<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=ALanners</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=ALanners"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/ALanners"/>
	<updated>2026-09-10T13:02:56Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13488</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13488"/>
		<updated>2024-01-04T12:57:26Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Lateral Movement */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE20”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
Lateral movement consists of techniques to compromise other systems in the victim network and make their way through the system landscape to the target. This involves repeatedly gaining access to the various systems that have been discovered. This can be done using own tools for lateral movement or using stolen credentials, which allows the use of native OS tools and is therefore less conspicuous. Examples of techniques include internal spearphishing and remote services such as RDP.&amp;lt;ref name=”RE17”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
In the course of the collection, information is gathered as potentially useful sources. The second step after collection often consists of exfiltration, i.e. stealing data. Classic files such as audio, video, email, browsers etc. are often of interest here. Screenshots or keyboard input can also be exfiltrated. &amp;lt;ref name=”RE18”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
Command and control is used to ensure that the compromised system can be communicated with in the victim network and can therefore be controlled. An attempt is made to package the C2 traffic in such a way that it imitates normal traffic. For example, different application layer protocols such as FTP, MAIL or DNS can be used for obfuscation. &amp;lt;ref name=”RE19”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13487</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13487"/>
		<updated>2024-01-04T12:52:01Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Collection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE20”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE17”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
In the course of the collection, information is gathered as potentially useful sources. The second step after collection often consists of exfiltration, i.e. stealing data. Classic files such as audio, video, email, browsers etc. are often of interest here. Screenshots or keyboard input can also be exfiltrated. &amp;lt;ref name=”RE18”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
Command and control is used to ensure that the compromised system can be communicated with in the victim network and can therefore be controlled. An attempt is made to package the C2 traffic in such a way that it imitates normal traffic. For example, different application layer protocols such as FTP, MAIL or DNS can be used for obfuscation. &amp;lt;ref name=”RE19”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13486</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13486"/>
		<updated>2024-01-04T12:48:24Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Command and Controll */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE20”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE17”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE18”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
Command and control is used to ensure that the compromised system can be communicated with in the victim network and can therefore be controlled. An attempt is made to package the C2 traffic in such a way that it imitates normal traffic. For example, different application layer protocols such as FTP, MAIL or DNS can be used for obfuscation. &amp;lt;ref name=”RE19”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13485</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13485"/>
		<updated>2024-01-04T12:45:31Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE20”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE17”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE18”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE19”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13484</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13484"/>
		<updated>2024-01-04T12:44:55Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE17”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE18”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE19”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13483</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13483"/>
		<updated>2024-01-04T12:44:30Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Lateral Movement&amp;quot; - available under: https://attack.mitre.org/tactics/TA0008/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Collection&amp;quot; - available under: https://attack.mitre.org/tactics/TA0009/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Command and Controll&amp;quot; - available under: https://attack.mitre.org/tactics/TA00011/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13482</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13482"/>
		<updated>2024-01-04T12:43:32Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Discovery */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
In order to obtain further information about the system landscape and the network, the perpetrators observe the digital environment so that they can then plan further steps. They always look at what the attackers can currently control and what they can gain from this or how they can use it to achieve their goals.&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13481</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13481"/>
		<updated>2024-01-04T12:34:15Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
The aim of the attacker is to steal credentials in order to be able to move laterally in the network, for example. Techniques such as keylogging or credential dumping using Mimikatz are used for this purpose.  If the attackers obtain legitimate credentials, it is also much more difficult to track down the attackers in their own systems and networks. &amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Credential Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0006/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
&amp;lt;ref name=”RE16”&amp;gt;&amp;quot;Discovery&amp;quot; - available under: https://attack.mitre.org/tactics/TA0007/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13480</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13480"/>
		<updated>2024-01-04T12:27:15Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
To avoid the compromise being noticed, use attack techniques of defence evasion. For example, security software can be switched off or uninstalled, or payloads and data can be encrypted and obfuscated. In addition, legitimate processes can be misused to carry out the attackers&#039; activities and thus conceal them. &lt;br /&gt;
&amp;lt;ref name=”RE15”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0005/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13479</id>
		<title>MITRE ATT&amp;CK</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=MITRE_ATT%26CK&amp;diff=13479"/>
		<updated>2024-01-04T12:23:03Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Developed by MITRE, ATT&amp;amp;CK is a globally accessible knowledge base focused on adversary behaviour - also called cyber threat intelligence . Cyber adversaries are known for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information an data to disrupting infrastructure and/or damaging business operations.&lt;br /&gt;
The MITRE ATT&amp;amp;CK knowledge-base is freely available to everyone. The knowledge base documents the common tactics, techniques and procedures used by cyber threat actors. The framework can be used as a resource for the development of specific threat models and methodologies, as well as the development of specific countermeasures. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;MITRE ATT&amp;amp;CK&amp;quot; - available under: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Groups==&lt;br /&gt;
The groups are &amp;quot;activity clusters&amp;quot; that are often observed in the cyber security bubble under a specific name. It should be noted that groups in the cybersecurity sector are often loosely connected and may be known by several names. In addition, it can happen that the same clusters are tracked by different actors under different names. In the context of the MITRE Groups documentation, the MITRE team endeavours to document the overlaps under the Associated Groups/Aliases section. Groups are in turn linked to techniques that are assigned to the respective tactics. As a result, there is a separate ATT&amp;amp;CK matrix for many groups. &amp;lt;ref name=”RE8”&amp;gt;&amp;quot;Groups&amp;quot; - available under: https://attack.mitre.org/groups/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Software==&lt;br /&gt;
