mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -11,8 +11,9 @@ This attack included several stages including redirect to a Visual Studio Code w
|
||||

|
||||
|
||||
## The first stage (delivery technique)
|
||||
In the beginning, I downloaded VS Code on Windows Target Machine, then I logged in to my GitHub account in the browser, and through it I logged in to my VScode account.
|
||||
|
||||
|
||||
https://medium.com/@truvis.thornton/visual-studio-code-embedded-reverse-shell-and-how-to-block-create-sentinel-detection-and-add-e864ebafaf6d
|
||||
|
||||

|
||||
|
||||
@@ -22,6 +23,7 @@ ________________________________________________________________________________
|
||||
|
||||
_______________________________________________________________________________________________________________________
|
||||
|
||||
To complete the process of linking the account you got with the VS code, I open CMD in Windows and write the command `code tunnel` so that the terminal gives us the link that we will use to complete the authentication process.
|
||||
|
||||

|
||||
|
||||
@@ -44,11 +46,14 @@ ________________________________________________________________________________
|
||||
|
||||
_______________________________________________________________________________________________________________________
|
||||
|
||||
After that, the link will appear in the CMD, which i will use and open from the attacker browser to gain control over the victim VSCode through the attacker browser.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
_______________________________________________________________________________________________________________________
|
||||
|
||||
Now I have control over the target machine through my browser in Kali Linux.
|
||||
|
||||

|
||||
|
||||
|
||||
Reference in New Issue
Block a user