Threatbox: Linux-based attack platform

ThreatBox is a standard and controlled attack platform based on the Linux operating system.

It started as a collection of scripts, established itself as a virtual machine, existed as s for building a Linux ISO, and has now turned into a series of playbooks.

The project is designed to be used as a starter process for creating, and using a standard attack platform for penetration testing.

Details for the idea of ​​a Standard platform can be found in the book Red Team Development and Operations – A Practical Guide, written by Joe Vest and James Tubberville.

Specifications

  • Basic tools ansible roles
  • Adjustments designed to facilitate security screening
  • Variable list for adding or removing git repositories, operating system packages, or python drives. (ancbox.yml)
  • Automatic switching of SSH port. Development starts at port 22, but resets the destination system to the desired SSH port using the ansible_port variable in yml
  • Download and collect many .net tools (eg SeatBelt.exe from Ghostpack  https://github.com/GhostPack/Seatbelt)
  • Most pythonprojects were installed using pipenv. Use the pipenv shell in the directory to access. See  address https://realpython.com/pipenv-guide/  for instructions for use of pipenv

Application snapshots

Information about the installation and use of the pretos, you will find here.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).