Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PurpleSharp is not available inside the tools directory #31

Open
RahulIngenious opened this issue Feb 15, 2024 · 5 comments
Open

PurpleSharp is not available inside the tools directory #31

RahulIngenious opened this issue Feb 15, 2024 · 5 comments
Assignees

Comments

@RahulIngenious
Copy link

Hi @iknowjason ,

as per the lab (Microsoft Sentinel lab with AD, deployed with terraform. Adds logging best practices with Sysmon.) demonstration PurpleSharp tool is supposed to be available in the tools directory of the host. However, when i ran the query or checked it manually i couldn't find any. Could you please look into this?

Also, i would like to know once this issue is resolved. After running this PrupleSharp adversary emulation tool. Would i be able to see the alerts in Defender for endpoint for the same?
PS: I have installed Defender for Endpoint on both hosts.

PurpleSharp

@iknowjason
Copy link
Owner

Hi @RahulIngenious

Yes, I will look into this and help get it resolved for you. It might be that the PurpleSharp download link has changed. I will verify.

What do you mean by, as per the lab (Microsoft Sentinel lab with AD, deployed with terraform? You mean the generator python script that creates this lab scenario? Or something outside of PurpleCloud tool?

Jason

@RahulIngenious
Copy link
Author

@iknowjason - Yes, the generator python script that creates this lab scenario

@iknowjason
Copy link
Owner

iknowjason commented Feb 15, 2024

@RahulIngenious

I just tested on a new lab and PurpleSharp downloads. In your case it could have been any kind of issue like a temporary networking issue. I"m attaching three images of what you can check on your end.

Why don't you just download PurpleSharp onto your system since it apparently didn't download? The bootstrap script shows the command. I will copy and paste it here. Open up a powershell admin session and type this:

Invoke-WebRequest -Uri "https://github.com/mvelazc0/PurpleSharp/releases/download/v1.3/PurpleSharp_x64.exe" -OutFile "C:\tools\PurpleSharp.exe"

@iknowjason
Copy link
Owner

Take a look at the user_data logfile and see what you see here. It should show something like this. It might give a clue as to why it didn't work for you.
pc1

This is what it looks like on my end, PurpleSharp automatically downloaded.

pc2

If it didn't download, just run that powershell in comment above and it will download.

pc3

@iknowjason
Copy link
Owner

@RahulIngenious

After you run PurpleSharp it should be able to generate alerts. As for Windows Defender endpoint, I can't troubleshoot your system on that.

@iknowjason iknowjason self-assigned this Feb 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants