BalCCon2k24

AttackMate: A modern open-source tool for automating cyberattacks
2024-09-22, 12:00–12:45 (Europe/Belgrade), Tesla

AttackMate is a modern open-source tool for automating cyberattacks. It supports scripting attack techniques across all kill chain phases and focuses on real-world attacks rather than purely simulated adversary behavior. AttackMate executes well-known exploits and publicly available malware and allows, therefore, variations of different attack techniques. One of AttackMate's significant advantages is that it combines several attack techniques into complex attack chains that reflect the behavior of advanced attackers. This talk explains the motivation behind the development of the AttackMate and illustrates possible use cases. It presents the essential concepts of the AttackMate framework and depicts how it extends the state of the art beyond existing tools. This presentation will provide an overview of the most valuable features of Attackmate. Eventually, the talk demonstrates how the AttackMate automatically exploits a target and gains root access.

Wolfgang Hotwagner is a research engineer in the Cyber Security Research Team at the Austrian Institute of Technology (AIT). He reported numerous security vulnerabilities in Open-Source projects and works on topics such as "Pentesting", "Log Anomaly Detection" and "Cyberrange".