Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Failed to subscribe error in monitor mode #386

Open
ION28 opened this issue Sep 14, 2020 · 1 comment
Open

Failed to subscribe error in monitor mode #386

ION28 opened this issue Sep 14, 2020 · 1 comment

Comments

@ION28
Copy link
Owner

ION28 commented Sep 14, 2020

.\BLUESPAWN-client-x64.exe --monitor -a Cursory


 ____  ____  ____  ____  ____  ____  ____  ____  ____
||B ||||L ||||U ||||E ||||S ||||P ||||A ||||W ||||N ||
||__||||__||||__||||__||||__||||__||||__||||__||||__||
|/__\||/__\||/__\||/__\||/__\||/__\||/__\||/__\||/__\|




[*][LOW] Monitoring the system
[*][LOW] Setting up monitoring for T1036 - Masquerading
[*][LOW] Setting up monitoring for T1037 - Boot or Logon Initialization Scripts
[*][LOW] Setting up monitoring for T1053 - Scheduled Task/Job
[*][LOW] Setting up monitoring for T1055 - Process Injection
[*][LOW] Setting up monitoring for T1068 - Exploitation for Privilege Escalation
[*][LOW] Setting up monitoring for T1070 - Indicator Removal on Host
[WARNING] EventLogs::QueryEvents: Unable to find channel Microsoft-Windows-Sysmon/Operational
[*][LOW] Setting up monitoring for T1136 - Create Account
[*][LOW] Setting up monitoring for T1484 - Group Policy Modification
[*][LOW] Setting up monitoring for T1505 - Server Software Component
[*][LOW] Setting up monitoring for T1543 - Create or Modify System Process
[ERROR] Failed to subscribe to changes to  (Error 6)
[*][LOW] Setting up monitoring for T1546 - Event Triggered Execution
[*][LOW] Setting up monitoring for T1547 - Boot or Logon Autostart Execution
[*][LOW] Setting up monitoring for T1553 - Subvert Trust Controls
[*][LOW] Setting up monitoring for T1562 - Impair Defenses
[*][LOW] Setting up monitoring for T1569 - Service Execution
@ION28
Copy link
Owner Author

ION28 commented Sep 14, 2020

User also reported the program immediately exiting when running this in monitor mode

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants