So we showed you how we use vulnerable drivers to steal tokens for a new process.
That is obviously not enough.
How about editing your current process token?
Check this:
https://t.co/8RrkzYf9Zj
https://t.co/pFjMdvsLt0
Access tokens are the beating heart of a process.
stealing tokens is an important method attackers need in order to escalate their privileges.
What if you could steal both local and AD tokens with one command line?
Well..now you can !
Check this out :
https://t.co/8RrkzXX0Lb
A lot has been said about removing hooks and kernel callbacks to stop an EDR from detecting malicious activity.
What if we could terminate the process completely?
Well ...we can.
Check this out:
https://t.co/8RrkzXX0Lb
PPL can be very pesky when you try to dump some creds.
Sometimes all you wish for is to turn it off with a click of a button.
Well... Your wish is our "command".
Want to know how?
Click this:
https://t.co/8RrkzXX0Lb
Bring Your Own Vulnerable Driver.
Just two weeks since we learnt how the infamous Lazarus group has carried major cyber attacks using CVE-2021-21551.
What if we could re-create that code?
what about mitigations ?
Check out our latest research and repo:
https://t.co/8RrkzYf9Zj