SaiSakthidar
|
98dd33a3cd
|
Remove CAIN
|
2025-12-03 15:42:57 -05:00 |
|
Brendan
|
21777b8969
|
Merge pull request #20685 from msutovsky-r7/persistence/windows/notepad++_persistence
Adds notepad++ persistence module for Windows
|
2025-11-21 14:28:28 -06:00 |
|
Martin Sutovsky
|
098af341f9
|
Fix payload name escaping
|
2025-11-21 13:04:52 +01:00 |
|
Brendan
|
bb728c44d7
|
Merge pull request #20560 from cdelafuente-r7/feat/mitre/T1021
Add T1021 "Remote Services" MITRE technique and sub-technique references
|
2025-11-20 11:19:31 -06:00 |
|
Martin Sutovsky
|
d904a526ee
|
Shamefully removes pry and pry-byebug
|
2025-11-20 17:08:28 +01:00 |
|
msutovsky-r7
|
e2097ee1bc
|
Land #20701, adds windows WSL registry persistence module
Windows WSL registry persistence
|
2025-11-20 15:15:22 +01:00 |
|
Martin Sutovsky
|
abaa4e6c7a
|
Fixes cmd_exec call
|
2025-11-20 11:27:34 +01:00 |
|
h00die
|
9ff3f94bc9
|
review comments for wsl persistence
|
2025-11-19 17:37:55 -05:00 |
|
Christophe De La Fuente
|
179a545312
|
Remove false positive references
|
2025-11-19 17:34:15 +01:00 |
|
Martin Sutovsky
|
554c952d06
|
Adds payload name escaping
|
2025-11-19 15:58:30 +01:00 |
|
Martin Sutovsky
|
6957f73bf5
|
Adds architecture match check
|
2025-11-19 08:12:30 +01:00 |
|
h00die
|
58f29548b3
|
review for windows/persistence/wsl/registry
|
2025-11-18 18:50:07 -05:00 |
|
h00die
|
3209fdc937
|
remove old file
|
2025-11-17 19:03:55 -05:00 |
|
h00die
|
7c8fbd1672
|
rework windows service persistence
|
2025-11-17 19:02:54 -05:00 |
|
h00die
|
a0222d0783
|
rework windows service persistence
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
1ad89ef1ef
|
rewriting service
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
06f5c89bf4
|
throw this away
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
8c211b4d4a
|
fix sc commands in windows service persistence
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
450e1df340
|
windows service now with persistence mixin
|
2025-11-17 19:02:50 -05:00 |
|
Martin Sutovsky
|
8285b433cb
|
Addresses comments
|
2025-11-17 11:04:28 +01:00 |
|
Martin Sutovsky
|
0e26719cf2
|
Adds dll_exitprocess
|
2025-11-17 09:24:09 +01:00 |
|
h00die
|
e3560e43cf
|
windows wsl registry persistence
|
2025-11-16 08:35:44 -05:00 |
|
Diego Ledda
|
c007d3a89f
|
Merge pull request #20674 from msutovsky-r7/exploit/win/cve-2025-59287
Adds module for unauthenticated deserialization in WSUS (CVE-2025-59287)
|
2025-11-12 12:40:32 +01:00 |
|
Martin Sutovsky
|
e35bd89033
|
Expands check method
|
2025-11-12 10:35:23 +01:00 |
|
Diego Ledda
|
29088b4712
|
Merge pull request #20576 from msutovsky-r7/modules/persistence/linqpad_deserialization
Moves LINQPad module into persistence category
|
2025-11-11 16:41:12 +01:00 |
|
Martin Sutovsky
|
9058f6676b
|
Removes if condition
|
2025-11-11 11:22:31 +01:00 |
|
Martin Sutovsky
|
6aeb81a499
|
Adds MITRE reference, updates docs
|
2025-11-10 18:32:13 +01:00 |
|
Martin Sutovsky
|
fc434414d3
|
Randomizes XML paramater
|
2025-11-10 16:54:49 +01:00 |
|
Martin Sutovsky
|
2cbf32ce40
|
Adds documentation base
|
2025-11-10 12:27:13 +01:00 |
|
Martin Sutovsky
|
d4283cd17f
|
Adds base for Notepad++ persistence
|
2025-11-10 10:58:03 +01:00 |
|
Martin Sutovsky
|
5ea47e5ac3
|
Adds formatting to XML data, adds automatic plugin ID extraction
|
2025-11-06 16:46:58 +01:00 |
|
Martin Sutovsky
|
570c7c0bf4
|
Changes CheckCode to Detected
|
2025-11-06 16:21:42 +01:00 |
|
Martin Sutovsky
|
b0afe5e24b
|
Randomizes parameters that can be randomized
|
2025-11-06 15:06:30 +01:00 |
|
Martin Sutovsky
|
904e752662
|
Code refactor
|
2025-11-06 14:52:49 +01:00 |
|
Martin Sutovsky
|
cb0011649c
|
Adds SCREEN_EFFECTS to SideEffects
|
2025-11-06 14:50:31 +01:00 |
|
Martin Sutovsky
|
f586fff090
|
Adds clear message if exploit fails
|
2025-11-06 14:46:02 +01:00 |
|
Martin Sutovsky
|
5ad76f82d1
|
Adds more docs, adds description
|
2025-11-04 13:49:43 +01:00 |
|
Martin Sutovsky
|
f195ebd453
|
Code refactor
|
2025-11-04 13:36:33 +01:00 |
|
Martin Sutovsky
|
98467f3a21
|
Adds msf payload to module, adds docs
|
2025-11-04 12:28:03 +01:00 |
|
Martin Sutovsky
|
e885da1f0b
|
Add rce for wsus
|
2025-11-03 20:47:28 +01:00 |
|
Martin Sutovsky
|
96edf7bad4
|
Updates
|
2025-11-03 14:25:39 +01:00 |
|
msutovsky-r7
|
af5baeb3c6
|
Land #20660, adds windows task scheduler persistence module
Windows task scheduler persistence
|
2025-10-31 10:16:19 +01:00 |
|
msutovsky-r7
|
09f1d1ae57
|
Land #20650, adds module for NCR Command Center Agent unauthenticated RCE (CVE-2021-3122)
Add NCR Command Center Agent Unauthenticated RCE (CVE-2021-3122)
|
2025-10-30 08:26:42 +01:00 |
|
Martin Sutovsky
|
666e63f993
|
Rubocopes module
|
2025-10-30 07:43:32 +01:00 |
|
Martin Sutovsky
|
ee3058bf92
|
Removes moved_from
|
2025-10-29 15:14:29 +01:00 |
|
msutovsky-r7
|
56480df99f
|
Land #20662, adds windows startup folder persistence module
windows persistence: startup folder
|
2025-10-29 13:23:35 +01:00 |
|
h00die
|
34b630736a
|
Merge remote-tracking branch 'origin/windows_taskscheduler_persistence' into windows_taskscheduler_persistence
|
2025-10-29 05:22:55 -04:00 |
|
h00die
|
f03b32551a
|
Update modules/exploits/windows/persistence/task_scheduler.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
|
2025-10-29 05:22:28 -04:00 |
|
h00die
|
b48215d9c1
|
Merge remote-tracking branch 'origin/windows_taskscheduler_persistence' into windows_taskscheduler_persistence
|
2025-10-29 05:21:45 -04:00 |
|
h00die
|
35f632bc85
|
windows persistence: task scheduler review
|
2025-10-29 05:20:57 -04:00 |
|