Skip to content

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 20:27
· 71 commits to main since this release

Everything new in this release came out of one real infection: a credential
stealer that Microsoft Defender never flagged, which relaunched itself through
MSBuild from a hidden scheduled task and was still sitting there a day later. A
full offline Defender scan removed one dropped file; the launcher and the
persistence survived it. Each feature below closes a specific gap that let that
happen.

What is new since v0.1.0

Canary files. Decoy files that exist only to be stolen — a fake saved-password
database, a fake wallet, a fake recovery phrase. Nothing on the machine uses
them, so a read has no innocent explanation. Windows' own auditing records which
process read one, and which account it ran as. No driver, no third party,
nothing on the network. This closes the gap the watcher could not: the theft
itself, which in the original case was over in about three minutes.

A behaviour watcher. The agent now takes a cheap snapshot every two minutes
and records anything newly registered to start itself in the shape unwanted
software uses — a launcher running a script from a writable folder, a hidden
scheduled task, an unsigned script in AppData. It writes to the audit log and
the window, and never acts on its own.

Launcher-aware persistence. The scanner resolves what a launcher is told to
run and judges that. A stealer's script hiding behind cmd.exe /c is no longer
scored as "signed by Microsoft, lives in System32", which is exactly what let the
original task look like part of Windows.

A browser extension inventory. An extension that can read every page is in
practical terms a program holding your passwords and session cookies, and it has
no signature to check and starts nothing at boot — so the rest of the tool was
blind to it. It calls nothing malicious; it reports what each one may do.

A Defender hardening report. Windows ships nineteen Attack Surface Reduction
rules, free and switched off. Seven are worth recommending and three target this
exact attack. It reports which are on and what each would prevent, and
deliberately refuses to switch them on for you.

Two new YARA rules: browser credential theft, and a build tool used as a
loader.

Install

Unzip anywhere. Keep both executables in the same folder — the agent only
serves clients installed alongside it, so separating them stops the shell
working.

Run kam-shell.exe. For the fast disk scan and the behaviour watcher, install
the agent as a service from an administrator terminal:

kam-agent.exe --install
sc start KamSecurityAgent

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them.
That is expected for an unsigned tool that enumerates every file on disk and runs
an elevated service. Verify the checksum against SHA256SUMS.txt, and build from
source if you would rather not trust a download.

There is still no installer, and the binaries are still unsigned. Both are
recorded as deliberate decisions in PLAN.md rather than oversights.