According to MITRE, software is defined as &amp;quot;operating system utilities, open-source software, or other tools used to conduct behaviour modeled in ATT&amp;amp;CK&amp;quot;. &lt;br /&gt;
Analogous to offender groups, there are also artefacts in the area of software that are known by different names but are the same software. Each entry in the software documentation contains a technical artefact, which in turn can be assigned to a group. The information is based on open source.&lt;br /&gt;
&lt;br /&gt;
MITRE distinguishes between tools and malware:&lt;br /&gt;
A tool is software that can be used by Defender, Pentester as well as redteamer or threat actors. This includes software that is not found in the corporate context as well as software that is used in the corporate context.&lt;br /&gt;
In contrast to tools, malware is designed to carry out malicious actions on the targetsystem.&amp;lt;ref name=”RE9”&amp;gt;&amp;quot;Software&amp;quot; - available under: https://attack.mitre.org/software/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Techniques==&lt;br /&gt;
Techniques in the context of the MITRE ATT&amp;amp;CK knowledge base describe how an attacker achieves a tactical objective, i.e. which actions he performs to achieve it. As a striking example, the threat actor can, for example, dump credentials in order to gain access to the victim&#039;s credentials. As of January 2023, a total of 201 techniques are documented with a total of 424 sub-techniques. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Enterprise Techniques&amp;quot; - available under: https://attack.mitre.org/techniques/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Tactics==&lt;br /&gt;
Tactics documented the why of an ATT&amp;amp;CK technique or sub-technique, it is therefore the actual target of the attacker. The targets reflect the respective process steps of the MITRE ATT&amp;amp;CK matrix - i.e. from reconnaissance to impact. For example, an attacker can use credential access or privilege escalation as a tactic. &amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Enterprise tactics&amp;quot; - available under: https://attack.mitre.org/tactics/enterprise/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==MITRE ATT&amp;amp;CK Matrix==&lt;br /&gt;
&lt;br /&gt;
The MITRE ATT&amp;amp;CK matrix is part of the knowledge base and provides actor-specific techniques and procedures for each phase of the attack. The process begins with reconnaissance and ends with impact. Different techniques and tactics are assigned to each process step, which can be clicked on and which then lead to documentation. &amp;lt;ref name=”RE4”&amp;gt;&amp;quot;ATT&amp;amp;CK Matrix&amp;quot; - available under: https://attack.mitre.org/#  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[File:MITRE_ATT%26CK_Matrix.png|frameless|center|caption]] &lt;br /&gt;
&lt;br /&gt;
In addition to the Enterprise Matrix, there is a matrix for Mobile and one for ICS &lt;br /&gt;
&lt;br /&gt;
===Reconnaissance===&lt;br /&gt;
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&amp;amp;CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. &amp;lt;ref name=”RE5”&amp;gt;&amp;quot;Reconnaissance&amp;quot; - available under: https://attack.mitre.org/tactics/TA0043/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Ressource Development===&lt;br /&gt;
Resource development encompasses methods by which adversaries generate, acquire, or steal resources to support their targeting activities. These resources may include infrastructure, accounts or capabilities. The threat actors can use these resources at different stages of their lifecycle - for example by using purchased or stolen domains for command and control infrastructure, using email accounts for phishing during initial access or acquiring code signing certificates to facilitate defence evasion. &amp;lt;ref name=”RE6”&amp;gt;&amp;quot;Resource Development&amp;quot; - available under: https://attack.mitre.org/tactics/TA0042/  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Initial Access===&lt;br /&gt;
Initial access consists of methods that the attackers use to gain a foothold in the victim&#039;s infrastructure. These include spearphishing, content injection or exploiting a vulnerability. A distinction can be made between measures that grant continuous access or temporary access, as passwords change continuously, for example.&lt;br /&gt;
&amp;lt;ref name=”RE7”&amp;gt;&amp;quot;Initial Access&amp;quot; - available under: https://attack.mitre.org/tactics/TA0001/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Execution===&lt;br /&gt;
Execution consists of executing the attacker&#039;s malicious code on the target system. Techniques from this phase are often combined with techniques from other phases in order to achieve several goals at once. Examples of techniques include the use of a command and script interpreter such as Powershell to execute malicious scripts or user execution of a malicious file. &amp;lt;ref name=”RE10”&amp;gt;&amp;quot;Execution&amp;quot; - available under: https://attack.mitre.org/tactics/TA0002/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Persistence===&lt;br /&gt;
Once threat actors have gained access to the system, they want to maintain access. This is ensured in the course of persistence. The attackers ensure that access is maintained by restarting the system, changing access data and making other changes. An example of this technique is the addition of code during boot or logon autostart execution.&amp;lt;ref name=”RE11”&amp;gt;&amp;quot;Persistence&amp;quot; - available under: https://attack.mitre.org/tactics/TA0003/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Privilege Escalation===&lt;br /&gt;
The aim is to ensure higher privileges - higher level permissions on systems and networks - based on the existing access. Higher privileges are often needed to achieve the actual goals. System weaknesses, misconfigurations and vulnerabilities are often exploited to achieve higher privileges.&lt;br /&gt;
According to MITRE, the target stages are, for example &amp;lt;ref name=”RE14”&amp;gt;&amp;quot; Privilege Escalation &amp;quot; - available under: https://attack.mitre.org/tactics/TA0004/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
* SYSTEM/root level&lt;br /&gt;
* local administrator&lt;br /&gt;
* user account with admin-like access&lt;br /&gt;
* user accounts with access to specific system or perform specific function&lt;br /&gt;
&lt;br /&gt;
===Defense Evasion===&lt;br /&gt;
&lt;br /&gt;
===Credential Access===&lt;br /&gt;
&lt;br /&gt;
===Discovery===&lt;br /&gt;
&lt;br /&gt;
===Lateral Movement===&lt;br /&gt;
&lt;br /&gt;
===Collection===&lt;br /&gt;
&lt;br /&gt;
===Command and Controll===&lt;br /&gt;
&lt;br /&gt;
===Exfiltration===&lt;br /&gt;
Techniques in the exfiltration phase are used to steal data from the victim&#039;s infrastructure. Once the data has been collected, it is compressed and encrypted to prevent detection. Subsequently, the transfer between victim and threat actor often takes place via C&amp;amp;C. Exfiltration techniques are i.e. data transfer size limits to avoid detection and, as mentioned, exfiltration over C2 channels. &amp;lt;ref name=”RE13”&amp;gt;&amp;quot;Exfiltration&amp;quot; - available under: https://attack.mitre.org/tactics/TA0010/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Impact===&lt;br /&gt;
Basically, the attackers have at least goal. This target is reached during the impact phase and systems or data are manipulated, disrupted or destroyed. Techniques are used that enable the threat actor to impair the availability or integrity of the business or processes. It should be noted that the symptoms are not always noticed immediately and the objectives can also be achieved without the victim realising it directly. A striking example would be the deletion of an account access or data destruction. &amp;lt;ref name=”RE12”&amp;gt;&amp;quot;Impact&amp;quot; - available under: https://attack.mitre.org/tactics/TA0040/ - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13478</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13478"/>
		<updated>2024-01-04T12:02:27Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Reconnaissance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz. The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* Two external wireless adapter, whereby the following can be recommended: 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
To find out which networks exist in the environment and which devices are associated with which network, the airodump-ng tool can be used for reconnaissance. The information such as BSSID, SSID or channel is important for the next steps.&lt;br /&gt;
&lt;br /&gt;
The following command can be used for starting the reconnaissance using airodump-ng:&lt;br /&gt;
  sudo airodump-ng &amp;lt;interface&amp;gt; -b abg&lt;br /&gt;
&lt;br /&gt;
The attributes a,b,g describe the bands on which airodump should sniff should sniff. &#039;b&#039; and &#039;g&#039; use 2.4GHz and &#039;a&#039; uses 5GHz&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
