Skip to content

[GITLAB MIRROR] The Iscariot Suite is a collection of tools to enhance and augment trusted open-source and commercial Blue Team/Sysadmin products, turning them into traitorware to achieve offensive security goals.

Notifications You must be signed in to change notification settings

badsectorlabs/iscariot-suite

Repository files navigation

Iscariot Suite

The Iscariot Suite is a collection of tools to enhance and augment trusted open-source and commercial Blue Team/Sysadmin products, turning them into traitorware to achieve offensive security goals. The Iscariot Suite takes its name from the famous traitor Judas Iscariot, who - according to biblical tradition - betrayed Jesus.

The Iscariot Suite was discussed in the presentation "Stop writing malware! The Blue team has done it for you!" The slides for this presentation are in this repo.

Traitorware (noun)
trai·​tor·​ware | \ˈtrā-tər-ˌwer\

1 : software that betrays the trust placed in it to perform malicious actions
2 : trusted software with benign original intent used for malicious actions

// The red team bypassed all our detections using traitorware.

Iscariot-Splunk

  • Uses Splunk native features to act as a full-blown Command and Control framework. The agent component is possible by installing the splunk universal forwarder. The server component is the standard Splunk Enterprise server.

Iscariot-Osquery

  • Using an osquery extension, a user can execute binaries, shell commands, unmodified Cobalt Strike BOFs, and C# assemblies in memory
  • The extension runs as its own process, but a child of the digitally signed osqueryd.exe


References/Credits:

About

[GITLAB MIRROR] The Iscariot Suite is a collection of tools to enhance and augment trusted open-source and commercial Blue Team/Sysadmin products, turning them into traitorware to achieve offensive security goals.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published