Giter VIP home page Giter VIP logo

kaiser's Introduction

Kaiser

File-less persistence, attacks and anti-forensic capabilities (Windows 7 32-bit).

NOTE: This project was NOT designed to evade AV detection.

Related paper: https://github.com/NtRaiseHardError/NtRaiseHardError.github.io/blob/master/_posts/2018-12-06-Anti-forensic-Malware-and-File-less-Malware.md

This project is discontinued.

How to Build/Use:

  1. Compile Kaiser.dll in Release mode
  2. Upload Kaiser.dll such that it can be directly downloaded as a raw binary
  3. Update the BuildKaiser.ps1 script to include the URL for Kaiser.dll
  4. Run BuildKaiser.ps1 to build the Payload.ps1 script
  5. Upload the Payload.ps1 script such that it can be directly downloaded as raw text
  6. Update the BuildKaiser.ps1 script to include the URL of Payload.ps1
  7. Run BuildKaiser.ps1 to build the Installer.ps1 script
  8. Run the Installer.ps1 script with administrative privileges on the target machine

Known bugs:

  • Threaded XxxNetSend sends will buffer (reason unknown)
  • PurgeXxx functions are not guaranteed to work (perhaps this is because it uses ShellExecuteEx
  • More?

TODO

  • CommandPrintStatus to print the status of Kaiser?
  • Convert functions in firewall.c to WinAPI
  • [OPTIONAL] Make C2 connection loop until established
  • Convert Functions in registry.c to WinAPI
  • Send debugging warnings/errors back to C2
  • Make PurgeProcessMonitor asynchronous (IWbemServices::ExecNotificationQueryAsync)

kaiser's People

Contributors

ntraiseharderror avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.