Source: GitHub
Author: unknown
URL: https://github.com/cyb3rfox/ghost
https://github.com/cyb3rfox/ghost
ONE SENTENCE SUMMARY:
GHOST Framework 2.0 provides zero-footprint testing of EDR solutions through versatile remote execution and multi-target orchestration capabilities.
MAIN POINTS:
- GHOST offers a controlled, repeatable method for EDR testing using multiple remote execution methods.
- Version 2.0 adds orchestration for multi-target testing and features like pivoting support.
- Supports execution methods: WMI, PowerShell Remoting, and WinRS.
- Automatic detection of best method and lateral movement targets is included.
- Provides HTML reporting with visual dashboards for analysis.
- Multi-target orchestration supports group-based target organization and automatic pivot discovery.
- Interactive setup available with script
Start-GHOST.ps1for ease of use. - Execution methods comparison highlights best use cases for WMI, PSRemoting, WinRS, and Auto.
- The framework uses JSON configuration files for target and credential management.
- Includes standard, advanced, and minimal test suites for EDR validation.
TAKEAWAYS:
- GHOST Framework leaves no footprint on target systems during testing.
- Multi-method execution engine allows flexibility in testing environments.
- Configuration is managed through JSON files, supporting customization for various needs.
- Comprehensive documentation includes error troubleshooting and test pattern addition.
- Offers robust logging and automatic path conversion for ease of use and traceability.