[Feature Request] Add Python module for Stealing Application Access Tokens
@terrancedejesus is already working on this.
Since May 10, 2023.
Assessment
This issue has not been assessed yet.
Description
🐍 Python Module for MITRE ATT&CK Technique
Tactic Name: Credential Access
Technique Name: Steal Application Access Token
Technique ID: T1528
Technique Description: Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Describe the solution you'd like
A Application Access Token Stealing Module for use with a compromised GWS environment for Credential Access.
Requirements:
- Google Admin SDK API enabled
- Python packages (google-auth google-auth-oauthlib google-auth-httplib2 google-api-python-client, email, base64)
- Scopes (https://www.googleapis.com/auth/admin.directory.user)
Module Workflow:
Step 1: Collect all available Application Access Tokens
Module Actions:
1. Authenticate
2. Build the Directory API client
3. Retrieve the list of application access tokens
4. Print the access tokens
ChatGPT Example Script
from google.oauth2 import service_account
from googleapiclient.discovery import build
# replace with the path to your service account key file
KEY_FILE_LOCATION = '/path/to/service_account_key.json'
# replace with your customer ID
CUSTOMER_ID = 'my_customer'
# replace with your scope
SCOPE = 'https://www.googleapis.com/auth/admin.directory.group.member.readonly'
# create credentials from service account key file
credentials = service_account.Credentials.from_service_account_file(KEY_FILE_LOCATION, scopes=[SCOPE])
# build the Directory API client
directory_service = build('admin', 'directory_v1', credentials=credentials)
# retrieve the list of application access tokens
results = directory_service.tokens().list(customer=CUSTOMER_ID).execute()
# print the access tokens
for token in results.get('items', []):
print(token.get('applicationName'), token.get('kind'), token.get('clientId'), token.get('scopes'))
- Dominant language
- Python
- Stars
- 169
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from elastic/SWAT
-
Dependency DashboardOpen
Difficulty 5/5 Over a week Newbie friendliness 15/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 52/100
-
[Maintenance] Documentation Screenshots not RenderingMay be free again @terrancedejesus claimed this 1136 days ago, and no pull request is open. Opencommunity maintenance
-
[Feature Request] Create `add-emulation` commandMay be free again @brokensound77 claimed this 1173 days ago, and no pull request is open. Openenhancement
-
[Feature Request] Add Python module for detecting T1098.003 - Additional Cloud RolesMay be free again @terrancedejesus claimed this 1241 days ago, and no pull request is open. OpenAPI: Admin enhancement Subtechnique: 003 Tactic: Persistence Technique: T1098
Similar issues
-
docs pydanty:is-working
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
pydantic/pydantic-ai#9800 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
[Bug]: With --api-server-count > 1, gauges such as vllm:num_requests_running have no samples until the first requestPossibly taken @roy6n23 claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
vllm-project/vllm#59988 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
pymc-devs/pymc-examples#897 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 91/100