3 ms·
> Why Meterpreter isn't controlled by an AI or achieving some other autonomous state, I'll never know How do you think meterpreter would be controlled by an AI
by world32 7y ago
> Why Meterpreter isn't controlled by an AI or achieving some other autonomous state, I'll never know
How do you think meterpreter would be controlled by an AI? Do you think there should be an AI that will automatically figure out a way to hack into a system or escalate privileges?
Regarding other tools like nmap and metasploit - they are frameworks which let you run modules specific to certain exploits. Metasploit has countless of new modules being developed all the time. And nmap has its own scripts to target new kinds of attacks.
Though the basic functionality of nmap will not change anytime soon because network protocols are largely the same since 10 years ago.
- ksaj 7y agoI see it doing the standard recon and working the appropriate exploit that would likely provide the most leverage with the least noise, but from within the target environment. So, yea, you've provided some good examples. Once behind the firewall, outbound connections to a c&c could set off alarms. Especially if the connections are sourced from multiple internal systems to a single external one. So let an ai decide what to do once lateral movement options become available, then report back findings at a more appropriate time and method that is also less likely to ring bells. That's just a quick synopsis. There is a lot more that could be done, but the secondary exploitation/invasion stages would probably see the biggest gains.
- world32 7y agoI don't see how will ever be possible? There are just way way too many parameters to code an AI to do lateral movement or escalation once inside a system. For example, even trying to exploit a famous vuln like dirtycow still often requires small tweaks to the exploit script in order to get it to work. There is no way an AI will be able to do that. Though if you are talking about an "AI" that checks processes running, versions installed etc. and runs the appropriate exploits scripts metasploit already has that in the getsystem command. Though I wouldn't really consider that AI. https://www.offensive-security.com/metasploit-unleashed/privilege-escalation/ https://www.offensive-security.com/metasploit-unleashed/priv...