NEW:Report completion of target surveys to the Analyst
For all files that are collected during an operation, the operator must ensure
that the file is hashed on target and on the op station. This validates the file collection
process. All of these hashes must be recorded in the opnotes AND sent to your analyst via chat. Failure
to do this will result in corrective actions. Viable hashing algorithims include MD5 and SHA1 at this time.
Order of operations regarding targets:
Mandatory commands
Box is 'clear'
Survey commands (if required)
Collection (if required)
Redirection (if required)
Effect (if required)
...
Disconnect commands
If an admin is logged into a target, report what they are doing and how long
they have been logged in. Also report any files or executables they are running. This should
be reported to your MC and annotated in your opnotes.
Windows defender is known to be on every Windows 7 and Windows 10 Operating System.
All targets with this security product are cleared for operation.
When Reporting SELinux - if it is enforcing OR permissive place that inside your report to the MC.
You are required to report both of these status'.
Downloading any file(s) outside the scope of the mission plan require MC approval.
Targets should be disconnected from as soon as a presence no longer needs to be maintained.
As operators, it is our responsibility to minimize the risk presented by our operations and reduce our
presence in networks to what is necessary for mission completion. Maintaining connections after they are
required jeopardizes the mission and will not be an accepted risk.
Ignore ALL student activity except your own
netsh is an unauthorized redirection method on Windows XP and older
Follow new Rapid7 guidance from: https://metasploit.help.rapid7.com/docs/getting-started
ssh tunnels over satellite hops require additional approval from your MC
the "-e" switch is unauthorized for use with netcat
Tunnels to targets with known IPs and ports must be set up upon initial master socket creation
Only 1 open interactive terminal is authorized per target, additional interactive slave connections require MC approval
The "tree" command is no longer required to be executed for the analyst survey