Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Can't launch a "exe path" from a payload when the executor is cmd #2184

Open
damgouj opened this issue Jan 9, 2025 · 0 comments
Open

Can't launch a "exe path" from a payload when the executor is cmd #2184

damgouj opened this issue Jan 9, 2025 · 0 comments
Labels
bug use for describing something not working as expected
Milestone

Comments

@damgouj
Copy link
Member

damgouj commented Jan 9, 2025

Description

The "exe path" isn't executed from cmd but it is with powershell.
Image
Image

When we execute it with the same command directly from the endpoint, it works
Image

Environment

OpenBAS 1.10.1, OpenBAS agent on a Windows endpoint

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. Import Payloads from Atomic red team
  2. Launch the Payload "Adfind - Enumerate Active Directory trusts"

Expected Output

The "exe path" from the payload is executed.

Actual Output

The "exe path" from the payload isn't executed.

@damgouj damgouj added bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team labels Jan 9, 2025
@damgouj damgouj changed the title Can't launch a path exe from a payload when the executor is cmd Can't launch a "exe path" from a payload when the executor is cmd Jan 9, 2025
@EllynBsc EllynBsc removed the needs triage use to identify issue needing triage from Filigran Product team label Jan 10, 2025
@EllynBsc EllynBsc added this to the Bugs backlog milestone Jan 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug use for describing something not working as expected
Projects
None yet
Development

No branches or pull requests

2 participants