| 1 | +Set-StrictMode -Version Latest |
| 2 | + |
| 3 | +$TestScriptRoot = Split-Path $MyInvocation.MyCommand.Path -Parent |
| 4 | +$ModuleRoot = Resolve-Path "$TestScriptRoot\..\..\" |
| 5 | +$ModuleManifest = "$ModuleRoot\AtomicTestHarnesses.psd1" |
| 6 | + |
| 7 | +Remove-Module [A]tomicTestHarnesses |
| 8 | +Import-Module $ModuleManifest -Force -ErrorAction Stop |
| 9 | + |
| 10 | +Describe 'Invoke-ATHInjectedThread' { |
| 11 | + BeforeAll { |
| 12 | + $Help = Get-Help -Name Invoke-ATHInjectedThread -Full |
| 13 | + |
| 14 | + $ExpectedTechniqueID = $null |
| 15 | + |
| 16 | + if ($Help.Synopsis.Split("`r`n")[-1] -match '^(?-i:Technique ID: )(?<TechniqueID>\S+) (?<TechniqueDescription>\(.+\))$') { |
| 17 | + $ExpectedTechniqueID = $Matches['TechniqueID'] |
| 18 | + } |
| 19 | + } |
| 20 | + |
| 21 | + Context 'Validating error conditions' -Tag 'Unit', 'T1055.002' { |
| 22 | + It 'should execute custom position-independent code' -Tag 'Unit', 'T1055.002' { |
| 23 | + $Result = Invoke-ATHInjectedThread -PositionIndependentCodeBytes @(0x90, 0x90, 0x90, 0xC3) # NOP, NOP, NOP, RET |
| 24 | + |
| 25 | + $Result | Should -Not -BeNullOrEmpty |
| 26 | + |
| 27 | + $Result.TechniqueID | Should -BeExactly $ExpectedTechniqueID |
| 28 | + $Result.TestSuccess | Should -BeNullOrEmpty |
| 29 | + $Result.TestGuid | Should -Not -BeNullOrEmpty |
| 30 | + $Result.InjectedCodeBytes | Should -Not -BeNullOrEmpty |
| 31 | + $Result.InjectedCodeHash | Should -BeExactly '97E3BFAD17932F638A894351239CA24CB76467E080C5B268307547D36366FE10' |
| 32 | + $Result.SourceProcessId | Should -Be $PID |
| 33 | + $Result.SourceExecutablePath | Should -Not -BeNullOrEmpty |
| 34 | + $Result.SourceCommandLine | Should -Not -BeNullOrEmpty |
| 35 | + $Result.TargetProcessId | Should -Not -BeNullOrEmpty |
| 36 | + $Result.TargetExecutablePath | Should -Match 'notepad\.exe$' |
| 37 | + $Result.TargetCommandLine | Should -BeExactly 'notepad.exe' |
| 39 | + $Result.TargetProcessAccessValue | Should -Be 1082 |
| 40 | + $Result.TargetBaseAddressHex | Should -Match '^[0-9A-F]{16}$' |
| 41 | + $Result.TargetAllocationPageProtect | Should -BeExactly 'PAGE_EXECUTE_READWRITE' |
| 42 | + $Result.TargetAllocationPageProtectValue | Should -Be 64 |
| 43 | + $Result.TargetThreadId | Should -Not -BeNullOrEmpty |
| 44 | + $Result.TargetChildProcessId | Should -BeNullOrEmpty |
| 45 | + $Result.TargetChildProcessCommandLine | Should -BeNullOrEmpty |
| 46 | + } |
| 47 | + |
| 48 | + It 'should inject into itself (the current process)' -Tag 'Unit', 'T1055.002' { |
| 49 | + $Result = Invoke-ATHInjectedThread -ProcessId $PID |
| 50 | + |
| 51 | + $Result | Should -Not -BeNullOrEmpty |
| 52 | + |
| 53 | + $Result.TechniqueID | Should -BeExactly $ExpectedTechniqueID |
| 54 | + $Result.TestSuccess | Should -BeTrue |
| 55 | + $Result.TestGuid | Should -Not -BeNullOrEmpty |
| 56 | + $Result.InjectedCodeBytes | Should -Not -BeNullOrEmpty |
| 57 | + $Result.InjectedCodeHash | Should -Not -BeNullOrEmpty |
| 58 | + $Result.SourceProcessId | Should -Be $PID |
| 59 | + $Result.SourceExecutablePath | Should -BeExactly $Result.TargetExecutablePath |
| 60 | + $Result.SourceCommandLine | Should -BeExactly $Result.TargetCommandLine |
| 61 | + $Result.TargetProcessId | Should -Be $PID |
| 62 | + $Result.TargetExecutablePath | Should -Not -BeNullOrEmpty |
