Amnesiac: The PowerShell Post-Exploit Framework for Stealthy Lateral Movement
Amnesiac
Amnesiac
is a post-exploitation framework designed to assist with lateral movement within active directory environments.
Amnesiac is being developed to bridge a gap on Windows OS, where post-exploitation frameworks are not readily available unless explicitly installed. In fact, it is entirely written in PowerShell, and can be loaded and executed in memory, just like any other PowerShell script.
Key Features
Command Execution over Named-Pipes (SMB)
Amnesiac sends commands and receives output through Named Pipes. If you want to know more about Named Pipes, this is a good read.
No Installation Required
Unlike traditional frameworks, Amnesiac does not require installation. It operates entirely in memory, reducing the risk of detection and forensic footprint.
User-Friendly Framework
Amnesiac is designed with usability in mind. It provides a user-friendly interface, making it accessible and efficient for both beginners and experienced users.
Versatile Post-Exploitation Modules
Amnesiac comes equipped with an array of post-exploitation modules, ranging from keyloggers to Kerberos ticket dumping tools. These modules can be seamlessly integrated into your testing and assessment workflows.
Acknowledgments
Amnesiac relies on few other projects for its modules. In each module, you’ll find reference link information, ensuring proper attribution to the original creators.
Install & Use
Copyright (C) 2024 Leo4j