sliverarmory / armory

The Official Sliver Armory
https://sliver.sh/
80 stars 11 forks source link

Porting Defender_Exclusions-BOF #30

Open nemesis7331 opened 1 year ago

nemesis7331 commented 1 year ago

I'm trying to port Defender_Exclusions-BOF, I see you already forked it, so I tried adding the extension.json and use it but no luck :(

[server] sliver (mtls-sk) > extensions install /home/kali/Downloads/Defender_Exclusions-BOF-main/dist

[*] Installing extension 'defender-excl' (1.0.0) ... 
[server] sliver (mtls-sk) > extensions load /home/kali/Downloads/Defender_Exclusions-BOF-main/dist

[*] Added defender-excl command: A BOF to determine Windows Defender exclusions:

[server] sliver (mtls-sk) > defender-excl 1

[!] Call extension error: rpc error: code = Unknown desc = The parameter is incorrect.

extension.json used:

{
    "name": "Defender_Exclusions-BOF ",
    "version": "1.0.0",
    "command_name": "defender-excl",
    "extension_author": "nemesis",
    "original_author": "EspressoCake",
    "repo_url": "https://github.com/EspressoCake/Defender_Exclusions-BOF",
    "help": "A BOF to determine Windows Defender exclusions:",
    "long_help": "",
    "depends_on": "coff-loader",
    "entrypoint": "go",
    "files": [
        {
            "os": "windows",
            "arch": "amd64",
            "path": "cEnumerateDefender.x64.o"
        },
        {
            "os": "windows",
            "arch": "386",
            "path": "cEnumerateDefender.x86.o"
        }
    ],
    "arguments": [
        {
            "name": "option",
            "desc": "1 - Folder; 2 - Process; 3 - Extension",
            "type": "int",
            "optional": false
        }
    ]
}