GithubHelp home page GithubHelp logo

cn33liz / starfighters Goto Github PK

View Code? Open in Web Editor NEW
320.0 320.0 66.0 27 KB

A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.

JavaScript 48.09% Visual Basic 51.91%

starfighters's People

Contributors

cn33liz avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

starfighters's Issues

Some modules have functionality reduced

Hello and thanks for a great project.
I am testing this out in my lab where I have a Windows 7 VM and a Kali host with Empire 2.0.

I blocked powershell.exe with AppLocker rules and am successfully able to stage a connection using the JS script here. However, I ran into some issues with the module functionality of Empire. Most of the interesting modules pull data from the host via Powershell. Many of the enumeration modules, such as powershell/situational_awareness/network/powerview/get_gpo, do not work if powershell.exe is blocked.

Would it be helpful to maintain a list of modules that are confirmed working within the StarFighters environment?

View de-serialized object code

First off, thanks for releasing such an awesome pentesting tool! Is there a way to view the deserialized object code before running it?

AV prevents execution

o.CreateInstance(entry_class);

It's prevented from executing because of the string "EmpireHost." I tried with a different string and it seems to work.

I suggest instead of releasing the output as the code, release the entire setup, so we can generate our own payloads with randomized entry class names. Or maybe there is an even better way of dynamically generating the entry class? Perhaps this is outside of the scope for the project...

Using Symantec Endpoint Protection.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.