For compatibility with CALDERA, Oilrig needs a Resources/utilities/crypt_executables.py file, similarly to the other emulation plans. Oilrig has a few payloads in Resources/Binaries/binaries.zip that are never ingested because there is nothing to decrypt the .zip (aside from doing it manually), but adding crypt_executables.py to this emulation plan should resolve that.
For compatibility with CALDERA, Oilrig needs a
Resources/utilities/crypt_executables.py
file, similarly to the other emulation plans. Oilrig has a few payloads inResources/Binaries/binaries.zip
that are never ingested because there is nothing to decrypt the .zip (aside from doing it manually), but addingcrypt_executables.py
to this emulation plan should resolve that.