With the pre-installed tools airmon-ng, airodump-ng, airbase-ng and aireplay-ng in Kali Linux, it is possible to initiate both a rogue access point and an Evil Twin attack. The only significant drawback is that these tools do not offer a captive portal option.&lt;br /&gt;
&lt;br /&gt;
An access point can be spawned as follows:&lt;br /&gt;
  sudo airbase-ng -e &amp;lt;wifiname&amp;gt; -c &amp;lt;channel&amp;gt; &amp;lt;interface&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To increase the range of the access point, the transmission power can be increased:&lt;br /&gt;
  sudo iwconfig interface txpower &amp;lt;NmW/NdBm&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In addition to the tools in the corresponding Deauth chapter, a Deauth attack can also be carried out using aireplay-ng:&lt;br /&gt;
  sudo aireplay-ng --deauth 50 -a &amp;lt;BSSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13477</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13477"/>
		<updated>2024-01-04T11:59:46Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Spawning Rogue Access Point */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz. The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* Two external wireless adapter, whereby the following can be recommended: 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
With the pre-installed tools airmon-ng, airodump-ng, airbase-ng and aireplay-ng in Kali Linux, it is possible to initiate both a rogue access point and an Evil Twin attack. The only significant drawback is that these tools do not offer a captive portal option.&lt;br /&gt;
&lt;br /&gt;
An access point can be spawned as follows:&lt;br /&gt;
  sudo airbase-ng -e &amp;lt;wifiname&amp;gt; -c &amp;lt;channel&amp;gt; &amp;lt;interface&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To increase the range of the access point, the transmission power can be increased:&lt;br /&gt;
  sudo iwconfig interface txpower &amp;lt;NmW/NdBm&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In addition to the tools in the corresponding Deauth chapter, a Deauth attack can also be carried out using aireplay-ng:&lt;br /&gt;
  sudo aireplay-ng --deauth 50 -a &amp;lt;BSSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13476</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13476"/>
		<updated>2024-01-04T11:15:22Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Hardware requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz. The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* Two external wireless adapter, whereby the following can be recommended: 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13475</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13475"/>
		<updated>2024-01-04T11:12:44Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Hands-on report */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz. The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13474</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13474"/>
		<updated>2024-01-04T11:12:35Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Hands-on report */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz. The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13473</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13473"/>
		<updated>2024-01-04T11:12:22Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Hands-on report */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
*When starting a rogue access point with aireplay and without an external Wireless Adapter, an error message may appear. This can be rectified by increasing the MTU. This is not easily possible on the internal interface on the Raspberry Pi and is blocked as the kernel does not support an MTU higher than 1500. There are then 2 options: Option (1): revise kernel settings and recompile or option (2): use external network antenna. Due to the risk and the necessary knowledge, option (2) is preferable. This means that an external Wi-Fi adapter is required as a wireless network interface. In addition, actions can be carried out on both 2.4 GHz and 5 GHz when using an appropriate network adapter. Without an external antenna, you can only work on 2.4 GHz.&lt;br /&gt;
The external network adapter choosen for the lab was an Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter. In the Linux environment, care should also be taken to ensure that the network adapters work with the respective distribution and kernel and that a corresponding driver is available. According to the manufacturer, the Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter can be used with Kali Linux without any problems.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13472</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13472"/>
		<updated>2024-01-04T11:09:12Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Rogue Access Point */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Spawning Rogue Access Point ===&lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13471</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13471"/>
		<updated>2024-01-04T11:08:58Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Deauthentication attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC address of the TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC address client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13470</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13470"/>
		<updated>2024-01-04T11:08:36Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Deauthentication attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC Adresse des TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC Adresse Client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 for Deauthentication&lt;br /&gt;
     0  Number of deauths to be sent, 0 means, &lt;br /&gt;
        that they are sent continuously&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13469</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13469"/>
		<updated>2024-01-04T11:07:59Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Deauthentication attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 2.4 GHz:&lt;br /&gt;
  aireplay-ng -0 0 -a &amp;lt;MAC Adresse des TargetAP&amp;gt; -c &lt;br /&gt;
  &amp;lt;MAC Adresse Client&amp;gt; &amp;lt;interfacename&amp;gt;&lt;br /&gt;
     -0 fuer Deauthentication&lt;br /&gt;
     0  Anzahl der zu sendenden Deauths, 0 bedeutet, &lt;br /&gt;
        dass sie kontinuierlich gesendet werden&lt;br /&gt;
&lt;br /&gt;
For carrying out a deauth attack on 5 GHz:&lt;br /&gt;
  sudo mdk4 &amp;lt;interface&amp;gt; d -E &amp;lt;WLAN SSID&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13468</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13468"/>
		<updated>2024-01-04T11:06:46Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Deauthentication attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack ===&lt;br /&gt;
Deauthentication attacks are a subtle yet serious threat. The targeted de-authentication attacks, which aim to remove connected devices from a Wi-Fi network, have the potential to have a significant impact on the availability and integrity of connections.&lt;br /&gt;
&lt;br /&gt;
The channel of the AP or the devices that are connected to the AP can be taken from the reconnaissance. For setting the channel on the Wi-Fi adapter:&lt;br /&gt;
  sudo iwlist &amp;lt;interface&amp;gt; channel&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power off&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; channel {channel, ex. &amp;quot;23&amp;quot;}&lt;br /&gt;
  sudo iwconfig &amp;lt;interface&amp;gt; power on&lt;br /&gt;
&lt;br /&gt;
To check whether the channel has been set&lt;br /&gt;
  sudo iwlist {interface} channel&lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13467</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13467"/>
		<updated>2024-01-04T11:03:13Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Alternative all-in-one frameworks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
All-in-one frameworks that combine the activities described above in one software are, for example, [https://wiki.elvis.science/index.php?title=Wifiphisher wifiphisher] and [https://wiki.elvis.science/index.php?title=Wifipumpkin3 wifipumpkin3]&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13466</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13466"/>
		<updated>2024-01-04T10:58:52Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Field report */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Hands-on report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13465</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13465"/>
		<updated>2024-01-04T10:58:30Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are:&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13464</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13464"/>
		<updated>2024-01-04T10:58:18Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13463</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13463"/>
		<updated>2024-01-04T10:58:10Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
The main scenarios in the context of rogue access points or Evil Twins are&lt;br /&gt;
* Machine-in-the-Middle/Content Injection tion&lt;br /&gt;
