Github spots to get payloads to play with


So, some people got the same idea.  Out there on github are all kinds of payloads you can play with that do some crazy things  Here are some links to some.

First one is Powersploit.  Its been talked about all over.  This is a good starter.  Also contains some good utility scripts for modifying your scripts.


Next is my favorite.  Empire.  I am going to link the stable branch but under the 2.0 branch you can find python payloads as well for your nix and OSX needs.

Root Project:


Subfolder with all the Powershell stuff:



And just for kicks, hey Dav-ee, look, an agent.


I couldn't help it.  That agent is way beyond mine.  Of course mine isn't design to communicate across the internet so securing connection not a big deal.

Here is a little snippet I made into a function to see if your current Powershell instance is high integrity or not (if your Powershell process that is currently running has bypassed UAC.).  At this present time I cannot tell you the usefulness of this in the BB world except to limit scripts if the process if not UAC bypassed but may come in handy.

function Get-isHighIntegrity
    $isAdmin = $false
	#If the process is running as System then we are in a high integrity process.
    if(([Environment]::UserName).ToLower() -eq 'system') {
        $isAdmin = $true
        # otherwise check the token groups
        $isadmin = ([Security.Principal.WindowsPrincipal] [Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole] 'Administrator')
    return $isAdmin

I believe this is a snippet from Empire's agent.  My old way was a huge C# routine to check pointers which looks to only be needed for processes you are not in.  This function returns a Boolean true if it is high integrity or false if not.

2 hours ago, rottingsun said:

The latest Empire stagers actually have a bunny target. :grin:

Yeah, I was speaking with the author on Github through his push request about it.  Was discussing if the way he did it was compatible with all versions of the bunny.  1.0 and up after I suggested making it for latest version.  He had a better point about making it just work across the board.

