Rtfm: Red Team Field Manual

Ben Clark

Language: English

Pages: 96

ISBN: 1494295504

Format: PDF / Kindle (mobi) / ePub

The Red Team Field Manual (RTFM) is a no fluff, but thorough reference guide for serious Red Team members who routinely find themselves on a mission without Google or the time to scan through a man page. The RTFM contains the basic syntax for commonly used Linux and Windows command line tools, but it also encapsulates unique use cases for powerful tools such as Python and Windows PowerShell. The RTFM will repeatedly save you time looking up the hard to remember Windows nuances such as Windows wmic and dsquery command line tools, key registry values, scheduled tasks syntax, startup locations and Windows scripting. More importantly, it should teach you some new red team techniques.

SOCAT soca~ LISTEN ON 1234 AND FORWARD TO PORT ON 2. 2. 2. 2 TCP4:LISTEN:1234 TCP4: STUNNEL - SSL ENCAPSULATED NC TUNNEL 0!1 attacker (client): Modifj /stunnel.conf clien:. = jes [netcat client] accept ~ 5555 connect ~ -~istening IP-:4444 On victim (listening server) l1odifJ /s:.unnel.conf client no server] accept ~ 4444 connect = nc -vlp ---= [ne~cat C:\ 80 On attacker (clien~): # nc -nv 12-.0.C.1 5555 q- (WINDOWS & LINUX) [ 8] GoOGLE HACKING one search within a.

(worldwide) 2.4-2.483.5 GHz 2.4 GHz 5.0 GHz 2.4/5.0 GHZ 4-8 GHz 12-18 GHz 18-26.5 GHz 26.5-40 GHz RFID Keyless Entry Cellular (lJS) GPS L Band 802.15.4 (ZigBee) 802.15.1 (Bluetooth) 802 .llb/g 802.11a 802 .lln C Band Ku Band K Band Ka Band FCC ID LOOKUP jhttps://apps.fcc.gov/oetcf/eas/reports/GenericSearch.cfm FREQUENCY DATABASE http://www.radioreference.com/apps/db/ ) ; KISMET REFERENCE e h n m i t g l u d c r L a H p +If CTRL+L w Q X [5] List Kismet servers Help Toggle.

IP(dst="") Constructing Packets # Setting protocol fields >>> ip=IP(src="") >>> ip.dst="" # Random addresses with RandIP() and RandMAC() >>> IP(dst=RandIP()) >>> Ether(dst=RandMAC()) # Combining layers >>> l3=IP()/TCP() >>> l2=Ether()/l3 # Set a range of numbers to be used (template) >>> IP(ttl=(1,30)) # Splitting layers apart >>> l2.getlayer(1) >> l2.getlayer(2) # Random numbers with RandInt() and RandLong() >>>.

Automatic Configured Automatic Configured Configured Yes No No No Yes No No No Yes Yes Default on Interfaces >2 Mbps Number of Queues 1 Provides for Minimal Delay No Modern Implementation Yes First In First Out (FIFO) Priority Queuing (PQ) LLQ Config Example Class Definitions High Tx Ring Medium Normal Hardware Queue Hardware Queue · Packets are transmitted in the order they are processed · No prioritization is provided · Default queuing method on highspeed (>2 Mbps).

Distributions such as Red Hat Enterprise Linux (RHEL), CentOS and Oracle Enterprise Linux (OEL) chkconfig --list chkconfig chkconfig List existing services and run service service status Check single service status Add service [optional to add level at which service runs] Remove service -list on [--level 3] chkconfig service off [--level 3] e.g. chkconfig iptables off SCREEN (C-a screen -S name screen -ls screen -r name screen -S name C-a C-a d C-a D D C-a c C-a C-a C-a ' numlname C-a " C-a.