| 63 | + $Result.TargetCommandLine | Should -Not -BeNullOrEmpty |
| 65 | + $Result.TargetProcessAccessValue | Should -Be 1082 |
| 66 | + $Result.TargetBaseAddressHex | Should -Match '^[0-9A-F]{16}$' |
| 67 | + $Result.TargetAllocationPageProtect | Should -BeExactly 'PAGE_EXECUTE_READWRITE' |
| 68 | + $Result.TargetAllocationPageProtectValue | Should -Be 64 |
| 69 | + $Result.TargetThreadId | Should -Not -BeNullOrEmpty |
| 70 | + $Result.TargetChildProcessId | Should -Not -BeNullOrEmpty |
| 71 | + $Result.TargetChildProcessCommandLine | Should -Not -BeNullOrEmpty |
| 72 | + } |
| 73 | + |
| 74 | + It 'should not inject into a non-existant process ID' -Tag 'Unit', 'T1055.002' { |
| 75 | + { Invoke-ATHInjectedThread -ProcessId 1 -ErrorAction Stop } | Should -Throw |
| 76 | + } |
| 77 | + |
| 78 | + It 'should not accept an empty array of position-independent code' -Tag 'Unit', 'T1055.002' { |
| 79 | + { Invoke-ATHInjectedThread -PositionIndependentCodeBytes @() -ErrorAction Stop } | Should -Throw |
| 80 | + } |
| 81 | + |
| 82 | + It 'should fail to inject when the template notepad.exe target fails to launch' -Tag 'Unit', 'T1055.002' { |
| 83 | + Mock Invoke-CimMethod { return @{ ReturnValue = 1 } } |
| 84 | + |
| 85 | + { Invoke-ATHInjectedThread -ErrorAction Stop } | Should -Throw |
| 86 | + } |
| 87 | + |
| 88 | + It 'should not have access to inject into the System process' -Tag 'Unit', 'T1055.002' { |
| 89 | + { Invoke-ATHInjectedThread -ProcessId 4 -ErrorAction Stop } | Should -Throw |
| 90 | + } |
| 91 | + |
| 92 | + It 'should not inject into a 32-bit process' -Tag 'Unit', 'T1055.002' { |
| 93 | + $Wow64Notepad = Start-Process -FilePath $Env:windir\SysWOW64\notepad.exe -WindowStyle Hidden -PassThru |
| 94 | + |
| 95 | + { $Wow64Notepad | Invoke-ATHInjectedThread -ErrorAction Stop } | Should -Throw |
| 96 | + |
| 97 | + $Wow64Notepad | Stop-Process -Force |
| 98 | + } |
| 99 | + |
| 100 | + It 'should indicate that the powershell.exe child process failed to launch' -Tag 'Unit', 'T1055.002' { |
| 101 | + Mock Wait-Event { return $null } |
| 102 | + |
| 103 | + { Invoke-ATHInjectedThread -ErrorAction Stop } | Should -Throw |
| 104 | + } |
| 105 | + } |
| 106 | + |
| 107 | + Context 'Expected artifacts and behaviors when exercising the attack technique' -Tag 'Technique', 'T1055.002' { |
| 108 | + BeforeAll { |
| 109 | + $Script:FixedTestGuid = 'aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa' |
| 110 | + |
| 111 | + $Script:TargetNotepadProc = Start-Process -FilePath $Env:windir\System32\notepad.exe -WindowStyle Hidden -PassThru |
| 112 | + } |
| 113 | + |
| 114 | + It 'should inject into a process (IsRWXMemory: <IsRWXMemory>, MinimumProcessAccess: <MinimumProcessAccess>, InjectIntoSpecificProcess: <InjectIntoSpecificProcess>)' -Tag 'Technique', 'T1055.002' { |
| 115 | + $Arguments = @{} |
| 116 | + |
| 117 | + if ($IsRWXMemory) { |
| 118 | + $ExpectedPageProtection = 'PAGE_EXECUTE_READWRITE' |
| 119 | + $ExpectedPageProtectionValue = 64 |
| 120 | + |
| 121 | + $Arguments['MemoryProtectionType'] = 'ReadWriteExecute' |
| 122 | + } else { |
| 123 | + $ExpectedPageProtection = 'PAGE_EXECUTE_READ' |
| 124 | + $ExpectedPageProtectionValue = 32 |
| 125 | + |
| 126 | + $Arguments['MemoryProtectionType'] = 'ReadExecute' |
| 127 | + } |
| 128 | + |
| 129 | + if ($MinimumProcessAccess) { |
