Skip to content

[Feature] Potential use of Rubeus and Mimikatz for AD testing #183

Description

@mika54321

Component

kali-sandbox / MCP servers

Related Roadmap Item

I am wondering if including windows based pentest tools for AD such as Mimikatz and Rubeus would be beneficial in RedAmon.

Both tools can be installed as pre-packaged onto Kali Sandbox and the pre-complied .exe can be transferred onto a compromised Windows host or injected into the memory of the host instead.

I am aware that both tools are well know and most of EDRs detect them easily; therefore, I am not sure how effective this would be compared to remote option (impacket etc) that already exists.

Injecting these tools in windows host's memory might take some skills and tradecraft from the Ai agent though in order to avoid EDR detection.

I will let @samugit83 and professional pentesters to weigh in here and share your opinion!

Description

Potentially expand attack and credential stealing options for Ai Agent by using a variety of tools and exploration options by executing them remotely (linux native existing tools from kali sandbox) vs locally (directly on a windows host)

Motivation

More options for attacks. Possibly to run all the options concurrently?

Proposed Implementation

No response

Alternatives Considered

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions