Blog post detailing Sysmon's file delete event internals and escalation to kernel code execution has been published here: https://undev.ninja/sysmon-internals-from-file-delete-event-to-kernel-code-execution/ …. PoC code uploaded here: https://github.com/NtRaiseHardError/Sysmon …. Affected versions: v11.0 and above.https://twitter.com/0x00dtm/status/1311307817551233024 …
-
1:09
Replying to @0x00dtm
good job- nice article :) Wondering if you can bypass the archiving of a temp file by writing the actual data as an alternative data stream and then just deleting the parent file / folder ? Do sysmon archive all streams?
7:01 AM - 2 Oct 2020
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.