* Malicious webpages through e.g. DNS spoofing&lt;br /&gt;
* Deauthentication attacks&lt;br /&gt;
* Technique for social engineering for more in-depth scenarios&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13462</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13462"/>
		<updated>2024-01-04T10:55:19Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Evil Twin using native Kali Linux Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Can be used to carry out reconnaissance. All surrounding networks and associated devices can be detected.&lt;br /&gt;
* Airbase-ng: Can be used to create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: Can be used to carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: dns-masq can be used to set up a DNS server. Furthermore activation of a corresponding route on the interfaces as well as enabling IP forwarding and setting up firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13461</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13461"/>
		<updated>2024-01-04T10:53:30Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Evil Twin using native Kali Linux Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
The following tools are all pre-installed on Kali Linux. All of the tools listed can be used to carry out an Evil Twin attack:&lt;br /&gt;
* Airmon-ng: Display interfaces and stop potentially disruptive processes.&lt;br /&gt;
* Airodump-ng: Operate for reconnaissance operate - all networks and connected devices.&lt;br /&gt;
* Airbase-ng: Create a Wi-Fi access point. created.&lt;br /&gt;
* Aireplay-ng: To carry out deauth- attacks&lt;br /&gt;
* Accompanying activities: Using dns- masq can be used to set up a DNS server can be set up. Activation of route on the corresponding interface as well as IP forwarding and corresponding firewall rules.&lt;br /&gt;
&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13460</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13460"/>
		<updated>2024-01-04T10:49:09Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising. Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13459</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13459"/>
		<updated>2024-01-04T10:48:48Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Potential measures to protect against Evil Twins */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the case of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13458</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13458"/>
		<updated>2024-01-04T10:48:34Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Evil Twin using native Kali Linux Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
=== Hardware requirements ===&lt;br /&gt;
At least the following hardware is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
=== Reconnaissance ===&lt;br /&gt;
&lt;br /&gt;
=== Rogue Access Point === &lt;br /&gt;
&lt;br /&gt;
=== Deauthentication attack === &lt;br /&gt;
&lt;br /&gt;
=== Alternative all-in-one frameworks ===&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13457</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13457"/>
		<updated>2024-01-04T10:43:58Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Field report */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
Kali Linux on a Raspberry Pi was tested extensively in the course of setting up an Evil Twin. Overall, the installation of the latest version of Kali Linux (as of December 2023) on a Raspberry Pi is not recommended for testing and lab purposes. The use for spawning an Evil Twin can also be achieved with other Linux systems, which is why it should be determined whether Kali Linux is absolutely necessary.&lt;br /&gt;
The following bugs were observed:&lt;br /&gt;
* After installing dependencies that were necessary to start Wifiphisher and Wifipumpkin 3, there were more boot problems&lt;br /&gt;
* Overall, booting was often prone to errors. Depending on the connected screen, it took several attempts.&lt;br /&gt;
* There were often non-reproducible bugs when starting programmes. For example, Wifiphisher did not work from time to time, no networks could be displayed and the like. The bugs occurred randomly and could not be reproduced.&lt;br /&gt;
* There were also bugs in the GUI area. For example, the bar for maximising, minimising and closing windows suddenly disappeared and it was no longer possible to move windows. To fix this, the corresponding driver had to be restarted.&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
At least the following kit is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13456</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13456"/>
		<updated>2024-01-04T10:34:51Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Evil Twin */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
At least the following kit is required to set up an Evil Twin:&lt;br /&gt;
* Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
* 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13455</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13455"/>
		<updated>2024-01-04T10:34:32Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Evil Twin using native Kali Linux Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
At least the following kit is required to set up an Evil Twin:&lt;br /&gt;
- Raspberry Pi 4 Model B - 8GB incl. accessories such as power cable and MicroSD&lt;br /&gt;
- 2 x Alfa AWUS036ACH Wide Range AC1200 Wireless Adapter&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13454</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13454"/>
		<updated>2024-01-04T10:32:59Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm Kali Linux on ARM] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4 Install Kali Linux on Raspberry Pi 3 &amp;amp; 4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13453</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13453"/>
		<updated>2024-01-04T10:32:09Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
For example, Kali Linux can be installed on a Raspberry Pi 4 Model B with 8 GB RAM. The Raspberry Pi 4 Model B is equipped with a Broadcom BCM2711, Quad core Cortex-A72 (ARM v8) 64-bit SoC @ 1.8GHz. This information is relevant because Kali Linux provides an image specifically for ARM processors on their website.&lt;br /&gt;
This image can be downloaded at [https://www.kali.org/get-kali/#kali-arm] The Raspberry Pi 4 is equipped with a 64-bit processor and supports the execution of 64-bit images. This results in two options: Either the Kali Linux RaspberryPi 2, 3, 4 32-bit or 64-bit image can be selected, whereby more documentation is available for the 32-bit variant. In addition, the 32-bit image ran with fewer problems than the 64-bit image during practical tests.&lt;br /&gt;
To get the image onto the Raspberry Pi, it must be transferred to a micro SD card. Balena Etcher or similar software can be used for this purpose.&lt;br /&gt;
Once the image has been successfully transferred to the SD card, it can be inserted into the corresponding slot on the Raspberry Pi 4. This can then be started and Kali Linux will boot from the SD card. The username and password are kali/kali.&lt;br /&gt;
&lt;br /&gt;
A more detailed guide to installing Kali Linux on a Raspberry Pi can be found in the following article: [https://wiki.elvis.science/index.php?title=Install_Kali_Linux_on_Raspberry_Pi_3_%26_4]&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13452</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13452"/>
		<updated>2024-01-04T10:29:47Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Potential measures to protect against Evil Twins ==&lt;br /&gt;
Organisational measures are closely linked to personal measures. As an organisational measure, it can be established, for example, that different passwords must be used for different services and applications. This can prevent the same password being used for VPN access as for Wi-Fi access. In the corporate context, the operation of a structured and continuously improving information security management system can also be categorised as an organisational measure.&lt;br /&gt;
&lt;br /&gt;
In the client-side area, care can be taken to ensure that the devices are configured so that only that only TLS-encrypted connections (e.g. HTTPS) are permitted. are allowed. This at least prevents the rogue access point from accessing data in plain text or manipulate it unnoticed.&lt;br /&gt;
&lt;br /&gt;
The use of a VPN can also be recommended as a technical measure against MitM attacks. This is usually accompanied by increased information security through encryption of the traffic, which prevents transmitted data from being read or manipulated. In the context of a Wi-Fi MitM attack, a VPN hides the client&#039;s communication, encrypts the network traffic and hides metadata such as IP addresses or domain names.&lt;br /&gt;
&lt;br /&gt;
