Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature Request] Integration of TikiTorch #87

Open
NotoriousRebel opened this issue Sep 29, 2019 · 6 comments
Open

[Feature Request] Integration of TikiTorch #87

NotoriousRebel opened this issue Sep 29, 2019 · 6 comments
Assignees

Comments

@NotoriousRebel
Copy link

Feature Request or Bug
Feature Request

Describe the feature request or bug
Creating a task that would allow a launcher to do Inject into new process using TikiTorch
given that you know the PID of target process would be awesome :)

Expected behavior
The launcher is now under a different process such as svchost or explorer

@rasta-mouse
Copy link
Contributor

rasta-mouse commented Sep 29, 2019

AFAIK Covenant can't generate Grunt shellcode (yet?), it's why there are no process injection Tasks at all. Not sure what the timescales for that are, but once that's tackled I'd love to port the functionality over.

EDIT: I should also point out that this is possible to do manually: https://rastamouse.me/2019/08/covenant-donut-tikitorch/

@NotoriousRebel
Copy link
Author

NotoriousRebel commented Sep 29, 2019

@rasta-mouse I read your blog post <3 it's pretty amazing, that's why I created this post. I wonder if it would be possible to automate this with PowerShell once you have the GruntStager.exe assuming you have Donut and Tikitorch on the system.

@rasta-mouse
Copy link
Contributor

Perhaps, but it wouldn't exactly be elegant. Best just to roadmap the development properly IMO.

@NotoriousRebel
Copy link
Author

@cobbr how hard would this be?

@cobbr
Copy link
Owner

cobbr commented Sep 30, 2019

No clue, I'm not super familiar with TikiTorch to be honest. Once we have process injection/migration integrated, I'll definitely take a look!

@rasta-mouse
Copy link
Contributor

@cobbr TikiTorch is just a library of a few process injection / hollowing techniques. There's nothing really special about it - if the correct Windows APIs were in SharpSploit (for example), a Covenant Task could just recreate the same steps as a TikiTorch payload would.

@cobbr cobbr added this to the v0.7 milestone Oct 1, 2019
@cobbr cobbr removed this from the v0.7 milestone Aug 26, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants