Skip to main content

Linux IR UAC tool Installation

 Linux incident response UAC tool Installation...


Download link of uac tool:

https://github.com/tclahr/uac

https://github.com/tclahr/uac/releases

This tool does not need to be installed on the target/compromised system. Just ship the tool there and collect artefacts. Please download the latest release of the tool from the above link. You will get the tool under Assets section for example named as: uac-3.3.0.tar.gz


Setting up uac tool:

Taking the tool to the victim/compromised machine:

scp uac-3.3.0.tar.gz lab@192.168.10.135:/tmp

scp uac-3.3.0.tar.gz lab@192.168.10.135: (If you do not give /tmp then the tool will be placed under that lab user home directory. Now provide the password of the target system)

ssh lab@192.168.10.135 (Access the target system with creds)

cd /tmp

tar zxf uac-3.3.0.tar.gz

cd uac-3.3.0/

sudo ./uac -p ir_triage /root (Run the tool using root user or with sudo privilege. -p for profile. This is default profile. Later we will see how to make customized profile. Captured artifacts will be saved on /root directory) 

ls -lh /root/uac-LAB-linux-*

It will be saved in this format --> uac-LAB-linux-20220701212047.tar.gz

Now time to check and analyze the result. You can transfer the tool in your analysis machine. 

mkdir uac-LAB-linux-output 

cd uac-LAB-linux-output/ 

tar zxf ../uac-LAB-linux-20220701212047.tar.gz (This will be on /root/ directory)


Now we will be creating customized uac profile:

git clone https://github.com/tclahr/uac.git

cd uac

ls -l uac

chmod +x uac

./uac -h

cd profiles

You will get two profiles there. full.yaml and ir_triage.yaml

Copy this file ir_triage.yaml with another name and start editing. 

cp profiles/ir_triage.yaml profiles/ir_triage_memory.yaml

Now edit this file ir_triage_memory.yaml using vim. This file contains list of artifacts that the tool will collect. We want this tool will capture the memory of the target system every time. In the artifacts directory, you will get every thing that the tool suppose to collect. 

artifacts:

  - memory_dump/avml.yaml

  - live_response/process/ps.yaml

  - live_response/process/lsof.yaml

  - live_response/process/top.yaml

Add this one memory_dump/avml.yaml at the top of the list. In this below location, the memory artifact collection file avml.yaml is present. 

uac/artifacts/memory_dump/avml.yaml 

Now we will edit this following file and add one more additional command. artifacts/live_response/process/lsof.yaml

cd artifacts/live_response/process/lsof.yaml

vim lsof.yaml

version: 2.1
artifacts:
  
  -
    description: Collect the list open files.
    supported_os: [aix, esxi, freebsd, linux, macos, netscaler, openbsd, solaris]
    collector: command
    command: lsof -nPl
    output_file: lsof_-nPl.txt
  -
    description: Collect open but unlinked files
    supported_os: [aix, esxi, freebsd, linux, macos, netscaler, openbsd, solaris]
    collector: command
    command: lsof +L1
    output_file: lsof_+L1.txt

Save it. Change the version for the betterment of tracking. We have added this one "command: lsof +L1"

This command options mean "show me open files with link count less than one --> Less than one means zero. Zero link count means the file has been deleted but still open. Attackers sometimes use these "open but unlinked" files to hide malware and other data.

Now save and run the tool again to the target system with this new profile. 


















Avi





Comments

Popular posts from this blog

API hacking lab setup

 Follow the commands to install and configure API hacking lab: 1. Install kali linux and update all the packages.  apt update -y apt upgrade -y or apt dist-upgrade -y or apt full-upgrade -y If you face any problem regarding update, install cloud flare warp in the host machine, then again start updating packages in your kali vm.  2. Install and configure burpsuite professional.  After that open burpsuite and go to Extensions tab. Click on BAppStore. Search for Autorize extension, It will help us to automate authorization testing. Click on Download Jython from the right side. From Jython website click on Jython standalone JAR and save it. Go to Extensios > Extensions settings >  under Core extension settings find out Python environment on the right pane. Select the jython jar file that you just downloaded. Now again go to BAppStore and re-search for Autorize extension. You will see Install option this time after selecting Autorize extension. Install it. You ...

Privilege Escalation Domain Level PowerUp - Part - 2

  Our target is first escalate our local privs to local admin level. Then we will hunt for to check we have the local admin privs to which other machines. Then we will check on those machines, any domain admin sessions are available or not.  Unquoted service path check: Get-WmiObject -class win32_service | Select-Object pathname From powerup: Get-ServiceUnquoted -Verbose Get services where the current user can write to its binary path or change arguments to the binary: Get-ModifiableServiceFile -Verbose Get the services whose configuration current user can modify, if you are in server operator group then you can do this: Get-ModifiableService -Verbose Or we can run all the above checks from using powerup.ps1 script: . .\PowerUp.ps1 Invoke-AllChecks help Invoke-ServiceAbuse -Examples Invoke-ServiceAbuse -Name AbyssWebServer -UserName dcorp\student15     (Here AbyssWebServer is the abuseable service name that you come to know after running Invoke-AllChecks command) Wh...

Disk acquisition and access for IR

 Goal for this lab is after we acquire the disk in .E01 format then how can we mount this to linux system for analysis.  দুইটা scenario cover করছি: (A) simple E01 + LVM (single disk), (B) E01 + Software RAID + LVM (multi-disk, যেমন disk1/disk2) From the linux analysis vm like sansforensic vm, you need to run the following commands.  We need to first create the working directories : mkdir -p /mnt/case/img /mnt/case/data E01 + LVM (single disk) - First case. Step 1 — E01 mount: ewfmount Webserver.E01 /mnt/case/img ls -lh  /mnt/case/img total 0  -r--r--r-- 1 root root 32G Feb 16 18:21 ewf1 Ewf1 is a raw disk image. It's size and main disk size are same. This is in read-only mode. See the permission. Step 2 — See the partition layout : mmls /mnt/case/img/ewf1 কোন offset-এ কোন partition আছে (boot, lvm ইত্যাদি) note করুন। RAID sign ( 0xfd ) আছে কিনা খেয়াল করুন — থাকলে Scenario B তে যান। lvscan | grep VulnOSv2-vg mount -o ro,noexec /dev/VulnOSv2-vg/root /mnt/case/dat...