Proof of concept exploit for ManagedITSync (Kaseya & ConnectWise integration)
-
Updated
Nov 7, 2017 - Python
Proof of concept exploit for ManagedITSync (Kaseya & ConnectWise integration)
This repository contains a script created by Truesec CSIRT team which can be used to identify signs of compromise and to some extent, mitigate further risk to a Kaseya monitored endpoint.
Using Powershell to send an ENTER keystroke to the Kaseya prompt window
PowerShell wrapper for the MyITProcess API
Toggle between enabling and disabling the Kaseya Remote Control
Simple KQL query that can be run either in MD for Endpoint (Threat hunting or Custom indicator) or in Azure Sentinel (Threat hunting or analytics rule).It's looking for 4 known IOCs related to the Kaseya attack
Add a description, image, and links to the kaseya topic page so that developers can more easily learn about it.
To associate your repository with the kaseya topic, visit your repo's landing page and select "manage topics."