Component
kali-sandbox / MCP servers
Related Roadmap Item
I am wondering if including windows based pentest tools for AD such as Mimikatz and Rubeus would be beneficial in RedAmon.
Both tools can be installed as pre-packaged onto Kali Sandbox and the pre-complied .exe can be transferred onto a compromised Windows host or injected into the memory of the host instead.
I am aware that both tools are well know and most of EDRs detect them easily; therefore, I am not sure how effective this would be compared to remote option (impacket etc) that already exists.
Injecting these tools in windows host's memory might take some skills and tradecraft from the Ai agent though in order to avoid EDR detection.
I will let @samugit83 and professional pentesters to weigh in here and share your opinion!
Description
Potentially expand attack and credential stealing options for Ai Agent by using a variety of tools and exploration options by executing them remotely (linux native existing tools from kali sandbox) vs locally (directly on a windows host)
Motivation
More options for attacks. Possibly to run all the options concurrently?
Proposed Implementation
No response
Alternatives Considered
No response
Component
kali-sandbox / MCP servers
Related Roadmap Item
I am wondering if including windows based pentest tools for AD such as Mimikatz and Rubeus would be beneficial in RedAmon.
Both tools can be installed as pre-packaged onto Kali Sandbox and the pre-complied .exe can be transferred onto a compromised Windows host or injected into the memory of the host instead.
I am aware that both tools are well know and most of EDRs detect them easily; therefore, I am not sure how effective this would be compared to remote option (impacket etc) that already exists.
Injecting these tools in windows host's memory might take some skills and tradecraft from the Ai agent though in order to avoid EDR detection.
I will let @samugit83 and professional pentesters to weigh in here and share your opinion!
Description
Potentially expand attack and credential stealing options for Ai Agent by using a variety of tools and exploration options by executing them remotely (linux native existing tools from kali sandbox) vs locally (directly on a windows host)
Motivation
More options for attacks. Possibly to run all the options concurrently?
Proposed Implementation
No response
Alternatives Considered
No response