| 131 | + $ExpectedProcessAccessValue = 1082 |
| 132 | + |
| 133 | + $Arguments['ProcessAccessType'] = 'MinimumAccess' |
| 134 | + } else { |
| 135 | + $ExpectedProcessAccess = 'PROCESS_ALL_ACCESS' |
| 136 | + $ExpectedProcessAccessValue = 2097151 |
| 137 | + |
| 138 | + $Arguments['ProcessAccessType'] = 'AllAccess' |
| 139 | + } |
| 140 | + |
| 141 | + if ($InjectIntoSpecificProcess) { |
| 142 | + $ExpectedProcessId = $TargetNotepadProc.Id |
| 143 | + |
| 144 | + $Arguments['ProcessId'] = $TargetNotepadProc.Id |
| 145 | + } else { |
| 146 | + $ExpectedProcessId = $null |
| 147 | + } |
| 148 | + |
| 149 | + $Result = Invoke-ATHInjectedThread -TestGuid $FixedTestGuid @Arguments |
| 150 | + |
| 151 | + $Result | Should -Not -BeNullOrEmpty |
| 152 | + |
| 153 | + $Result.TechniqueID | Should -BeExactly $ExpectedTechniqueID |
| 154 | + $Result.TestSuccess | Should -BeTrue |
| 155 | + $Result.TestGuid | Should -BeExactly $FixedTestGuid |
| 156 | + $Result.InjectedCodeBytes | Should -Not -BeNullOrEmpty |
| 157 | + $Result.InjectedCodeHash | Should -Not -BeNullOrEmpty |
| 158 | + $Result.SourceProcessId | Should -Be $PID |
| 159 | + $Result.SourceExecutablePath | Should -Not -BeNullOrEmpty |
| 160 | + $Result.SourceCommandLine | Should -Not -BeNullOrEmpty |
| 161 | + |
| 162 | + if ($InjectIntoSpecificProcess) { |
| 163 | + $Result.TargetProcessId | Should -Be $ExpectedProcessId |
| 164 | + } else { |
| 165 | + $Result.TargetProcessId | Should -Not -BeNullOrEmpty |
| 166 | + } |
| 167 | + |
| 168 | + $Result.TargetExecutablePath | Should -Match 'notepad\.exe' |
| 169 | + $Result.TargetCommandLine | Should -Match 'notepad\.exe' |
| 170 | + $Result.TargetProcessAccess | Should -BeExactly $ExpectedProcessAccess |
| 171 | + $Result.TargetProcessAccessHex | Should -BeExactly $ExpectedProcessAccessHex |
| 172 | + $Result.TargetBaseAddressHex | Should -Match '^[0-9A-F]{16}$' |
| 173 | + $Result.TargetAllocationPageProtect | Should -BeExactly $ExpectedPageProtection |
| 174 | + $Result.TargetAllocationPageProtectValue | Should -Be $ExpectedPageProtectionValue |
| 175 | + $Result.TargetThreadId | Should -Not -BeNullOrEmpty |
| 176 | + $Result.TargetChildProcessId | Should -Not -BeNullOrEmpty |
| 177 | + $Result.TargetChildProcessCommandLine | Should -Match $FixedTestGuid |
| 178 | + } -TestCases @( |
| 179 | + @{ IsRWXMemory = $False; MinimumProcessAccess = $False; InjectIntoSpecificProcess = $False }, |
| 180 | + @{ IsRWXMemory = $True; MinimumProcessAccess = $False; InjectIntoSpecificProcess = $False }, |
| 181 | + @{ IsRWXMemory = $False; MinimumProcessAccess = $True; InjectIntoSpecificProcess = $False }, |
| 182 | + @{ IsRWXMemory = $True; MinimumProcessAccess = $True; InjectIntoSpecificProcess = $False }, |
| 183 | + @{ IsRWXMemory = $False; MinimumProcessAccess = $False; InjectIntoSpecificProcess = $True }, |
| 184 | + @{ IsRWXMemory = $True; MinimumProcessAccess = $False; InjectIntoSpecificProcess = $True }, |
| 185 | + @{ IsRWXMemory = $False; MinimumProcessAccess = $True; InjectIntoSpecificProcess = $True }, |
| 186 | + @{ IsRWXMemory = $True; MinimumProcessAccess = $True; InjectIntoSpecificProcess = $True } |
| 187 | + ) |
| 188 | + |
| 189 | + AfterAll { |
| 190 | + $Script:TargetNotepadProc | Stop-Process -Force |
| 191 | + } |
| 192 | + } |
| 193 | +} |
0 commit comments