Closed tfriesen closed 3 years ago
I'll see what I can do, but this definitely seems to be something that would have to be changed on Empire's side. Thanks
One alternative idea I had would be to, if possible, check if we can connect to a host on port 135 before attempting Invoke-wmi. This has the advantage in that invoke-wmi is... kind of slow... so if you only have one agent, and many dead hosts, it can take a while to go through them.
Thanks for the tool, I've been enjoying testing it out!
When DeathStar is trying to spread laterally, the output reports successful spread when it targets a host that doesn't exist.
Where host X.local does not exist (found the hostname via outdated GPO), but Y.local does exist.
If I monitor activity by interacting with the active agent, this is what I see:
The second line refers to Y.local.
This may not be fixable because it seems that Invoke-WMI reports success ("executed") when it targets non-existant host. DeathStar is just passing the info along.