Microsoft OneDrive

OneDrive is another popular file sharing service, similar to Dropbox. In the latest version of Empire, you should be able to see an additional prebuilt listener, onedrive, as shown in the following screenshot:

Set up the onedrive c2c as follows:

  1. Create a Microsoft developer account (https://developer.microsoft.com/en-us/store/register), or sign up for the Application developer program (https://developer.microsoft.com).
  1. Register a new application by entering a name and clicking Create, as shown in the following screenshot:

  1. Once the application is created, attackers should be able see a newly created Application ID, as shown here:

  1. Now, we are ready to fire up Empire and set up our listener. Set the ClientID (the Application Id from the previous step) and execute the listener, as shown in the following screenshot:

  1. The URL can be opened in a browser to generate the authentication code, as shown in the following screenshot:

  1. The code from the URL can now be used to set up the Empire listener, as follows:

  1. Just as with Dropbox, now you should be able to see a folder named Empire with three subfolders called resultsstaging, and taskings in your OneDrive, with the correct Client ID and authentication code, as shown here:

  1. Once the payload is executed successfully on the target, this should listen on the OneDrive listener, as shown in the following screenshot:

Other public platforms that can be used for persistence C2 include the following:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.216.251.37