T1145 discover SSH keys

This commit is contained in:
Tony M Lambert
2018-10-19 16:36:28 -04:00
parent a91994c5bb
commit abb43d1b4f
+17
View File
@@ -17,3 +17,20 @@ atomic_tests:
command: |
echo "ATOMICREDTEAM" > %windir%\cert.key
dir c:\ /b /s .key | findstr /e .key
- name: Discover Private SSH Keys
description: |
Discover private SSH keys on a macOS or Linux system.
supported_platforms:
- macos
- linux
input_arguments:
output_file:
description: Output file containing locations of SSH key files
type: path
default: /tmp/keyfile_locations.txt
executor:
name: sh
command: |
find / -name id_rsa > #{output_file}
find / -name id_dsa >> #{output_file}