09:51:34 -04:00
Mike Salvatore 51b5fc601a
Merge pull request #1437 from guardicore/fix-swimm-unit-pba
Add Swimm unit for adding a PBA
2021-08-31 09:44:38 -04:00
Shreya Malviya d118cdf3f5 travis: Update Swimm version 2021-08-31 12:49:57 +05:30
Shreya Malviya cae1206fbd swimm: Update exercise Add a new Post Breach Action (PBA) afMu3y3ny5lnrYFWl3EI 2021-08-31 12:34:40 +05:30
Shreya Malviya fc49ad341b swimm: Create exercise Add a new Post Breach Action (PBA) 2021-08-31 12:34:28 +05:30
Mike Salvatore d22c7813a5 BB: Switch the scanning order in tunneling tests
Because the SMB exploiter deploys the 32-bit agent, which will then
upgrade itself to 64-bit, it takes a long time between when exploitation
is successful and the agent calls home. By switching the order that
hosts are scanned in, this test runs approximately 25 seconds quicker
and allows us to reduce the `keep_tunnel_open_time` setting by 30
seconds.
2021-08-30 13:28:25 -04:00
Ilija Lazoroski 85316bcbb0 UT: Add test for deactive and delete new auto windows user 2021-08-30 16:10:14 +02:00
Mike Salvatore 9c352c1b1f Agent: Reformat long line in CommunicateAsBackdoorUser 2021-08-30 10:08:46 -04:00
VakarisZ 0635169362
Remove unused and broken package gathering feature on windows. (#1431)
Agent: Remove unused and broken package gathering feature on windows.
2021-08-30 09:56:34 -04:00
Mike Salvatore 00ccc3755d Move changelog entries from PR #1433 from v1.11.0 to unreleased 2021-08-30 09:46:24 -04:00
Mike Salvatore 09f14687d3 Fixed minor typos in CHANGELOG.md 2021-08-30 09:44:20 -04:00
Mike Salvatore 318e71bcb4
Merge pull request #1433 from guardicore/1410/remove-backdoor-pba
Remove Backdoor user PBA
2021-08-30 09:43:13 -04:00
Mike Salvatore 1bf3013fc2 Update changelog for PR #1433 2021-08-30 09:41:18 -04:00
Ilija Lazoroski e435894187 docs: Change the docs for PowerShell 2021-08-30 14:34:21 +02:00
Ilija Lazoroski 7aa230e9d0 UT: Renamed Communicate as new user 2021-08-30 14:22:23 +02:00
Ilija Lazoroski 10697934d6 Rename Communicate as new user to Communicate as backdoor user 2021-08-30 14:01:40 +02:00
Mike Salvatore 805ef70db1
Merge pull request #1425 from guardicore/powershell_exploiter
PowerShell Remoting exploiter refactor
2021-08-30 07:54:29 -04:00
Ilija Lazoroski 7e293ac16d Remove Backdoor user PBA 2021-08-30 13:46:07 +02:00
Mike Salvatore 02bd3efd2d
Merge pull request #1434 from guardicore/pba-use-random-pwd
Use random password for CommunicateAsNewUser PBA
2021-08-30 07:17:56 -04:00
Shreya Malviya deb037c617 tests: Add unit tests for communicate as back door user PBA 2021-08-30 16:21:22 +05:30
Shreya Malviya 0f2f39f0a0 CHANGELOG: Update with entry for random password for CommunicateAsNewUser PBA 2021-08-30 16:21:22 +05:30
Shreya Malviya f727e75697 agent: Use random password for CommunicateAsNewUser PBA 2021-08-30 16:21:22 +05:30
Shreya Malviya 54f80df1f4 bb: Remove extra line from end of file 2021-08-30 15:12:35 +05:30
Ilija Lazoroski e9ac64f108 docs: Add better documentation for powershell remoting exploiter 2021-08-27 11:18:16 +02:00
Mike Salvatore 98fcfde389
Merge pull request #1426 from guardicore/1246/config-template-bb-test
Add PowerShell config and bb test
2021-08-26 09:19:03 -04:00
Shreya Malviya 57109c11a9 cc: Change 'powershell' -> 'PowerShell' in issue overview in security report 2021-08-26 17:06:19 +05:30
Ilija Lazoroski 9a96e6ed39 Zoo: Refactor start and stop gcp machine functions 2021-08-26 10:35:22 +02:00
Mike Salvatore a80cd676b4 Common: Remove unused CredentialsError 2021-08-25 15:37:17 -04:00
Mike Salvatore c875aa349f Tests: Change test order/names in powershell_utils/test_utils.py 2021-08-25 15:33:46 -04:00
Mike Salvatore 8aedc2c391 Agent: Add pyinstaller hooks for pypsrp 2021-08-25 14:44:31 -04:00
Mike Salvatore 176828d458 Agent: Log exception if PowerShellExploiter fails to copy agent 2021-08-25 14:18:43 -04:00
Mike Salvatore 86d7879c31 Agent: Remove leading space from RUN_MONKEY string template 2021-08-25 13:33:03 -04:00
Mike Salvatore e70d1c714b Agent: Remove context manager from _authenticate()
Since the PowerShellExploiter's _authenticate() method returns the
client object, it doesn't make sense for it to be constructed in a
context manager.
2021-08-25 13:30:30 -04:00
Mike Salvatore b871398682 Agent: Add useful logging to powershell exploiter 2021-08-25 13:30:30 -04:00
Shreya Malviya 876cdbeffa island: Check if credential in exploit telemetry is `None` before processing it 2021-08-25 19:31:36 +05:30
Ilija Lazoroski e6ca0fd3b6 Zoo: Parallelize start and stop of gcp machines 2021-08-25 10:07:41 +02:00