A very short blog post for all of you that cannot let go of Task Scheduler as a persistence technique:https://www.a12d404.net/windows/2019/10/30/schedsvc-persist-without-task.html …
-
-
Replying to @markus_pieton
Great post- Always interested in undocumented dll sideloads, but mostly from the perspective of converting file creation to code execution in exploit chains :) For persistence maybe cng.sys is interesting? If exists in system32 it will get loaded on boot- I assume as a driver
2 replies 0 retweets 0 likes -
Replying to @jonasLyk
I think the driver needs to be signed, so that could be another obstacle that you need to overcome.
1 reply 0 retweets 0 likes
Replying to @markus_pieton
true, forgot about that
3:21 AM - 31 Oct 2019
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.