[Feature Request] Add Python module for Creating a New Google Workspace Account
@brokensound77 已经在做这个了。
开始于 2023年5月9日。
评估
这个 Issue 还没有评估数据。
描述
🐍 Python Module for MITRE ATT&CK Technique
Tactic Name: Persistence
Technique Name: Create Account
Technique ID: T1136
Technique Description: Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Describe the solution you'd like
New Google Workspace Account Creation Module for use with a compromised GWS environment for Persistence.
Requirements:
- Google Admin SDK API enabled
- Python packages (google-auth google-auth-oauthlib google-auth-httplib2 google-api-python-client, email, base64)
- Scopes (https://www.googleapis.com/auth/admin.directory.user, https://www.googleapis.com/auth/admin.directory.rolemanagement)
Module Workflow:
Step 1: Enter the account first name:
Step 2: Enter the account last name:
Step 3: Enter the email for the account:
Step 4: Enter the password (temporary):
Step 5: Create
Module Actions:
1. Authenticate
2. Create a new user
3. Create a custom role with the desired permissions
4. Assign the role to the newly created user
5. Enable or disable API access for the user
6. Return Success with user email and password
ChatGPT Example Script
from google.oauth2 import service_account
from googleapiclient import discovery, errors
# Replace with your credentials file path and your Google Workspace domain
SERVICE_ACCOUNT_FILE = 'path/to/credentials.json'
DOMAIN = 'your-domain.com'
# Set up credentials with the required scopes
credentials = service_account.Credentials.from_service_account_file(
SERVICE_ACCOUNT_FILE,
scopes=['https://www.googleapis.com/auth/admin.directory.user',
'https://www.googleapis.com/auth/admin.directory.rolemanagement'])
# Create an Admin SDK API client
service = discovery.build('admin', 'directory_v1', credentials=credentials)
# Create a user
user_body = {
'primaryEmail': 'new-user@{}'.format(DOMAIN),
'name': {
'givenName': 'John',
'familyName': 'Doe'
},
'password': 'UserPassword123'
}
user = service.users().insert(body=user_body).execute()
# Create a custom role with specific permissions
role_body = {
'roleName': 'Custom Role',
'rolePrivileges': [
{
'privilegeName': 'User Management',
'serviceId': 'your-service-id'
}
]
}
role = service.roles().insert(customer='my_customer', body=role_body).execute()
# Assign the custom role to the user
assignment_body = {
'roleId': role['roleId'],
'assignedTo': user['id']
}
assignment = service.roleAssignments().insert(customer='my_customer', body=assignment_body).execute()
print('User created and custom role assigned')
- 主要语言
- Python
- 星标
- 169
- 派生
- 8
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
elastic/SWAT 的其他 Issue
-
难度 5/5 一周以上 新手友好度 15/100
-
bug
难度 3/5 1-2 天 新手友好度 52/100
-
[Maintenance] Documentation Screenshots not Rendering可能重新可做 @terrancedejesus 于 1131 天前认领,目前没有进行中的 PR。 未关闭community maintenance
-
[Feature Request] Create `add-emulation` command可能重新可做 @brokensound77 于 1168 天前认领,目前没有进行中的 PR。 未关闭enhancement
-
[Feature Request] Add Python module for detecting T1098.003 - Additional Cloud Roles可能重新可做 @terrancedejesus 于 1236 天前认领,目前没有进行中的 PR。 未关闭API: Admin enhancement Subtechnique: 003 Tactic: Persistence Technique: T1098
相似的 Issue
-
customer-reported
难度 2/5 1-3 小时 新手友好度 68/100
Azure/azure-cli#34150 · 1 条评论 ·
维护者通常 1 天内回复
-
community-request
难度 1/5 1 小时以内 新手友好度 95/100
NVIDIA-NeMo/Curator#2464 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
WeblateOrg/translation-finder#1099 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
trezor/trezor-firmware#7997 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复