Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

scp and file/tool transfer function #16

Open
tropChaud opened this issue Oct 2, 2024 · 0 comments
Open

scp and file/tool transfer function #16

tropChaud opened this issue Oct 2, 2024 · 0 comments
Assignees

Comments

@tropChaud
Copy link

tropChaud commented Oct 2, 2024

Are you open to adding scp and probably an associated new function for something like "file transfer" or "tool transfer" (likely T1570)? If so I'm happy to open a PR

Apparently used by CACTUS ransomware actors to distribute their encryptor after initial compromise of the environment: "The threat actors copied the executable file, labeled with the victim's ID, to the hosts via SCP and granted it execution rights. scp -t '/{Victim ID}"
https://www.bitdefender.com/blog/businessinsights/cactus-analyzing-a-coordinated-ransomware-attack-on-corporate-networks/

The -t flag appears more like a log artefact rather than a common execution parameter so I would focus on the command format provided in Atomic Red Team for example: https://www.reddit.com/r/vmware/comments/12qzrxg/auditing_vsphere_datastore_activities_download/

*Edited to provide Atomic Red Team link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants