Working from home
-
Akamai
- Remote
- salvatoresecurity.com
Block or Report
Block or report mssalvatore
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
guardicore/monkey Public
Infection Monkey - An open-source adversary emulation platform
4,041 contributions in the last year
Less
More
Activity overview
Contributed to
guardicore/monkey,
guardicode/serpentarium,
mssalvatore/infection-monkey-roadmap
and 21 other
repositories
Contribution activity
March 2023
Created 145 commits in 3 repositories
Created 1 repository
Created a pull request in guardicore/monkey that received 4 comments
Consolidate agent configuration service
What does this PR do?
Consolidates the agent configuration and schema services under a unified service. This eliminates the AgentConfigurationSchem…
+284
−201
•
4
comments
Opened 10 other pull requests in 1 repository
guardicore/monkey
10
merged
- 3077 get otp from env
- 2758 disable hadoop speculative execution
- Flask response utility
- Remove address to ip port
- 3032 replace netifaces with ifaddr
- Island: Fix logic error in AgentSignalsService
-
Handle defaults in
DIContainer - Agent: Add secret_type_filter callable
- 3039 smarter brute force credentials generator
- Consolidate agent configuration service resources
Reviewed 33 pull requests in 1 repository
guardicore/monkey
25 pull requests
- 2952 smb exploiter implementation
- Don't leak OTP in logs
- Island: Do manual "is user already registered" check
- Modify exploiters to use OTP in commands
- 3077 get otp from env
- Agent: Change http clients to use the OTP for authentication
- 2952 remove hard coded smb exploiter
- 3013 monkey island docker release
- AgentOTPProvider
- 3013 monkey island docker hub
- Add IOTPProvider
- Simplify authentication HTTP API
- SMB: Add SMBOptions to SMBPlugin
- 3040 generalize plugin scripts
- SMB: Add pipfile for dependencies
- Island: Add /api/register-agent endpoint
- Island: Add /api/request-otp endpoint
- 2157 consolidate authentication service logic
- Unregister flask security endpoints
- Docs: Update island password reset documentation
- Island: Disable default flask-security endpoints
- 2817 replace agent singleton
-
Handle defaults in
DIContainer - Island: Set terminate signal for duplicate agents
- 2817 add agent registration time field
- Some pull request reviews not shown.
Created an issue in guardicore/monkey that received 3 comments
Reduce risk of #2049
Spike Objective Reduce the risk associated with #2049 Scope Time bounded (1.25d) @VakarisZ Understand the proposed solution in #2049 Consider how …
3
comments
Opened 18 other issues in 2 repositories
guardicore/monkey
13
open
4
closed
- Agent IDs are inconsistent
- ETE tests fail
- Minor unit test improvements
- Test for XSS vulnerabilities
- OTP override for development only
- Authentication token renewal
- Implement OTP/AgentAuthentication in the Island
- Implement OTP compliance on the Agent
- Create mock OTP/Agent-Auth API endpoints
- Configuration import/export is broken
- Combine the agent log and island log repositories/engtoints into LogService
- Combine the AgentSignalsService and ISimulationRepository into SimulationService
- DockerHub Island image download tracking
- GitHub release asset download tracking
- Generalizable plugin build scripts
- Smarter brute forcing
- Switch from netifaces to ifaddr
niess/python-appimage
1
open
9
contributions
in private repositories
Mar 2 – Mar 17