Personal measures focus on the end user. Awareness-raising measures in particular can be derived in this context. It is important to sensitise users to the existing risks, make them aware and motivate them to support and implement the technical and organisational security measures. An easy-to-understand personal measure can be, for example, to pay attention to Wi-Fi names and other irregularities and to report these to the relevant reporting centres in the event of anomalies. This allows a quick response in the event of an emergency.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13451</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13451"/>
		<updated>2024-01-04T10:26:01Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;br /&gt;
&lt;br /&gt;
== Kali Linux on Raspberry Pi ==&lt;br /&gt;
&lt;br /&gt;
=== Field report ===&lt;br /&gt;
&lt;br /&gt;
== Evil Twin ==&lt;br /&gt;
&lt;br /&gt;
=== Evil Twin using native Kali Linux Tools ===&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13450</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13450"/>
		<updated>2024-01-03T21:47:51Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a framework for spawning malicious access points, especially designed for red team deployments and Wi-Fi security pentesting. The framework allows pentester to perform man-in-the-middle attacks against wireless clients. Wifiphisher can run on devices such as the Raspberry Pi.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The framework utilises modern Wi-Fi techniques and tactics such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons. Wifiphisher is characterised by its modularity, allowing users to develop customized Python modules to extend the tool. Furthermore custom phishing scenarios for specific targeted attacks can be created.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. The process can ne launched with a simple command, while advanced users can take advantage of its many features per command line. The interactive text-based console interface guides users through process of an attack, ensuring usability for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE2”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/extra-phishing-pages  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
Installation:&lt;br /&gt;
&lt;br /&gt;
Firstly, you have to install the dependencies:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get install hostapd dnsmasq python-pyric python-jinja2&lt;br /&gt;
&lt;br /&gt;
Wifiphisher can be cloned from the corresponding gitrepo:&lt;br /&gt;
&lt;br /&gt;
  git clone https://github.com/wifiphisher/wifiphisher.git&lt;br /&gt;
  cd wifiphisher&lt;br /&gt;
  sudo python setup.py install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifiphisher can also be installed as follows:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get -y install wifiphisher&lt;br /&gt;
&lt;br /&gt;
Starting wifiphisher:&lt;br /&gt;
&lt;br /&gt;
  sudo wifiphisher&lt;br /&gt;
&lt;br /&gt;
After wifiphisher has been started, a process is run through in which the network to be imitated and the corresponding captive portal can be selected. The deauth process then starts. The big advantage of Wifiphisher over other frameworks such as Wifipumpkin3 is that the captive portal can be accessed via https and the user therefore does not receive a warning when entering the access data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Help section:&lt;br /&gt;
  sudo wifiphisher -h&lt;br /&gt;
&lt;br /&gt;
All possible options, apart from the standard process, can be taken from the help section.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13447</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13447"/>
		<updated>2024-01-03T21:37:01Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a framework for spawning malicious access points, especially designed for red team deployments and Wi-Fi security pentesting. The framework allows pentester to perform man-in-the-middle attacks against wireless clients. Wifiphisher can run on devices such as the Raspberry Pi.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The framework utilises modern Wi-Fi techniques and tactics such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons. Wifiphisher is characterised by its modularity, allowing users to develop customized Python modules to extend the tool. Furthermore custom phishing scenarios for specific targeted attacks can be created.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. Beginners can launch the tool with a simple command, while advanced users can take advantage of its many features. The interactive, text-based user interface guides testers through the creation of attacks, ensuring accessibility for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE2”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/extra-phishing-pages  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
Installation:&lt;br /&gt;
&lt;br /&gt;
Firstly, you have to install the dependencies:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get install hostapd dnsmasq python-pyric python-jinja2&lt;br /&gt;
&lt;br /&gt;
Wifiphisher can be cloned from the corresponding gitrepo:&lt;br /&gt;
&lt;br /&gt;
  git clone https://github.com/wifiphisher/wifiphisher.git&lt;br /&gt;
  cd wifiphisher&lt;br /&gt;
  sudo python setup.py install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifiphisher can also be installed as follows:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get -y install wifiphisher&lt;br /&gt;
&lt;br /&gt;
Starting wifiphisher:&lt;br /&gt;
&lt;br /&gt;
  sudo wifiphisher&lt;br /&gt;
&lt;br /&gt;
After wifiphisher has been started, a process is run through in which the network to be imitated and the corresponding captive portal can be selected. The deauth process then starts. The big advantage of Wifiphisher over other frameworks such as Wifipumpkin3 is that the captive portal can be accessed via https and the user therefore does not receive a warning when entering the access data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Help section:&lt;br /&gt;
  sudo wifiphisher -h&lt;br /&gt;
&lt;br /&gt;
All possible options, apart from the standard process, can be taken from the help section.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13445</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13445"/>
		<updated>2024-01-03T21:07:54Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a robust malicious access point framework designed for red team deployments and Wi-Fi security testing. Wifiphisher allows penetration testers to take a man-in-the-middle position against wireless clients by performing targeted Wi-Fi mapping attacks. Wifiphisher can run on devices such as the Raspberry Pi and utilises modern Wi-Fi association techniques such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons&amp;quot;, making it a powerful tool for extended operations.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Flexibility is one of the key features of Wifiphisher, which supports a variety of arguments and provides a collection of phishing templates for different deployment scenarios. Wifiphisher is characterised by its modularity, allowing users to develop both simple and complex Python modules to extend the tool&#039;s functionality or create custom phishing scenarios for specific targeted attacks.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. Beginners can launch the tool with a simple command, while advanced users can take advantage of its many features. The interactive, text-based user interface guides testers through the creation of attacks, ensuring accessibility for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE2”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/extra-phishing-pages  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
Installation:&lt;br /&gt;
&lt;br /&gt;
Firstly, you have to install the dependencies:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get install hostapd dnsmasq python-pyric python-jinja2&lt;br /&gt;
&lt;br /&gt;
Wifiphisher can be cloned from the corresponding gitrepo:&lt;br /&gt;
&lt;br /&gt;
  git clone https://github.com/wifiphisher/wifiphisher.git&lt;br /&gt;
  cd wifiphisher&lt;br /&gt;
  sudo python setup.py install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifiphisher can also be installed as follows:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get -y install wifiphisher&lt;br /&gt;
&lt;br /&gt;
Starting wifiphisher:&lt;br /&gt;
&lt;br /&gt;
  sudo wifiphisher&lt;br /&gt;
&lt;br /&gt;
After wifiphisher has been started, a process is run through in which the network to be imitated and the corresponding captive portal can be selected. The deauth process then starts. The big advantage of Wifiphisher over other frameworks such as Wifipumpkin3 is that the captive portal can be accessed via https and the user therefore does not receive a warning when entering the access data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Help section:&lt;br /&gt;
  sudo wifiphisher -h&lt;br /&gt;
&lt;br /&gt;
All possible options, apart from the standard process, can be taken from the help section.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13444</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13444"/>
