Git Product home page Git Product logo

agent's Introduction

Agent

What is it?

A small agent which logs activity from User Space into Windows EventLog. Log entries can then be shipped to a SIEM by a collector such as WinLogBeat. The agent has a basic persistence mechanism, as it can run both as a Windows service and as a User Space application. When running as a service it will make sure that a Scheduled Task exists to start the Agent as a normal application every X minutes under the/any logged on user account.

Syntax

agent.exe [-i] [-s] [-u] [-p]

-i : installs the application (copies the exe to Program Files, registers & starts the service). Requires elevated access rights.

-s : runs as a service. Don't use this argument when starting normally (from User Space).

-u : runs service code, but from the User Space. Use this for debugging purposes.

-p : spawns itself then quit, used when started by Task Scheduler

Source notes

Code shows how to:

  • Build a Windows Service, and run the Service from User land to troubleshoot
  • Threading with Timers
  • Create EventLog entries, Scheduled Tasks
  • Run scripts (blocks of code) using PowerShell, and WMI queries
  • Calling a Web service for info

To customize the code, one could start to:

  • Change Resources\AgentName, which will define:

    • name of service (<AgentName>Svc)
    • EventLog source
    • name of ScheduledTask ("Launch <AgentName>-<SID>")
    • name of executable file installed under \Program Files
  • Change configurable strings in Resources:

    • InstallFolder for the folder name under \Program Files
    • ServiceDisplay: display name for service
    • ServiceDescription: description for service

Meta: CEH9

agent's People

Contributors

scattic avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.