210 likes | 354 Views
Team Operations. Collaborate with Armitage and Metasploit. Overview. Team Operations Teaming Features Architecture and Setup Session Passing Using External Tools Team Organization. Team Operations. Armitage Teaming. User Experience Single user-like Local control of Metasploit
E N D
Team Operations Collaborate with Armitage and Metasploit
Overview • Team Operations • Teaming Features • Architecture and Setup • Session Passing • Using External Tools • Team Organization
Armitage Teaming • User Experience • Single user-like • Local control of Metasploit • Teaming Features • Real Time Communication • Data Sharing • Session Sharing
Setup • Perform these steps on shared server… • Start Metasploit’s RPC daemon • msfrpcd -U username -P password –f • Start Deconfliction server • armitage --server attack_server_ip55553 username password • Connect clients!
Session Passing • Inject meterpreter into memory • Point at any multi/handleryou like • Uses: • Send session to a friend • Duplicate your access
Session Passing • Inject meterpreter into memory • Point at any multi/handleryou like • Uses: • Send session to a friend • Duplicate your access
Session Passing • Inject meterpreter into memory • Point at any multi/handleryou like • Uses: • Send session to a friend • Duplicate your access
External Tools • In a team environment, not everyone will use Armitage • Everyone can still benefit from Armitage’s accesses • Metasploit SOCKS proxy routes client traffic using pivot • Web browsers may use a proxy server to connect
Team Organization • Split team into roles • Attack • Multiple post-exploitation roles • Distribute attacks • Centralize post-exploitation
Team Organization • Use Armitage on big screen • Event log augments existingcommunication channel • External tools may play too(not everyone needs Armitage)
Summary • Team Operations • Teaming Features • Architecture and Setup • Session Passing • Using External Tools • Team Organization