Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). Pupy is publicly available on GitHub.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Pupy can execute Lazagne as well as Mimikatz using PowerShell. |
| T1003.004 LSA Secrets |
Pupy can use Lazagne for harvesting credentials. |
| T1003.005 Cached Domain Credentials |
Pupy can use Lazagne for harvesting credentials. |
| T1016 System Network Configuration Discovery |
Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions. |
| T1021.001 Remote Desktop Protocol |
Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client. |
| T1033 System Owner/User Discovery |
Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts. |
| T1041 Exfiltration Over C2 Channel |
Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server. |
| T1046 Network Service Discovery |
Pupy has a built-in module for port scanning. |
| T1049 System Network Connections Discovery |
Pupy has a built-in utility command for |
| T1055.001 Dynamic-link Library Injection |
Pupy can migrate into another process using reflective DLL injection. |
| T1056.001 Keylogging |
Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped. |
| T1057 Process Discovery |
Pupy can list the running processes and get the process ID and parent process’s ID. |
| T1059.001 PowerShell |
Pupy has a module for loading and executing PowerShell scripts. |
| T1059.006 Python |
Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc. |
| T1071.001 Web Protocols |
Pupy can communicate over HTTP for C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.