		<updated>2024-01-03T21:07:22Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* First steps */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a robust malicious access point framework designed for red team deployments and Wi-Fi security testing. Wifiphisher allows penetration testers to take a man-in-the-middle position against wireless clients by performing targeted Wi-Fi mapping attacks. Wifiphisher can run on devices such as the Raspberry Pi and utilises modern Wi-Fi association techniques such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons&amp;quot;, making it a powerful tool for extended operations.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Flexibility is one of the key features of Wifiphisher, which supports a variety of arguments and provides a collection of phishing templates for different deployment scenarios. Wifiphisher is characterised by its modularity, allowing users to develop both simple and complex Python modules to extend the tool&#039;s functionality or create custom phishing scenarios for specific targeted attacks.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. Beginners can launch the tool with a simple command, while advanced users can take advantage of its many features. The interactive, text-based user interface guides testers through the creation of attacks, ensuring accessibility for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE2”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
Installation:&lt;br /&gt;
&lt;br /&gt;
Firstly, you have to install the dependencies:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get install hostapd dnsmasq python-pyric python-jinja2&lt;br /&gt;
&lt;br /&gt;
Wifiphisher can be cloned from the corresponding gitrepo:&lt;br /&gt;
&lt;br /&gt;
  git clone https://github.com/wifiphisher/wifiphisher.git&lt;br /&gt;
  cd wifiphisher&lt;br /&gt;
  sudo python setup.py install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifiphisher can also be installed as follows:&lt;br /&gt;
&lt;br /&gt;
  sudo apt-get -y install wifiphisher&lt;br /&gt;
&lt;br /&gt;
Starting wifiphisher:&lt;br /&gt;
&lt;br /&gt;
  sudo wifiphisher&lt;br /&gt;
&lt;br /&gt;
After wifiphisher has been started, a process is run through in which the network to be imitated and the corresponding captive portal can be selected. The deauth process then starts. The big advantage of Wifiphisher over other frameworks such as Wifipumpkin3 is that the captive portal can be accessed via https and the user therefore does not receive a warning when entering the access data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Help section:&lt;br /&gt;
  sudo wifiphisher -h&lt;br /&gt;
&lt;br /&gt;
All possible options, apart from the standard process, can be taken from the help section.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13443</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13443"/>
		<updated>2024-01-03T21:01:30Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a robust malicious access point framework designed for red team deployments and Wi-Fi security testing. Wifiphisher allows penetration testers to take a man-in-the-middle position against wireless clients by performing targeted Wi-Fi mapping attacks. Wifiphisher can run on devices such as the Raspberry Pi and utilises modern Wi-Fi association techniques such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons&amp;quot;, making it a powerful tool for extended operations.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Flexibility is one of the key features of Wifiphisher, which supports a variety of arguments and provides a collection of phishing templates for different deployment scenarios. Wifiphisher is characterised by its modularity, allowing users to develop both simple and complex Python modules to extend the tool&#039;s functionality or create custom phishing scenarios for specific targeted attacks.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. Beginners can launch the tool with a simple command, while advanced users can take advantage of its many features. The interactive, text-based user interface guides testers through the creation of attacks, ensuring accessibility for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE2”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13442</id>
		<title>Wifiphisher</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifiphisher&amp;diff=13442"/>
		<updated>2024-01-03T21:00:57Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifiphisher is a comprehensive framework for setting up rogue access points. The framework can be used during penetration tests to test Wi-Fi security, among other things. At the same time, with Wifiphisher an Evil Twin can be setup and used to test personal measures such as security awareness.&lt;br /&gt;
&lt;br /&gt;
== Wifiphisher == &lt;br /&gt;
Wifiphisher is a robust malicious access point framework designed for red team deployments and Wi-Fi security testing. Wifiphisher allows penetration testers to take a man-in-the-middle position against wireless clients by performing targeted Wi-Fi mapping attacks. Wifiphisher can run on devices such as the Raspberry Pi and utilises modern Wi-Fi association techniques such as &amp;quot;Evil Twin&amp;quot;, &amp;quot;KARMA&amp;quot; and &amp;quot;Known Beacons&amp;quot;, making it a powerful tool for extended operations.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;wifiphisher &amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Flexibility is one of the key features of Wifiphisher, which supports a variety of arguments and provides a collection of phishing templates for different deployment scenarios. Wifiphisher is characterised by its modularity, allowing users to develop both simple and complex Python modules to extend the tool&#039;s functionality or create custom phishing scenarios for specific targeted attacks.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Despite its advanced capabilities, Wifiphisher remains user-friendly. Beginners can launch the tool with a simple command, while advanced users can take advantage of its many features. The interactive, text-based user interface guides testers through the creation of attacks, ensuring accessibility for users with varying levels of knowledge.&amp;lt;ref name=”RE1”/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Community based phishing pages ==&lt;br /&gt;
Since wifiphisher is community based, there are some extensions. Community-based phishing pages can be highlighted as an example. For example, there are phishing templates that imitate instagram, google or starbucks pages.&amp;lt;ref name=”RE1”&amp;gt;&amp;quot;extra-phishing-pages&amp;quot; - available under: https://github.com/wifiphisher/wifiphisher  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== First steps ==&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13427</id>
		<title>Evil Twin Attack via Kali on Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Twin_Attack_via_Kali_on_Raspberry_Pi&amp;diff=13427"/>
		<updated>2024-01-03T18:19:00Z</updated>

		<summary type="html">&lt;p&gt;ALanners: Created page with &amp;quot;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An Evil Twin is a rogue access point designed to imitate a legitimate access point in order to carry out malicious actions such as phising.Regular laptops and Wi-Fi adapters can be used to set up an Evil Twin, or Raspberry Pis, as these are quite small and can be easily packed into a bagpack when powered by a battery bank. This setup can then be left in one place for several days, for example, during which time the AP can phish information.&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13426</id>
		<title>Wifipumpkin3</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13426"/>
		<updated>2024-01-03T18:14:04Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifipumpkin3 is a framework for setting up rogue access points and the associated evil twins. The framework is written in Python. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;Wifipumpkin3&amp;quot; - available under: https://github.com/P0cL4bs/wifipumpkin3  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
According to the authors, the main features of the framework are as follows &amp;lt;ref name=”RE1”/&amp;gt;:&lt;br /&gt;
    Rogue access point attack&lt;br /&gt;
    Man-in-the-middle attack&lt;br /&gt;
    Module for deauthentication attack&lt;br /&gt;
    Module for extra-captiveflask templates&lt;br /&gt;
    Rogue Dns Server&lt;br /&gt;
    Captive portal attack (captiveflask)&lt;br /&gt;
    Intercept, inspect, modify and replay web traffic&lt;br /&gt;
    WiFi networks scanning&lt;br /&gt;
    DNS monitoring service&lt;br /&gt;
    Credentials harvesting&lt;br /&gt;
    Phishkin3 (Support MFA phishing attack via captive portal)&lt;br /&gt;
    EvilQR3 (Support Phishing QR code attack)&lt;br /&gt;
    Transparent Proxies&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Wifipumpkin3 is written in Python3, which is why the installation of Python3 (version 3.7 or later) is required. In addition, it requires a Wi-Fi adapter that allows access point (AP) mode. &lt;br /&gt;
Windows and Mac OSX are currently (01.01.2024) not supported. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Getting Started - Installation&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation: &#039;&#039;&#039;&lt;br /&gt;
