Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Development #14

Merged
merged 75 commits into from
Sep 3, 2019
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
7e759d5
Update .travis.yml
killswitch-GUI Aug 18, 2019
7a01a16
Update .travis.yml
killswitch-GUI Aug 18, 2019
9b3d9fb
Update .travis.yml
killswitch-GUI Aug 18, 2019
85a1505
Update .travis.yml
killswitch-GUI Aug 18, 2019
1df04e2
Update .travis.yml
killswitch-GUI Aug 18, 2019
4a22001
Update .travis.yml
killswitch-GUI Aug 18, 2019
dd59c8c
Update .travis.yml
killswitch-GUI Aug 18, 2019
59b61ba
Update .travis.yml
killswitch-GUI Aug 18, 2019
eb06891
Update .travis.yml
killswitch-GUI Aug 18, 2019
7770d29
Update .travis.yml
killswitch-GUI Aug 18, 2019
325b8c3
Update .travis.yml
killswitch-GUI Aug 18, 2019
2274376
Update .travis.yml
killswitch-GUI Aug 18, 2019
bbf8098
Update .travis.yml
killswitch-GUI Aug 18, 2019
56af9be
Update .travis.yml
killswitch-GUI Aug 18, 2019
496f378
Update .travis.yml
killswitch-GUI Aug 18, 2019
7825378
Update .travis.yml
killswitch-GUI Aug 18, 2019
896667b
Update .travis.yml
killswitch-GUI Aug 18, 2019
1fbd039
Update .travis.yml
killswitch-GUI Aug 18, 2019
d1fe93d
Update .travis.yml
killswitch-GUI Aug 18, 2019
fcbd574
Update .travis.yml
killswitch-GUI Aug 18, 2019
177629a
Update .travis.yml
killswitch-GUI Aug 18, 2019
ef5ea4f
Update .travis.yml
killswitch-GUI Aug 18, 2019
1c0f7ec
Update .travis.yml
killswitch-GUI Aug 18, 2019
c31e7ac
Update .travis.yml
killswitch-GUI Aug 18, 2019
4e6a83f
Update README.md
killswitch-GUI Aug 18, 2019
3477624
Update .travis.yml
killswitch-GUI Aug 18, 2019
d4c254e
Update .travis.yml
killswitch-GUI Aug 18, 2019
967953b
Update .travis.yml
killswitch-GUI Aug 18, 2019
99db68b
Update .travis.yml
killswitch-GUI Aug 18, 2019
6bee712
Update .travis.yml
killswitch-GUI Aug 18, 2019
4e14e9f
Update .travis.yml
killswitch-GUI Aug 18, 2019
7b3130d
Update .travis.yml
killswitch-GUI Aug 18, 2019
877f160
Update .travis.yml
killswitch-GUI Aug 18, 2019
7a890ce
Update .travis.yml
killswitch-GUI Aug 18, 2019
b80a31d
Update .travis.yml
killswitch-GUI Aug 18, 2019
7ee10a2
Update .travis.yml
killswitch-GUI Aug 18, 2019
64931da
Merge pull request #11 from obscuritylabs/killswitch-GUI-patch-1
killswitch-GUI Aug 18, 2019
2199d15
Create README.md
killswitch-GUI Aug 19, 2019
e952eaa
Create README.md
killswitch-GUI Aug 19, 2019
53e82bf
Create README.md
killswitch-GUI Aug 19, 2019
897f232
Create README.md
killswitch-GUI Aug 19, 2019
80061ea
Update README.md
killswitch-GUI Aug 19, 2019
056dff0
Update README.md
killswitch-GUI Aug 19, 2019
49fb2f1
Update README.md
killswitch-GUI Aug 19, 2019
f57f242
Update README.md
killswitch-GUI Aug 19, 2019
0be0d23
Update README.md
killswitch-GUI Aug 19, 2019
87307f0
Update README.md
killswitch-GUI Aug 19, 2019
8ed3072
Create ISSUE_TEMPLATE.md
killswitch-GUI Aug 19, 2019
d0aa52f
Add files via upload
killswitch-GUI Aug 19, 2019
c255f4e
Update README.md
killswitch-GUI Aug 19, 2019
fa21b0c
Update README.md
killswitch-GUI Aug 19, 2019
8413771
Update README.md
killswitch-GUI Aug 19, 2019
fb78a67
Update README.md
killswitch-GUI Aug 19, 2019
aad6fb5
Update Pipfile
killswitch-GUI Aug 19, 2019
02c6cac
Update README.md
killswitch-GUI Sep 2, 2019
9245f8d
HastyStroke
killswitch-GUI Sep 2, 2019
9b0680c
Update README.md
killswitch-GUI Sep 2, 2019
0140bb4
Update README.md
killswitch-GUI Sep 2, 2019
0e03d31
Update .travis.yml
killswitch-GUI Sep 3, 2019
85fe31a
Create README.md
killswitch-GUI Sep 3, 2019
3143c11
Create README.md
killswitch-GUI Sep 3, 2019
1917f43
Update README.md
killswitch-GUI Sep 3, 2019
9b89789
update tooling
killswitch-GUI Sep 3, 2019
b92daa3
update tooling
killswitch-GUI Sep 3, 2019
5135e1d
Update README.md
killswitch-GUI Sep 3, 2019
99cfcd0
Update README.md
killswitch-GUI Sep 3, 2019
37589ac
Update README.md
killswitch-GUI Sep 3, 2019
86f1270
Update README.md
killswitch-GUI Sep 3, 2019
db17a73
Update README.md
killswitch-GUI Sep 3, 2019
3169233
Update README.md
killswitch-GUI Sep 3, 2019
1b79f53
1.0.0
killswitch-GUI Sep 3, 2019
14abd7e
Merge branch 'dev' of https://github.com/obscuritylabs/HastySeries in…
killswitch-GUI Sep 3, 2019
ff5ec9c
Merge pull request #13 from obscuritylabs/dev
killswitch-GUI Sep 3, 2019
e8e1cdd
Merge branch 'master' into development
killswitch-GUI Sep 3, 2019
46ad884
cleanup
killswitch-GUI Sep 3, 2019
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added .github/2019-08-18 21_59_48-Command Prompt.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/2019-09-03 00_41_38-Command Prompt.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions .github/ISSUE_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@

