No Cert? No Problem - ClickOnce (Ab)Use for Trusted Code Execution

  Рет қаралды 340

SpecterOps

SpecterOps

Күн бұрын

Initial access payloads have historically had limited methods that work seamlessly in phishing campaigns and can maintain a level of evasion. This payload category has been dominated by Microsoft Office types, but as recent news has shown, the lifespan of even this technique is shortening. A vehicle for payload delivery that has been greatly overlooked for initial access is ClickOnce. ClickOnce is very versatile and has a lot of opportunities for maintaining a level of evasion and obfuscation.
In this webinar, Nick Powers and Steven Flores discuss methods of bypassing Windows controls such as SmartScreen, application whitelisting, and trusted code abuses with ClickOnce applications. Additionally, they review methods of turning regular signed or high reputation .NET assemblies into weaponized ClickOnce deployments. This results in circumvention of common security controls and extend the value of ClickOnce in the offensive use case. Lastly, they discuss delivery mechanisms to increase the overall legitimacy of ClickOnce application deployment in phishing campaigns. This webinar can bring to attention the power of ClickOnce applications and code execution techniques that are not commonly used.

Пікірлер
BloodHound Update: Fall 2023
59:49
SpecterOps
Рет қаралды 453
А ВЫ УМЕЕТЕ ПЛАВАТЬ?? #shorts
00:21
Паша Осадчий
Рет қаралды 2 МЛН
Can This Bubble Save My Life? 😱
00:55
Topper Guild
Рет қаралды 86 МЛН
Whoa
01:00
Justin Flom
Рет қаралды 46 МЛН
Prank vs Prank #shorts
00:28
Mr DegrEE
Рет қаралды 10 МЛН
Power BI CI/CD, the REST API, and VSCode (with Gerhard Brueckl)
1:19:08
Havens Consulting
Рет қаралды 10 М.
Active Directory Pentesting 101 - Part 1
1:08:29
7 Minute Security
Рет қаралды 3,4 М.
Fully Functional Chatbot with Llama Index: Build a Custom ChatGPT
50:38
Data Science Dojo
Рет қаралды 6 М.
LSA Whisperer - Evan McBroom [SO-CON 2024]
48:21
SpecterOps
Рет қаралды 281
To Infinity and Beyond: Building Purple Team Test Cases
1:14:42
А ВЫ УМЕЕТЕ ПЛАВАТЬ?? #shorts
00:21
Паша Осадчий
Рет қаралды 2 МЛН