If you symlink to \??\globalroot\device\mup\;webdavredirector\candcip\davwwwroot\ and make the payload create a symlink \??\globalroot -> \??\nul It will only get executed when not already loaded, on termination \??\globalroot resolves through to shadow \global??\globalroot
-
This Tweet is unavailable.
-
Show this thread
this persistence method will not show up in any tool dedicated to show what will get executed on boot. If offline scanned implant is gone and persistence very unlikely to show up.
4:42 AM - 26 Oct 2020
0 replies
0 retweets
7 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.