Neton is a tool for getting information from Internet connected sandboxes. It is composed by an agent and a web interface that displays the collected information.
The Neton agent gets information from the systems on which it runs and exfiltrates it via HTTPS to the web server.
Some of the information it collects:
- Operating system and hardware information
- Find files on mounted drives
- List unsigned microsoft drivers
- Run SharpEDRChecker
- Run Pafish
- Run Al-Khaser
- Detect hooks
- Take screenshots of the desktop
Images
9 3 1Deployment
NetonWeb
- Install (with virtualenv):
source venv/bin/activate
pip3 install -r requirements.txt
- Configure the database:
python3 manage.py makemigrations core
python3 manage.py migrate core
- Create user:
Launch (test)
python3 manage.py runserverLaunch (prod)
- Generate the certificates and store them in the certs folder:
Launch gunicorn:
./launch_prod.sh
Agent
Build solution with Visual Studio. The agent configuration can be done from the Program.cs class.- url variable: Url where the information will be exfiltrated (NetonWeb’s).
- sandboxId variable: Identifier of the sandbox where the samples are uploaded.
- wave variable: Way of organising the different times the samples are sent. muestras. 2
Sample data
In the sample data folder there is a
You must be registered for see links
with several samples collected from the following services:- Virustotal
- Tria.ge
- Metadefender
- Hybrid Analysis
- Any.run
- Intezer Analyze
- Pikker
- AlienVault OTX
- Threat.Zone
Credentials:
- User: raccoon
- Password: jAmb.Abj3.j11pmMa
Extra info
- Slides (ES):
You must be registered for see links
- Video (ES):
You must be registered for see medias
- Video (EN):
You must be registered for see medias
Credits
- SharpEDRChecker:
You must be registered for see links
- Pafish:
You must be registered for see links
- Al-Khaser:
You must be registered for see links
- OffensiveCSharp → HookDetector:
You must be registered for see links
- OffensiveCSharp → DriverQuery:
You must be registered for see links
GitHub:
You must be registered for see images
You must be registered for see links