14 changes: 14 additions & 0 deletions .travis.yml
Original file line number Diff line number Diff line change
@@ -1,2 +1,16 @@
os: windows
language: shell

env:
- MSBUILD_PATH="/C/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/MSBuild/15.0/Bin"

install:
- choco install sysinternals python2 python3 7zip
- psexec -s powershell.exe -command 'Add-WindowsCapability –Online -Name NetFx3~~~~'

before_script:
- export PATH=$MSBUILD_PATH:$PATH

script:
- msbuild.exe HastyArp/HastyArp.sln //m -p:Configuration=Release
- ls -lisa
52 changes: 52 additions & 0 deletions HastyArp/README.md
Original file line number Diff line number Diff line change
@@ -1 +1,53 @@
# HastyArp
A post-explotation ARP.exe command implemented in pure C#.

## Build
All binaries in HastySeries are built targeting .NET 3.5, for windows 7+ support. The following build env should be used:

* Windows 10 - 1803
* Visual Studio 2017
* .NET 3.5
* `choco install sysinternals` or strings from SysInternals in your current path

ALL HastySeries compiled binaries can be found on the github page with the most recent releases. NOTE: THESE have many static sigs.. dont drop to disk unless you are sure they are cleared via PSP testing.

## Operate
### Command Examples:
```cmd
C:\Users\rt\Desktop\HastySeries\bin\Release>HastyArp.exe
```
### Expected Output:
```cmd
Interface: INT: 1 --- TYPE: 4 --- IP: 224.0.0.22
224.0.0.22 00-00-00-00-00-00
239.255.255.250 00-00-00-00-00-00
Interface: INT: 3 --- TYPE: 4 --- IP: 224.0.0.22
224.0.0.22 01-00-5E-00-00-16
Interface: INT: 7 --- TYPE: 3 --- IP: 192.168.137.2
192.168.137.2 00-50-56-E9-02-48
192.168.137.254 00-50-56-E3-0F-55
192.168.137.255 FF-FF-FF-FF-FF-FF
224.0.0.22 01-00-5E-00-00-16
224.0.0.251 01-00-5E-00-00-FB
224.0.0.252 01-00-5E-00-00-FC
255.255.255.255 FF-FF-FF-FF-FF-FF
Interface: INT: 8 --- TYPE: 2 --- IP: 169.254.169.254
169.254.169.254 00-00-00-00-00-00
169.254.241.22 00-00-00-00-00-00
169.254.255.255 FF-FF-FF-FF-FF-FF
224.0.0.22 01-00-5E-00-00-16
224.0.0.251 01-00-5E-00-00-FB
224.0.0.252 01-00-5E-00-00-FC
239.255.255.250 01-00-5E-7F-FF-FA
255.255.255.255 FF-FF-FF-FF-FF-F
```

## OpSec
### Strings
To prevent some basic string matching, some basic precautions where taken. of course this is a example and if OpSec is upmost concern change static key and use the `HastyFixup` string fixup project to build new strings before re-compile.

