When the #redteam disables EDR
PS to
LPE
DLL LO hijack "Citrix\ICAService" to elevate
Deployed signed driver, NalDrv.sys
Exploited driver to access kernel mem / CVE-2015-2291
Kernel access to bypass DSE, add driver
Then:
Disabled EDR
Enabled WDigest
Mimi
cc/ @cyberpug010
-
Show this thread
-
A lot of great detection opportunities here Bring your own (vulnerable) drivers (BYOvD)!?
it!
https://www.virustotal.com/gui/file/4429f32db1cc70567919d7d47b844a91cf1329a6cd116f582305f3b7b60cd60b/community …
cc/ @tfornez1 reply 0 retweets 6 likesShow this thread
Replying to @jhencinski @tfornez
or...just replace drvmain.sdb with https://cdn.discordapp.com/attachments/794460959615090712/807965504161054740/drvmain.sdb … - mimikatz loads
1:26 PM - 27 Apr 2021
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.