Skip to content

Commit 803dafe

Browse files
committed
LaraC2 Shell -- MDE Live Response Interactive Shell
Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response. Dual API mode (Internal portal + Official public), 7 auth methods, 25 native LR commands plus arbitrary command execution via auto-uploaded B64 executor stubs, cross-OS targeting (Windows, Linux, macOS), transparent rate limiting and session lifecycle. MIT License. See README.md for full documentation.
0 parents  commit 803dafe

38 files changed

Lines changed: 26007 additions & 0 deletions
Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
@{
2+
Severity = @('Error', 'Warning')
3+
4+
ExcludeRules = @(
5+
# We use Write-Host intentionally for colored shell output.
6+
'PSAvoidUsingWriteHost',
7+
8+
# Private functions use _ prefix naming convention by design.
9+
'PSUseApprovedVerbs',
10+
11+
# ShouldProcess not needed for our internal state functions.
12+
'PSUseShouldProcessForStateChangingFunctions',
13+
14+
# ConvertTo-SecureString used for internal auth flows where the source
15+
# is already in-memory plaintext from the operator's interactive prompt.
16+
'PSAvoidUsingConvertToSecureStringWithPlainText',
17+
18+
# We use positional parameters in internal helpers for brevity.
19+
'PSAvoidUsingPositionalParameters',
20+
21+
# _Int_ConnectByCredential intentionally accepts Username+Password for
22+
# Entra credential auth flow; the same entry point also triggers the
23+
# plain-text parameter warning for the same reason.
24+
'PSAvoidUsingUsernameAndPasswordParams',
25+
'PSAvoidUsingPlainTextForPassword',
26+
27+
# Empty catch blocks are used intentionally for non-fatal cleanup and
28+
# best-effort state updates (rate limiter, library cleanup, auth
29+
# fallback). Making any of these fail loudly would break the shell
30+
# for transient conditions they are specifically designed to ignore.
31+
'PSAvoidUsingEmptyCatchBlock',
32+
33+
# Functions that return collections use plural nouns (Get-MDEMachines,
34+
# Get-MDEActions, Show-MDEMachines, etc.). This matches the MDE API
35+
# surface and how PowerShell itself handles collection-returning
36+
# cmdlets (Get-Process, Get-Service).
37+
'PSUseSingularNouns'
38+
)
39+
40+
Rules = @{
41+
PSUseCompatibleSyntax = @{
42+
Enable = $true
43+
TargetVersions = @('7.0')
44+
}
45+
}
46+
}

‎.gitattributes‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
*.yml text eol=lf
2+
*.yaml text eol=lf
3+
*.sh text eol=lf

‎.github/CODEOWNERS‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
# Code owners -- automatically requested for review on PRs
2+
* @akefallonitis