  &lt;br /&gt;
Dependencies should be installed first:&lt;br /&gt;
   sudo apt install python3.7-dev libssl-dev libffi-dev build-essential python3.7&lt;br /&gt;
&lt;br /&gt;
Then wifipumpkin3 can be cloned from the github repo and uninstalled:&lt;br /&gt;
   git clone https://github.com/P0cL4bs/wifipumpkin3.git&lt;br /&gt;
   cd wifipumpkin3&lt;br /&gt;
   sudo make install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifipumpkin3 can be installed under Kali Linux (2022.2) as follows:&lt;br /&gt;
   sudo apt install wifipumpkin3&lt;br /&gt;
&lt;br /&gt;
== Some examples of use ==&lt;br /&gt;
The operation of wifipumpkin3 is reminiscent of the operation of Metasploit. The framework can be started as follows:&lt;br /&gt;
   sudo wp3&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The following commands are relevant for setting up an Evil Twin:&amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Getting Started - Usage&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#usage  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Display all information/parameters about the access point to be spawned:&lt;br /&gt;
   ap&lt;br /&gt;
&lt;br /&gt;
As in Metasploit, the variables of the AP can be set with set:&lt;br /&gt;
   set&lt;br /&gt;
&lt;br /&gt;
Display installed proxies:&lt;br /&gt;
   proxies&lt;br /&gt;
&lt;br /&gt;
A proxy can be activated or set as follows:&lt;br /&gt;
   set proxy proxy_name&lt;br /&gt;
&lt;br /&gt;
The configured access point can be started with the following command: &lt;br /&gt;
   start&lt;br /&gt;
&lt;br /&gt;
The AP then starts according to the entered configurations, whereby, depending on the proxy, the traffic or the connected devices and intercepted credentials of the captive portal are then displayed, for example.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
According to the author, wifipumpkin3 comes with the following pre-installed proxies&amp;lt;ref name=”RE4”&amp;gt;&amp;quot;Getting Started - Proxies&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#proxies  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
   pumpkinproxy - Proxy for intercept network traffic on TCP protocol.&lt;br /&gt;
   captiveflask - Allow block Internet access for users until they open the page login page.&lt;br /&gt;
   noproxy - Runnning without proxy redirect traffic&lt;br /&gt;
&lt;br /&gt;
The respective options of a proxy can also be defined with true/false. For example, pumpkinproxy offers options for html_injection or javascript injection, which can be defined and activated as required. Similarly, the captive portal can be defined for the captive flask proxy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13425</id>
		<title>Wifipumpkin3</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13425"/>
		<updated>2024-01-03T18:13:44Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifipumpkin3 is a framework for setting up rogue access points and the associated evil twins. The framework is written in Python. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;Wifipumpkin3&amp;quot; - available under: https://github.com/P0cL4bs/wifipumpkin3  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
According to the authors, the main features of the framework are as follows &amp;lt;ref name=”RE1”/&amp;gt;:&lt;br /&gt;
    Rogue access point attack&lt;br /&gt;
    Man-in-the-middle attack&lt;br /&gt;
    Module for deauthentication attack&lt;br /&gt;
    Module for extra-captiveflask templates&lt;br /&gt;
    Rogue Dns Server&lt;br /&gt;
    Captive portal attack (captiveflask)&lt;br /&gt;
    Intercept, inspect, modify and replay web traffic&lt;br /&gt;
    WiFi networks scanning&lt;br /&gt;
    DNS monitoring service&lt;br /&gt;
    Credentials harvesting&lt;br /&gt;
    Phishkin3 (Support MFA phishing attack via captive portal)&lt;br /&gt;
    EvilQR3 (Support Phishing QR code attack)&lt;br /&gt;
    Transparent Proxies&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Wifipumpkin3 is written in Python3, which is why the installation of Python3 (version 3.7 or later) is required. In addition, it requires a Wi-Fi adapter that allows access point (AP) mode. &lt;br /&gt;
Windows and Mac OSX are currently (01.01.2024) not supported. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Getting Started - Installation&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation: &#039;&#039;&#039;&lt;br /&gt;
  &lt;br /&gt;
Dependencies should be installed first:&lt;br /&gt;
   sudo apt install python3.7-dev libssl-dev libffi-dev build-essential python3.7&lt;br /&gt;
&lt;br /&gt;
Then wifipumpkin3 can be cloned from the github repo and uninstalled:&lt;br /&gt;
   git clone https://github.com/P0cL4bs/wifipumpkin3.git&lt;br /&gt;
   cd wifipumpkin3&lt;br /&gt;
   sudo make install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifipumpkin3 can be installed under Kali Linux (2022.2) as follows:&lt;br /&gt;
   sudo apt install wifipumpkin3&lt;br /&gt;
&lt;br /&gt;
== Some examples of use ==&lt;br /&gt;
The operation of wifipumpkin3 is reminiscent of the operation of Metasploit. The framework can be started as follows:&lt;br /&gt;
   sudo wp3&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The following commands are relevant for setting up an Evil Twin:&amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Getting Started - Usage&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#usage  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Display all information/parameters about the access point to be spawned:&lt;br /&gt;
   ap&lt;br /&gt;
&lt;br /&gt;
As in Metasploit, the variables of the AP can be set with set:&lt;br /&gt;
   set&lt;br /&gt;
&lt;br /&gt;
Display installed proxies:&lt;br /&gt;
   proxies&lt;br /&gt;
&lt;br /&gt;
A proxy can be activated or set as follows:&lt;br /&gt;
   set proxy proxy_name&lt;br /&gt;
&lt;br /&gt;
The configured access point can be started with the following command: &lt;br /&gt;
   start&lt;br /&gt;
&lt;br /&gt;
The AP then starts according to the entered configurations, whereby, depending on the proxy, the traffic or the connected devices and intercepted credentials of the captive portal are then displayed, for example.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
According to the author, wifipumpkin3 comes with the following pre-installed proxies&amp;lt;ref name=”RE4”&amp;gt;&amp;quot;Getting Started - Proxies&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#proxies  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;:&lt;br /&gt;
   pumpkinproxy - Proxy for intercept network traffic on TCP protocol doc&lt;br /&gt;
   captiveflask - Allow block Internet access for users until they open the page login page. doc&lt;br /&gt;
   noproxy - Runnning without proxy redirect traffic&lt;br /&gt;
&lt;br /&gt;
The respective options of a proxy can also be defined with true/false. For example, pumpkinproxy offers options for html_injection or javascript injection, which can be defined and activated as required. Similarly, the captive portal can be defined for the captive flask proxy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13424</id>
		<title>Wifipumpkin3</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13424"/>
		<updated>2024-01-03T18:13:20Z</updated>

		<summary type="html">&lt;p&gt;ALanners: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifipumpkin3 is a framework for setting up rogue access points and the associated evil twins. The framework is written in Python. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;Wifipumpkin3&amp;quot; - available under: https://github.com/P0cL4bs/wifipumpkin3  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
According to the authors, the main features of the framework are as follows &amp;lt;ref name=”RE1”/&amp;gt;:&lt;br /&gt;
    Rogue access point attack&lt;br /&gt;
    Man-in-the-middle attack&lt;br /&gt;
    Module for deauthentication attack&lt;br /&gt;
    Module for extra-captiveflask templates&lt;br /&gt;
    Rogue Dns Server&lt;br /&gt;
    Captive portal attack (captiveflask)&lt;br /&gt;
    Intercept, inspect, modify and replay web traffic&lt;br /&gt;
    WiFi networks scanning&lt;br /&gt;
    DNS monitoring service&lt;br /&gt;
    Credentials harvesting&lt;br /&gt;
    Phishkin3 (Support MFA phishing attack via captive portal)&lt;br /&gt;
    EvilQR3 (Support Phishing QR code attack)&lt;br /&gt;
    Transparent Proxies&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Wifipumpkin3 is written in Python3, which is why the installation of Python3 (version 3.7 or later) is required. In addition, it requires a Wi-Fi adapter that allows access point (AP) mode. &lt;br /&gt;
Windows and Mac OSX are currently (01.01.2024) not supported. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Getting Started - Installation&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation: &#039;&#039;&#039;&lt;br /&gt;
  &lt;br /&gt;
Dependencies should be installed first:&lt;br /&gt;
   sudo apt install python3.7-dev libssl-dev libffi-dev build-essential python3.7&lt;br /&gt;
&lt;br /&gt;
