These days "living off the land" is gaining popularity. What I dont get is why there is not more "EATING the land" If there already is functionality for your intended goal- why not use it?
-
-
Show this thread
-
A simple example is cryptolockers.... hey- we already have bitlocker for that, change some settings- maybe inject a little code and you will avoid detection and antivirus etc.
Show this thread -
But- what about persistence? Well, why not reuse the built in kernel mode executing virtual machines? There is even one intended for ofuscation of the codes execution. By transforming code into Warbird bytecode and injecting it a place like authenticode validation you get it all
Show this thread -
Obscurity, evasaion of AV and persistent execution. But what about stuff like c&c- surviving reboots etc. Well, the filtering platform could be a fit for that, kernel mode, interpeted and obscure. You could survive reboots as an ummm firewall rule I guess?
Show this thread -
You can intercept and inject traffic into network as you want- bypass other filters, AV, endpoints etc. while not being listed as a loaded driver/nor a running exe/dll in any lists that could be inspected. Few people would even know how to approach detection of such a beast.
Show this thread
End of conversation
New conversation -
-
-
Auto-updating apps from the vendor that could be updated one day and initiate remote support requests.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
It sounds like all of this can only be gained from expert and messing around in a home lab. If not where do you learn such in depth things???
-
well- the premise of the question was what an anvanced state level threat actor could do. But- the playing field is comfortable levelled for this level of bullshit :) You learn just as well by yourself on your ass in a couch as any place.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.