From ef821f75e210b1be98f88bc076408ef0fd4c9666 Mon Sep 17 00:00:00 2001 From: Mike Salvatore Date: Thu, 15 Sep 2022 08:01:39 -0400 Subject: [PATCH] Agent: Add agent source to CredentialsStolenEvent in ZerologonExploiter --- monkey/infection_monkey/exploit/zerologon.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/monkey/infection_monkey/exploit/zerologon.py b/monkey/infection_monkey/exploit/zerologon.py index d9e48d5a0..d5a58af30 100644 --- a/monkey/infection_monkey/exploit/zerologon.py +++ b/monkey/infection_monkey/exploit/zerologon.py @@ -26,6 +26,7 @@ from infection_monkey.exploit.zerologon_utils.vuln_assessment import get_dc_deta from infection_monkey.exploit.zerologon_utils.wmiexec import Wmiexec from infection_monkey.i_puppet import ExploiterResultData from infection_monkey.utils.capture_output import StdoutCapture +from infection_monkey.utils.ids import get_agent_id from infection_monkey.utils.threading import interruptible_iter logger = logging.getLogger(__name__) @@ -310,6 +311,7 @@ class ZerologonExploiter(HostExploiter): self, extracted_credentials: Sequence[Credentials] ) -> None: credentials_stolen_event = CredentialsStolenEvent( + source=get_agent_id(), tags=ZEROLOGON_EVENT_TAGS, stolen_credentials=extracted_credentials, )