Prevention strategy for Process Herpaderping:
Place WDAC into any form of enforcement, even allow all.
Thank you to @PhilipTsukerman and @AmirKutcher for this discovery and insight!https://twitter.com/mattifestation/status/1349706384280064001 …
-
Show this thread
-
what about process lemming demming?
1 reply 0 retweets 4 likes -
Replying to @jonasLyk @mattifestation and
Jonas L Retweeted Jonas L
Jonas L added,
1 reply 0 retweets 0 likes -
I'm not familiar with this technique. Do you have a reference explaining it beyond the screenshot? Either way, give the ConvertFrom-CIPolicy example a shot.
1 reply 0 retweets 0 likes -
there is not that much to it- when you delete the file you can put another file in its place, creating mismatch between mapped mem and file content. Or- open with supersede and oplock and append and overwrite without causing rescan
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @mattifestation and
the core trick being that the locks follow the unnamed primary data stream.
1 reply 0 retweets 0 likes -
That sounds cool! My brain can't process the mechanics behind it fully in this thread. Would you consider writing a blog post about it? Thanks!
1 reply 0 retweets 1 like -
when you say that i start to wonder if I am missing some aspect of the techniques- would you mind maybe having a little chat about it?
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @mattifestation and
maybe this explains better- lets try and fix the showing of the new stream namepic.twitter.com/g60SqTdMiF
2 replies 0 retweets 1 like -
Replying to @jonasLyk @mattifestation and
I thought about using your trick for a Process Herpaderping-like attack, but was discouraged because it would be pretty simple to detect the file rename. I don't think any files get renamed to ":[something]" for legitimate uses.
1 reply 0 retweets 0 likes
true- i get that. Zone.Identifier though....... that happen all the time. maybe the trick can be improoved :)
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.