elastic / SWAT

Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK framework.
Apache License 2.0
161 stars 7 forks source link

[Emulation Tuning] Adjust `Send HTML with Embedded Javascript with Gmail` Emulation #74

Closed terrancedejesus closed 1 year ago

terrancedejesus commented 1 year ago

Overview

This pull request makes adjustments to the Send HTML with Embedded Javascript with Gmail emulation.

Emulation Testing

Note that in order to test this emulation, 2 separate google workspace accounts were necessary where one needs to be external to the organization being monitored. OAuth creds and valid sessions then needed to be established within the credential store as well.

Screenshot 2023-08-30 at 12 41 56 PM Screenshot 2023-08-30 at 12 42 06 PM

Screenshot 2023-08-30 at 12 53 47 PM

Screenshot 2023-08-30 at 12 54 01 PM

Screenshot 2023-08-30 at 12 58 46 PM