Hacking Tools

Xenon : A New Tool In The Mythic Framework

Xenon is a Windows agent designed for the Mythic framework, inspired by tools like Cobalt Strike.

It is currently in an early stage of development and is not considered operationally secure (OPSEC safe), meaning it may contain memory leaks and other issues that could lead to crashes.

Despite these limitations, Xenon offers several features that make it useful for testing and educational purposes.

Key Features Of Xenon

  1. Modular Command Inclusion: Xenon allows users to include commands in a modular fashion, making it easier to extend its functionality.
  2. Malleable C2 Profiles with HTTPX: Xenon supports malleable command and control (C2) profiles using the HTTPX framework. This allows operators to configure how the agent communicates with its server, including features like domain rotation, callback jitter, and message transforms.
  3. Compatibility with Cobalt Strike BOFs: Xenon can execute Beacon Object Files (BOFs) from Cobalt Strike, providing additional situational awareness capabilities.

Xenon includes a range of basic commands for file management and process interaction:

  • pwd: Displays the current working directory.
  • ls: Lists directory contents.
  • cd: Changes the working directory.
  • cp: Copies files.
  • rm: Removes files or directories.
  • mkdir: Creates new directories.
  • getuid: Retrieves the current user ID.
  • make_token and steal_token: Create and impersonate tokens for identity manipulation.
  • ps: Lists running processes.
  • shell: Executes shell commands.
  • sleep: Adjusts the sleep timer and jitter for evasion.

Xenon also includes several situational awareness commands, such as:

  • sa_adcs_enum: Enumerates Certificate Authorities and templates in Active Directory.
  • sa_arp: Lists the ARP table.
  • sa_driversigs: Checks service image paths for AV/EDR vendor signatures.
  • sa_get_password_policy: Retrieves password policies for a server or domain.
  • sa_ipconfig: Displays IPv4 addresses, hostnames, and DNS servers.

The roadmap for Xenon includes addressing memory issues, implementing new commands for assembly execution and lateral movement, and integrating PowerShell support.

Despite its early stage, Xenon offers a promising platform for learning and experimentation with Windows internals and C programming.

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

OSCP : Navigating The Essential Toolkit For Penetration Testing

The OSCP (Offensive Security Certified Professional) certification is a highly respected credential in the cybersecurity…

14 minutes ago

Famatech Advanced IP Scanner Or Advanced Port Scanner Usage

Famatech offers two powerful network management tools: Advanced IP Scanner and Advanced Port Scanner. Both…

14 minutes ago

ELF Loader And PS5-JAR-Loader : Tools For Enhanced Functionality

In the realm of PlayStation 5 (PS5) development, two significant tools have emerged to enhance…

15 minutes ago

C2IntelFeeds : Enhancing Cybersecurity With Threat Intelligence

C2IntelFeeds is a powerful tool designed to provide actionable threat intelligence to cybersecurity professionals. It…

2 hours ago

goLAPS : The Ultimate Guide To Managing LAPS Passwords with Golang

goLAPS is a tool designed to interact with the Local Administrator Password Solution (LAPS) in…

4 hours ago

200-OK-Modifier : Mastering Web Application Analysis And Penetration Testing

The 200-OK-Modifier is a versatile Burp extension that allows users to modify server response codes…

4 hours ago