Kostas's banner
Kostas's profile picture

Kostas

@Kostastsale19,822 subscribers

I like building things that solve real problems, working across cybersecurity, product, and research | 🇬🇷🇨🇦

Shorts

Sometimes the call comes a little too late and you gotta do what you gotta do 😂

Sometimes the call comes a little too late and you gotta do what you gotta do 😂

11,535 次观看

I came across a great persistence mechanism and created a Sigma rule for it. Just drop your batch script or add a line that points to your payload inside C:\Windows\Setup\Scripts\ErrorHandler.cmd, and upon execution of C:\Windows\System32\oobe\Setup.exe, the payload will run. In the clip below, I have cmd.exe /c calc.exe as the payload. If ErrorHandler doesn't exist, you can create it along with the directory. Thanks to @Hexacorn for posting about it 🙏 In regards to the rest binaries under the C:\Windows\System32\oobe\ directory, most of them will not work, whereas others will force a restart (i.e. audit.exe) 🔗:

I came across a great persistence mechanism and created a Sigma rule for it. Just drop your batch script or add a line that points to your payload inside C:\Windows\Setup\Scripts\ErrorHandler.cmd, and upon execution of C:\Windows\System32\oobe\Setup.exe, the payload will run. In the clip below, I have cmd.exe /c calc.exe as the payload. If ErrorHandler doesn't exist, you can create it along with the directory. Thanks to @Hexacorn for posting about it 🙏 In regards to the rest binaries under the C:\Windows\System32\oobe\ directory, most of them will not work, whereas others will force a restart (i.e. audit.exe) 🔗:

17,501 次观看

Videos

没有更多内容可加载