Back home
中文

ENDPOINT & ADVERSARY

Endpoint & Adversary Techniques

Endpoint tradecraft, privilege and persistence techniques, and adversary implementation research.

All categories

NOTE

Note

3

PROCEDURE

Procedure

56
01
Malicious Macro Launches a bat Script Through the Shell Function to Execute Commands
02
Launching Calculator by Invoking Malicious Macro Code Through Word Template Injection
03
Creating a Scheduled Task Through Macro Code
04
Using Bad-PDF to Steal NTLM Hashes from a Windows Host
05
Exporting Domain Credential Files Through Direct Volume Access with NinjaCopy
06
Stealing Domain Users' Plaintext Passwords with a Windows Password Filter DLL
07
Dumping Domain Cached Credentials (mscash) with cachedump
08
Abusing Security Support Provider (SSP) to Steal Domain Controller User Credentials
09
Exporting User Credentials from the Proc File System Through MimiPenguin
10
Obtaining Domain Password Credentials with NtdsAudit
11
Using C++ to Call ntdll.RtlCompressBuffer to Compress Collected Data
12
SNMP Service Brute Force and Information Gathering
13
Testing Target Connectivity with the Test-Connection Function in PowerShell
14
Collecting Information on windows with powershell and Saving It to the File System as html
15
Gathering Network Information on windows Systems Through Command Execution
16
Verifying a User's Working Environment by Counting Files in the Documents Directory
17
Detecting a Sandbox Environment by Calculating Active Window Titles and Checking a Specific Module
18
mavinject.exe
19
Arbitrary Command Execution Using the Mssql sp_procoption Stored Procedure
20
Injecting Malicious Code into a Legitimate Process Through Process Hollowing and Executing It
21
Creating a windows Service with powershell
22
Creating a Scheduled Task with powershell
23
Achieving Persistence by Adding a Registry Startup Entry with a powershell Script
24
Maintaining Access by Combining the Windows Screen Saver Feature with MSF
25
Maintaining Access to a Windows System with a Word WLL Add-In
26
Maintaining Access by Creating a windows System Service Backdoor with powershell
27
Maintaining Access by Abusing a systemd Timer to Create a Scheduled Task
28
Creating a Scheduled Task Through the ITaskService COM Component to Achieve Automatic Startup
29
Maintaining Access to a Windows System Through DLL Hijacking Combined with MSF
30
Maintaining Windows Access by Creating a VBS Backdoor with MSF persistence
31
Setting the Registry Startup Item to calc.exe Through a VBS Script
32
Maintaining Access by Executing a Backdoor Through Default File Associations
33
Using the Local APPINFO RPC Service to Bypass Windows UAC and Launch a High-Privilege Application
34
Bypassing UAC Through Registry Hijacking
35
Modifying Process Access-Token Privileges with AdjustTokenPrivileges
36
Disabling UAC by Modifying the Registry
37
Obtaining a High-Privilege Shell by Hijacking a Binary Used by the 7-Zip Installer
38
System Privilege Escalation by Obtaining windows Patch Information
39
Obtaining a Host Shell by Executing a Payload with the Allowlisted Rundll32.exe
40
Obtaining Shell Access by Executing a Payload with the Allowlisted zipfldr.dll
41
Abusing MSXSL.EXE to Execute an XSL File for Arbitrary Command Execution
42
Abusing the WindowsUpdate Program to Execute a Malicious DLL and Obtain Host Access
43
Abusing the Allowlisted IEexec.exe to Execute a Backdoor and Obtain Host Access
44
Obtaining Windows System Privileges Through CLR Hijacking Combined with MSF
45
Side-Loading a Malicious duser.dll Through the Allowlisted rekeywiz.exe to Launch Calculator
46
Listening on a Specified Port on Windows with PowerShell
47
Creating a New Directory on a Specified FTP Server Through powershell
48
Decoding a Server Port from Base64 Multiple Times with PowerShell
49
Clearing Traces on Windows with a BAT Program
50
Using powershell to Copy a File to a System Directory and Disguise It as a Normal File
51
Using mklink to Execute a File's ADS Alternate Data Stream
52
Stopping the Windows Volume Shadow Copy Service with PowerShell
53
Setting a File or Directory's Attributes to Hidden with PowerShell
54
Deleting Disk Volume Shadow Copies Through WMI
55
Evading Antivirus Detection with ADS Alternate Data Streams
56
Disabling Office Macro Warnings Through the Registry to Execute Macro Code More Stealthily

ANALYSIS

Analysis

4