1) All strings are XOR'd with a static key
2) All strings are than encoded with Base64
3) Strings are decoded at execution
4) Strings are XOR'd with static key
5) String is presented to console
43 changes: 43 additions & 0 deletions HastyDrives/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# HastyDrives
A post-explotation command implemented in pure C# to list all drives and details that may be useful to a operator.

## Build
All binaries in HastySeries are built targeting .NET 3.5, for windows 7+ support. The following build env should be used:

* Windows 10 - 1803
* Visual Studio 2017
* .NET 3.5
* `choco install sysinternals` or strings from SysInternals in your current path

ALL HastySeries compiled binaries can be found on the github page with the most recent releases. NOTE: THESE have many static sigs.. dont drop to disk unless you are sure they are cleared via PSP testing.

## Operate
### Command Examples:
```cmd
C:\Users\rt\Desktop\HastySeries\bin\Release>HastyDrives.exe
```
### Expected Output:
```cmd
*-------------------------HastyDrives-------------------------*
|Drive C:\
| Drive type: Fixed
| Volume label:
| File system: NTFS
| Available space to current user: 21268123648 bytes
| Total available space: 21268123648 bytes
| Total size of drive: 63778582528 bytes
*--------------------------------------------------------------*
|Drive D:\
| Drive type: CDRom
*--------------------------------------------------------------*
```

## OpSec
### Strings
To prevent some basic string matching, some basic precautions where taken. of course this is a example and if OpSec is upmost concern change static key and use the `HastyFixup` string fixup project to build new strings before re-compile.

1) All strings are XOR'd with a static key
2) All strings are than encoded with Base64
3) Strings are decoded at execution
4) Strings are XOR'd with static key
5) String is presented to console
30 changes: 28 additions & 2 deletions HastyDump/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,33 @@ All binaries in HastySeries are built targeting .NET 3.5, for windows 7+ support
ALL HastySeries compiled binaries can be found on the github page with the most recent releases. NOTE: THESE have many static sigs.. dont drop to disk unless you are sure they are cleared via PSP testing.

## Operate

### Command Examples:
```cmd
C:\Users\rt\Desktop\HastySeries\bin\Release>HastyDump.exe -help
C:\Users\rt\Desktop\HastySeries\bin\Release>HastyDump.exe 13028 "C:\\Users\\rt\\Desktop\\test.bin"
```
### Expected Output:
```cmd
[*] RUNTIME TARGET CHECKS:
OperatingSystem Version: Microsoft Windows NT 6.2.9200.0
Target MachineName: DESKTOP-1VRIH74
Target DomainName: DESKTOP-1VRIH74
Target UserName: rt
Target Time Zone: Pacific Standard Time
Target Time: 8/18/2019 9:56:55 PM
Target ProcessorCount: 4
[*] SUCCESS: Obtained process image name
[*] SUCCESS: Obtained process image name
[*] INFO: target image: \Device\HarddiskVolume4\Windows\System32\cmd.exe
[*] SUCCESS: Creating file stream/handle: C:\\Users\\rt\\Desktop\\test.bin
[*] IMAGE TARGET DETAILS:
Image size: 129872 KB
Image location: C:\Users\rt\Desktop\test.bin
[*] INFO: Close file handle of: C:\\Users\\rt\\Desktop\\test.bin
[*] INFO: Close process handle of process ID: 13028
```
### Example Screenshot:
![2019-08-18 21_59_48-Command Prompt](https://user-images.githubusercontent.com/8761706/63241898-0e0da380-c25e-11e9-8c4d-a50a7688b600.png)

## OpSec
### Strings
Expand All @@ -22,4 +48,4 @@ To prevent some basic string matching, some basic precautions where taken. of co
2) All strings are than encoded with Base64
3) Strings are decoded at execution
4) Strings are XOR'd with static key
5) String is presented to console
5) String is presented to console
11 changes: 0 additions & 11 deletions HastyFixup/Pipfile

This file was deleted.

Loading