Then wifipumpkin3 can be cloned from the github repo and uninstalled:&lt;br /&gt;
   git clone https://github.com/P0cL4bs/wifipumpkin3.git&lt;br /&gt;
   cd wifipumpkin3&lt;br /&gt;
   sudo make install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifipumpkin3 can be installed under Kali Linux (2022.2) as follows:&lt;br /&gt;
   sudo apt install wifipumpkin3&lt;br /&gt;
&lt;br /&gt;
== Some examples of use ==&lt;br /&gt;
The operation of wifipumpkin3 is reminiscent of the operation of Metasploit. The framework can be started as follows:&lt;br /&gt;
   sudo wp3&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The following commands are relevant for setting up an Evil Twin:&amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Getting Started - Usage&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#usage  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Display all information/parameters about the access point to be spawned:&lt;br /&gt;
   ap&lt;br /&gt;
&lt;br /&gt;
As in Metasploit, the variables of the AP can be set with set:&lt;br /&gt;
   set&lt;br /&gt;
&lt;br /&gt;
Display installed proxies:&lt;br /&gt;
   proxies&lt;br /&gt;
&lt;br /&gt;
A proxy can be activated or set as follows:&lt;br /&gt;
   set proxy proxy_name&lt;br /&gt;
&lt;br /&gt;
The configured access point can be started with the following command: &lt;br /&gt;
   start&lt;br /&gt;
&lt;br /&gt;
The AP then starts according to the entered configurations, whereby, depending on the proxy, the traffic or the connected devices and intercepted credentials of the captive portal are then displayed, for example.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE4”&amp;gt;&amp;quot;Getting Started - Proxies&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#proxies  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
According to the author, wifipumpkin3 comes with the following pre-installed proxies:&lt;br /&gt;
   pumpkinproxy - Proxy for intercept network traffic on TCP protocol doc&lt;br /&gt;
   captiveflask - Allow block Internet access for users until they open the page login page. doc&lt;br /&gt;
   noproxy - Runnning without proxy redirect traffic&lt;br /&gt;
&lt;br /&gt;
The respective options of a proxy can also be defined with true/false. For example, pumpkinproxy offers options for html_injection or javascript injection, which can be defined and activated as required. Similarly, the captive portal can be defined for the captive flask proxy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13423</id>
		<title>Wifipumpkin3</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13423"/>
		<updated>2024-01-03T18:10:15Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Some examples of use */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifipumpkin3 is a framework for setting up rogue access points and the associated evil twins. The framework is written in Python. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;Wifipumpkin3&amp;quot; - available under: https://github.com/P0cL4bs/wifipumpkin3  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
According to the authors, the main features of the framework are as follows &amp;lt;ref name=”RE1”/&amp;gt;:&lt;br /&gt;
    Rogue access point attack&lt;br /&gt;
    Man-in-the-middle attack&lt;br /&gt;
    Module for deauthentication attack&lt;br /&gt;
    Module for extra-captiveflask templates&lt;br /&gt;
    Rogue Dns Server&lt;br /&gt;
    Captive portal attack (captiveflask)&lt;br /&gt;
    Intercept, inspect, modify and replay web traffic&lt;br /&gt;
    WiFi networks scanning&lt;br /&gt;
    DNS monitoring service&lt;br /&gt;
    Credentials harvesting&lt;br /&gt;
    Phishkin3 (Support MFA phishing attack via captive portal)&lt;br /&gt;
    EvilQR3 (Support Phishing QR code attack)&lt;br /&gt;
    Transparent Proxies&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Wifipumpkin3 is written in Python3, which is why the installation of Python3 (version 3.7 or later) is required. In addition, it requires a Wi-Fi adapter that allows access point (AP) mode. &lt;br /&gt;
Windows and Mac OSX are currently (01.01.2024) not supported. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Getting Started - Installation&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation: &#039;&#039;&#039;&lt;br /&gt;
  &lt;br /&gt;
Dependencies should be installed first:&lt;br /&gt;
   sudo apt install python3.7-dev libssl-dev libffi-dev build-essential python3.7&lt;br /&gt;
&lt;br /&gt;
Then wifipumpkin3 can be cloned from the github repo and uninstalled:&lt;br /&gt;
   git clone https://github.com/P0cL4bs/wifipumpkin3.git&lt;br /&gt;
   cd wifipumpkin3&lt;br /&gt;
   sudo make install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifipumpkin3 can be installed under Kali Linux (2022.2) as follows:&lt;br /&gt;
   sudo apt install wifipumpkin3&lt;br /&gt;
&lt;br /&gt;
== Some examples of use ==&lt;br /&gt;
The operation of wifipumpkin3 is reminiscent of the operation of Metasploit. The framework can be started as follows:&lt;br /&gt;
   sudo wp3&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The following commands are relevant for setting up an Evil Twin:&amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Getting Started - Usage&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#usage  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Display all information/parameters about the access point to be spawned:&lt;br /&gt;
   ap&lt;br /&gt;
&lt;br /&gt;
As in Metasploit, the variables of the AP can be set with set:&lt;br /&gt;
   set&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Display installed proxies:&lt;br /&gt;
   proxies&lt;br /&gt;
&lt;br /&gt;
A proxy can be activated or set as follows:&lt;br /&gt;
   set proxy proxy_name&lt;br /&gt;
&lt;br /&gt;
The configured access point can be started with the following command: &lt;br /&gt;
   start&lt;br /&gt;
&lt;br /&gt;
The AP then starts according to the entered configurations, whereby, depending on the proxy, the traffic or the connected devices and intercepted credentials of the captive portal are then displayed, for example.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE4”&amp;gt;&amp;quot;Getting Started - Proxies&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#proxies  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13422</id>
		<title>Wifipumpkin3</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wifipumpkin3&amp;diff=13422"/>
		<updated>2024-01-03T18:03:29Z</updated>

		<summary type="html">&lt;p&gt;ALanners: /* Installation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wifipumpkin3 is a framework for setting up rogue access points and the associated evil twins. The framework is written in Python. &amp;lt;ref name=”RE1”&amp;gt;&amp;quot;Wifipumpkin3&amp;quot; - available under: https://github.com/P0cL4bs/wifipumpkin3  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
According to the authors, the main features of the framework are as follows &amp;lt;ref name=”RE1”/&amp;gt;:&lt;br /&gt;
    Rogue access point attack&lt;br /&gt;
    Man-in-the-middle attack&lt;br /&gt;
    Module for deauthentication attack&lt;br /&gt;
    Module for extra-captiveflask templates&lt;br /&gt;
    Rogue Dns Server&lt;br /&gt;
    Captive portal attack (captiveflask)&lt;br /&gt;
    Intercept, inspect, modify and replay web traffic&lt;br /&gt;
    WiFi networks scanning&lt;br /&gt;
    DNS monitoring service&lt;br /&gt;
    Credentials harvesting&lt;br /&gt;
    Phishkin3 (Support MFA phishing attack via captive portal)&lt;br /&gt;
    EvilQR3 (Support Phishing QR code attack)&lt;br /&gt;
    Transparent Proxies&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Wifipumpkin3 is written in Python3, which is why the installation of Python3 (version 3.7 or later) is required. In addition, it requires a Wi-Fi adapter that allows access point (AP) mode. &lt;br /&gt;
Windows and Mac OSX are currently (01.01.2024) not supported. &amp;lt;ref name=”RE2”&amp;gt;&amp;quot;Getting Started - Installation&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Installation: &#039;&#039;&#039;&lt;br /&gt;
  &lt;br /&gt;
Dependencies should be installed first:&lt;br /&gt;
   sudo apt install python3.7-dev libssl-dev libffi-dev build-essential python3.7&lt;br /&gt;
&lt;br /&gt;
Then wifipumpkin3 can be cloned from the github repo and uninstalled:&lt;br /&gt;
   git clone https://github.com/P0cL4bs/wifipumpkin3.git&lt;br /&gt;
   cd wifipumpkin3&lt;br /&gt;
   sudo make install&lt;br /&gt;
&lt;br /&gt;
Alternatively, wifipumpkin3 can be installed under Kali Linux (2022.2) as follows:&lt;br /&gt;
   sudo apt install wifipumpkin3&lt;br /&gt;
&lt;br /&gt;
== Some examples of use ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE3”&amp;gt;&amp;quot;Getting Started - Usage&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#usage  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=”RE4”&amp;gt;&amp;quot;Getting Started - Proxies&amp;quot; - available under: https://wifipumpkin3.github.io/docs/getting-started#proxies  - Retrieved 2024-01-01.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>ALanners</name></author>
	</entry>
</feed>