Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug: script block logging bypass not working #4

Open
williamknows opened this issue Jan 23, 2021 · 5 comments
Open

Bug: script block logging bypass not working #4

williamknows opened this issue Jan 23, 2021 · 5 comments

Comments

@williamknows
Copy link

williamknows commented Jan 23, 2021

Config:

  • commit 3c3e059 (currently the latest) compiled with the default configuration for .NET 4.
  • Tested against Server 2016 and Windows 10 (from DetectionLab)
  • Execution via CNA script (import then execute of PowerView commands).

The script block logging bypass used no longer appears to work. I'm seeing a lot of 4104 logs for executed commands.

@mgeeky
Copy link
Owner

mgeeky commented Mar 12, 2021

Damn, that's unfortunate. I'll look into this as soon as I find a spare minute.

Thanks for this issue report. Will keep it open until I address it.

Regards,
Mariusz.

@S3cur3Th1sSh1t
Copy link

There was a patch for the first bypass. It’s written down here:

https://cobbr.io/ScriptBlock-Logging-Bypass.html

https://gist.github.com/cobbr/d8072d730b24fbae6ffe3aed8ca9c407

It was changed somewhere around November 2017. I got the gists bypass working two days ago ;-)

@mgeeky
Copy link
Owner

mgeeky commented Mar 14, 2021

Thanks @S3cur3Th1sSh1t for your heads-up! Makes it way much easier to fix that one. Will try to hunt it down in a matter of days.

Cheers Mate!
Mariusz.

@ghost
Copy link

ghost commented Sep 25, 2021

stracciatella-remote doesn't seem to work , the command still executes on localhost though.

stracciatella-remote -v remote ip adress + pipe name + command , here's the syntax I used, weird it still execute on localhost.
Any help ? :) thx

@mgeeky
Copy link
Owner

mgeeky commented May 17, 2022

This issue with Script Block Logging should be now addressed in the latest version. :)

Let me know if problem remains.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants