ANTIVIRUS EVASION / Veil Framework (I): Installation and setup
- Layout for this exercise:
data:image/s3,"s3://crabby-images/9577f/9577fd5e1fa96967d0e7cde4ffbcbb16ee0ce571" alt=""
1 - Introduction to Veil Framework
- The Veil Framework is a collection of security tools that implement various attack methods focused on evading antivirus detection.
https://www.veil-framework.com/framework/
https://github.com/Veil-Framework
- The most recent version at this moment (Veil 3.1.4) is composed of these tools:
a) Evasion generates payload executables that bypass common antivirus solutions.
b) Ordnance quickly generates Metasploit stager shellcode.
data:image/s3,"s3://crabby-images/2c7da/2c7da34e3a9df596ed66f9b8212d88174e1a3000" alt=""
2 - Installing Veil Framework
- In this exercise we are using a Kali Linux distribution.
- In case git is not installed:
data:image/s3,"s3://crabby-images/da261/da2610a0c9258cef8f995a0e4660f943f297be69" alt=""
- From Veil github, copying to the clipboard:
data:image/s3,"s3://crabby-images/b827a/b827a49ca1f31b50a1b669ebdb17aff50c5d38a3" alt=""
- Cloning:
data:image/s3,"s3://crabby-images/46964/4696421d5e5427970067d3442b2ed1a35c83b46e" alt=""
- A new directory Veil is created:
data:image/s3,"s3://crabby-images/715d3/715d3a669c4ddf9bb7551809aafb99f75ee5fc9b" alt=""
- Setting up the framework:
data:image/s3,"s3://crabby-images/3129a/3129a8cb3846e99b7e8959299a839e8f9476f1e5" alt=""
3 - Browsing Veil Framework options
- Launching the program:
data:image/s3,"s3://crabby-images/76994/76994a732ec59798d23d1601f67bcd2e194b9924" alt=""
- Veil provides some commands. For instance the command list displays the two available tools, Evasion and Ordnance:
data:image/s3,"s3://crabby-images/83ef8/83ef83abb8f9c5cf039500c7abc2ceee01e88742" alt=""
data:image/s3,"s3://crabby-images/de091/de0911ff8b4e04af738a75935165c44e2309fbe5" alt=""
4 - Evasion
- Choosing Evasion:
data:image/s3,"s3://crabby-images/f7a48/f7a48e832ace33e25b897c05dff295dd3674fc47" alt=""
data:image/s3,"s3://crabby-images/b423e/b423e0bc4227c4a164b64f5cea8b752858dbf357" alt=""
- Listing the 41 Evasion payloads:
data:image/s3,"s3://crabby-images/3dddf/3dddfb3e8d60965d495d316c1dbae6810531cf5d" alt=""
data:image/s3,"s3://crabby-images/56f94/56f94566c3ec562b4b3bc4c3c555409470917815" alt=""
......................... etc ............................................................
data:image/s3,"s3://crabby-images/0806d/0806d5d1c961dd94fc904e1caee497fc80f4994f" alt=""
5 - Ordnance
- Choosing Ordnance:
data:image/s3,"s3://crabby-images/d4672/d46720d679bc6e8635574185d9a54eff4fda5185" alt=""
data:image/s3,"s3://crabby-images/aedf1/aedf1b9a10beb3d1972a084f6f472f80ac2e71aa" alt=""
- Listing Ordnance payloads:
data:image/s3,"s3://crabby-images/a5622/a562294a9e095867dddfc6cdbac57d3fb0a58b19" alt=""
data:image/s3,"s3://crabby-images/826c2/826c263bb9d1d3f56705bcd200d80f1e3d3545dd" alt=""
- Listing Ordnance encoder (XOR):
data:image/s3,"s3://crabby-images/59606/59606a054ff6c6ffa4a673c8662494ff1fc5d354" alt=""
data:image/s3,"s3://crabby-images/d62b9/d62b95b7b2d2d18dbfb9918b3755403fc3249372" alt=""