guardicore / monkey

Infection Monkey - An open-source adversary emulation platform
https://www.guardicore.com/infectionmonkey/
GNU General Public License v3.0
6.55k stars 763 forks source link

Keepass payload/collector #2903

Open VakarisZ opened 1 year ago

VakarisZ commented 1 year ago

Is your feature request related to a problem? Please describe. Keepass has a vulnerability: https://github.com/alt3kx/CVE-2023-24055_PoC

Describe the solution you'd like We could create a credential collector to exploit this (longshot) We could create a payload that modifies the file with custom triggers (should be possible once pluggable payloads are done?)

shreyamalviya commented 6 months ago

https://github.com/GhostPack/KeeThief