PBSC CyberWeek 2022 PowerShell Empire Demo

Поділитися
Вставка

КОМЕНТАРІ • 15

  • @samsepoil2111
    @samsepoil2111 Рік тому +2

    This was a great demonstration. Thanks!

  • @stanislavsmetanin1307
    @stanislavsmetanin1307 9 місяців тому

    Would be nice to see a showcase how EMPIRE works under the hood. For instance: What is it doing when prevesc/bypassuac happens.

  • @papimbodjpm10
    @papimbodjpm10 11 місяців тому

    Nice it's getting experience for that but… I want to know if you get the Wifi IP address you can get any user you want even Android?

  • @bmkay
    @bmkay Рік тому +1

    Thank you for making this video. Can you explain again the distinction between the BindIP and the HostIP in the listener? Is the distinction because you're using a C2 server with a client on different systems? My pentest training lab is on a local LAN, so I usually leave the BindIP blank. I want to know what situations would require the BindIP.

    • @BeariumNetworks
      @BeariumNetworks  Рік тому

      In my lab environment, I have multiple routers segmenting the network, so the bind IP is being used so the payload routes properly and hits my attacking machine. That 10.4.x.x address could be considered over the internet based on how my lab is configured.

  • @Chinmoy-bf6cz
    @Chinmoy-bf6cz Рік тому

    Bro, how can we use it in WAN... And how to port forward and which port forward method we should use with empire please reply..

  • @ГрафСмерть
    @ГрафСмерть 8 місяців тому

    agent don't do feedback, just not work........ I'VE BEEN TRYING TO FIGURE OUT WHAT I'M DOING WRONG FOR HALF A YEAR NOW, BUT NO MATTER HOW HARD I TRY, NOTHING HELPS!!!! HELP MEEEEEEEEEEEEEEE

    • @lafang.xcix_v
      @lafang.xcix_v 6 місяців тому

      Hey, could you explain to me your error or what's going wrong, I could explain

  • @bradtopler8559
    @bradtopler8559 2 роки тому

    Hi. Very informative video, but it does not work in real life. If you try to run stager, you will encounter a problem. Windows antivirus will block you. Also, even if you obfuscate your code, it will trigger an AMSI level lockout. How do you fix this?

    • @tirtharajkarmakar1192
      @tirtharajkarmakar1192 Рік тому

      I think the best way of doing this is using a rubber ducky.... Firstly use some ducky script to stop the antivirus services and then set the code....
      This is my opinion, what about yours?

    • @BeariumNetworks
      @BeariumNetworks  Рік тому +1

      Well, fortunately windows defender is patched to protect from this! The demo was for a class project to demo how a poorly patched environment could be easily attacked.

    • @BeariumNetworks
      @BeariumNetworks  Рік тому

      @@tirtharajkarmakar1192 That could work. Though with physical access, you should be able to get most anything done!

  • @srdandordevic2202
    @srdandordevic2202 Рік тому +1

    yea bud your defender it off

    • @BeariumNetworks
      @BeariumNetworks  Рік тому

      Yep, it was demo regarding unsecured environments. This was a video made for a class project to demonstrate how badly a poorly patched system can be infiltrated.

  • @maulanamalik8322
    @maulanamalik8322 11 місяців тому

    any github link to this tools?