‎.github/CONTRIBUTING.md‎

Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
# Contributing to LaraC2 Shell
2+
3+
Thank you for your interest in contributing. This document provides guidelines for contributing to LaraC2 Shell.
4+
5+
## Getting Started
6+
7+
1. **Fork** the repository
8+
2. **Clone** your fork locally
9+
3. **Create a branch** for your changes: `git checkout -b feature/my-feature`
10+
4. **Make your changes** and add tests
11+
5. **Run tests** to verify nothing is broken
12+
6. **Commit** with a clear message
13+
7. **Push** and open a Pull Request
14+
15+
## Development Setup
16+
17+
```powershell
18+
# Prerequisites: PowerShell Core 7.0+, Pester 5.x, PSScriptAnalyzer
19+
Install-Module -Name Pester -MinimumVersion 5.0 -Scope CurrentUser
20+
Install-Module -Name PSScriptAnalyzer -Scope CurrentUser
21+
22+
# Run offline tests (no MDE tenant needed)
23+
pwsh -NoProfile -Command "Invoke-Pester -Path tests/shell/LaraC2Shell.Offline.Tests.ps1 -Output Detailed"
24+
25+
# Run the same lint CI runs
26+
pwsh -NoProfile -Command "Invoke-ScriptAnalyzer -Path ./shell -Recurse -Settings ./.config/PSScriptAnalyzerSettings.psd1"
27+
```
28+
29+
## Code Style
30+
31+
- Follow existing patterns in the codebase
32+
- Use `[CmdletBinding()]` and proper parameter validation
33+
- Include `.SYNOPSIS` and `.PARAMETER` documentation for public functions
34+
- Private helper functions use `_` prefix (e.g., `_Out-Info`, `_Parse-Response`)
35+
- PSScriptAnalyzer runs on every PR -- check `.config/PSScriptAnalyzerSettings.psd1` for rules
36+
37+
## Testing
38+
39+
- **All PRs must pass offline tests** (712+ tests, no credentials needed) and the PSScriptAnalyzer lint job
40+
- Add tests for new features or bug fixes
41+
- Test files go in `tests/shell/` following the existing naming convention
42+
- Online tests require an MDE tenant and are run separately
43+
44+
## Pull Request Process
45+
46+
1. Ensure all offline tests pass
47+
2. Update documentation if your change affects user-facing behavior
48+
3. Keep PRs focused -- one feature or fix per PR
49+
4. Describe what your PR does and why in the description
50+
51+
## Reporting Issues
52+
53+
- Use GitHub Issues with the provided templates
54+
- Include: PowerShell version, OS, error messages, steps to reproduce
55+
- For security vulnerabilities, follow [SECURITY.md](../SECURITY.md) -- do not open a public issue
56+
57+
## License
58+
59+
By contributing, you agree that your contributions will be licensed under the MIT License.
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
---
2+
name: Bug Report
3+
about: Report a bug or unexpected behavior
4+
title: '[BUG] '
5+
labels: bug
6+
---
7+
8+
## Description
9+
10+
<!-- Clear description of the bug -->
11+
12+
## Steps to Reproduce
13+
14+
1.
15+
2.
16+
3.
17+
18+
## Expected Behavior
19+
20+
<!-- What should have happened -->
21+
22+
## Actual Behavior
23+
24+
<!-- What actually happened. Include error messages. -->
25+
26+
## Environment
27+
28+
- **OS**: <!-- e.g., Windows 11, Ubuntu 22.04, macOS 14 -->
29+
- **PowerShell version**: <!-- output of $PSVersionTable.PSVersion -->
30+
- **API mode**: <!-- Official / Internal -->
31+
- **Auth method**: <!-- e.g., client credentials, device code, TOTP -->
32+
33+
## Additional Context
34+
35+
<!-- Screenshots, logs, config excerpts (redact secrets!) -->
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
name: Feature Request
3+
about: Suggest a new feature or improvement
4+
title: '[FEATURE] '
5+
labels: enhancement
6+
---
7+
8+
## Description
9+
10+
<!-- What feature would you like to see? -->
11+
12+
## Use Case
13+
14+
<!-- Why is this feature needed? What problem does it solve? -->
15+
16+
## Proposed Solution
17+
18+
<!-- How should it work? Include examples if possible. -->
19+
20+
## Alternatives Considered
21+
22+
<!-- Any alternative approaches you've considered? -->

‎.github/PULL_REQUEST_TEMPLATE.md‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
## Description
2+
3+
<!-- What does this PR do? Why is this change needed? -->
4+
5+
## Type of Change
6+
7+
- [ ] Bug fix
8+
- [ ] New feature
9+
- [ ] Documentation update
10+
- [ ] Refactoring (no functional change)
11+
- [ ] Test coverage improvement
12+
13+
## Testing
14+
15+
- [ ] All offline tests pass (`Invoke-Pester -Path tests/shell/LaraC2Shell.Offline.Tests.ps1`)
16+
- [ ] New tests added for changed functionality
17+
- [ ] Tested on: Windows / Linux / macOS (delete as appropriate)
18+
19+
## Checklist
20+
21+
- [ ] Code follows existing style and patterns
22+
- [ ] Documentation updated (if user-facing change)
23+
- [ ] No credentials, secrets, or machine-specific data committed
24+
- [ ] PSScriptAnalyzer passes (checked by CI)

‎.github/dependabot.yml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# Keep GitHub Actions versions patched automatically.
2+
# Docs: https://docs.github.com/en/code-security/dependabot/working-with-dependabot
3+
version: 2
4+
updates:
5+
- package-ecosystem: "github-actions"
6+
directory: "/"
7+
schedule:
8+
interval: "weekly"
9+
open-pull-requests-limit: 5
10+
commit-message:
11+
prefix: "ci"

0 commit comments

Comments
 (0)