[Feature Request] Add Python module for Google Workspace Phishing Payload Creation
@brokensound77 is already working on this.
Since May 9, 2023.
Assessment
This issue has not been assessed yet.
Description
🐍 Python Module for MITRE ATT&CK Technique
Tactic Name: Initial Access, Lateral Movement, Privilege Escalation
Technique Name: Phishing, Internal Spearphishing
Technique ID: T1566, T1534
Technique Description: Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering.
Describe the solution you'd like
Payload Creation Module for use with a threat actors GWS infra for Initial Access or a compromised GWS environment for Lateral Movement and Privilege Escalation.
Requirements:
- Google Drive, Google App Scripts API, Google Docs, and Google Sheets APIs enabled
- Python packages (google-auth google-auth-oauthlib google-auth-httplib2 google-api-python-client)
- Scopes (https://www.googleapis.com/auth/drive.file, https://www.googleapis.com/auth/documents,
https://www.googleapis.com/auth/spreadsheets, https://www.googleapis.com/auth/drive)
Module Workflow:
Step 1: Select your payload type (doc, sheet, form):
Step 2: Select App Script payload
Step 3: Choose lure
Step 4: Submit
Module Actions:
1. Authenticate
2. Create file
3. Populate file with lure content
4. Create App Script project and bind to file
5. Set the file permissions and return the link
ChatGPT Example Script
from google.oauth2.credentials import Credentials
from google_auth_oauthlib.flow import InstalledAppFlow
from google.auth.transport.requests import Request
from googleapiclient.errors import HttpError
from googleapiclient.discovery import build
SCOPES = [
'https://www.googleapis.com/auth/drive.file',
'https://www.googleapis.com/auth/spreadsheets',
'https://www.googleapis.com/auth/script.projects',
'https://www.googleapis.com/auth/drive'
]
def create_google_file(file_type, data=None):
try:
service = build('drive', 'v3', credentials=creds)
if file_type == 'document':
mimeType = 'application/vnd.google-apps.document'
elif file_type == 'spreadsheet':
mimeType = 'application/vnd.google-apps.spreadsheet'
elif file_type == 'form':
mimeType = 'application/vnd.google-apps.form'
else:
raise ValueError('Invalid file_type. Must be "document", "spreadsheet", or "form".')
file_metadata = {'name': f'My {file_type.capitalize()}', 'mimeType': mimeType}
file = service.files().create(body=file_metadata, fields='id').execute()
print(F'Created {file_type.capitalize()} with ID: {file.get("id")}')
if file_type == 'spreadsheet':
script_id = create_and_bind_app_script(file.get('id'))
print(F'Created and bound Apps Script project with ID: {script_id}')
if data:
populate_sheet(file.get('id'), data)
share_link = create_share_link(file.get('id'))
print(F'Shareable link: {share_link}')
except HttpError as error:
print(F'An error occurred: {error}')
def create_and_bind_app_script(sheet_id):
try:
service = build('script', 'v1', credentials=creds)
# Create a new Apps Script project
request = {
'title': 'My Custom Functions'
}
script = service.projects().create(body=request).execute()
# Bind the Apps Script project to the Google Sheet
request = {
'addResource': {
'scriptId': script['scriptId'],
'resource': {
'sheetId': sheet_id
}
}
}
service.projects().updateContent(body=request).execute()
return script['scriptId']
except HttpError as error:
print(F'An error occurred: {error}')
def populate_sheet(sheet_id, data):
try:
service = build('sheets', 'v4', credentials=creds)
# Assuming data is a list of lists, where each inner list is a row
# of data to be written to the sheet
body = {
'values': data
}
range_name = 'A1'
result = service.spreadsheets().values().update(
spreadsheetId=sheet_id, range=range_name,
valueInputOption='RAW', body=body).execute()
print(F'Populated sheet with {result.get("updatedCells")} cells.')
except HttpError as error:
print(F'An error occurred: {error}')
def create_share_link(file_id):
try:
service = build('drive', 'v3', credentials=creds)
# Set permissions for the file
permissions = {
'role': 'writer', # or 'reader', depending on the access level you want to grant
'type': 'anyone'
}
service.permissions().create(fileId=file_id, body=permissions).execute()
# Get the shareable link
file = service.files().get(fileId=file_id, fields='webViewLink').execute()
share_link = file.get('webViewLink')
return share_link
except HttpError as error:
print(F'An error occurred: {error}')
# Replace 'spreadsheet' with 'document' or 'form' for other file types
data = [["Header1", "Header2"], [1, 2], [3, 4]]
create_google_file('spreadsheet', data)
- Dominant language
- Python
- Stars
- 169
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from elastic/SWAT
-
Dependency DashboardOpen
Difficulty 5/5 Over a week Newbie friendliness 15/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 52/100
-
[Maintenance] Documentation Screenshots not RenderingMay be free again @terrancedejesus claimed this 1134 days ago, and no pull request is open. Opencommunity maintenance
-
[Feature Request] Create `add-emulation` commandMay be free again @brokensound77 claimed this 1170 days ago, and no pull request is open. Openenhancement
-
[Feature Request] Add Python module for detecting T1098.003 - Additional Cloud RolesMay be free again @terrancedejesus claimed this 1239 days ago, and no pull request is open. OpenAPI: Admin enhancement Subtechnique: 003 Tactic: Persistence Technique: T1098
Similar issues
-
New InternshipOpennew_internship
Difficulty 1/5 Under an hour Newbie friendliness 70/100
-
[BUG] Reports tab: "Unban" button tooltip shows raw `{{ip}}` placeholder instead of the IP addressOpenbug javascript ui
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bunkerity/bunkerweb#4001 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
PedestrianDynamics/pyFDS-Evac#476 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
google/differential-privacy#516 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
adobe-fonts/source-serif#153 ·