Found 1 bookmarks
Newest
#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation
#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation
This blog is based on a session we presented at DEF CON 2023 on Sunday, August 13, 2023, in Las Vegas. Privilege escalation is a common attack vector in the Windows OS. There are multiple offensive tools in the wild that can execute code as “NT AUTHORITY\SYSTEM” (Meterpreter, CobaltStrike, Potato tools), and they all usually do so by duplicating tokens and manipulating services. This allows them to perform attacks like LSASS Shtinkering.
·deepinstinct.com·
#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation