guardicore / guardicore/monkey

Investigate `pyWhisker`

Open
#3,765 0 comments 0 reactions 0 assignees View on GitHub
Exploit Plugins Spike
Dominant language
Python
Stars
7.1k
Forks
830
PR merge metrics
No merged PRs in 30d

Description

# Spike

## Objective
[pyWhisker](https://github.com/ShutdownRepo/pywhisker) allows manipulating the `msDS-KeyCredentialLink` attribute of a target user/computer to obtain control over it. Investigate if we can add this as a plugin.

## Scope
Time-boxed: 2.0d

## Output
A POC script and a new issue to add it as a plugin, if it can be used. An explanation if it can't.

## Resources
- https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.