Pivoting with PCAP with Core Impact

January 19, 2018

In this quick video, we show how the PCAP plugin can be installed and used in order to quickly and efficiently improve the speed of information gathering tasks.

Since installing the PCAP plugin requires administrative privileges, we'll begin by running a local escalation module. For this example, we'll use an exploit for the unpatched MS16-039 vulnerability.

When the module finishes, we'll then have a new agent running with SYSTEM privileges.

Pivoting and installing the PCAP plugin is as easy as right-clicking on the agent and selecting the proper options from the menu.

The PCAP plugin will be installed in the agent and we can benefit from it by being able to run information gathering modules such as Network Discovery or Port scanning using FAST techniques.

