Persistence techniques
by Kxd - Monday January 29, 2024 at 01:15 AM
#11
(Feb 04, 2024, 02:58 PM)red_dot Wrote:
(Feb 03, 2024, 11:01 PM)Nevertheless Wrote: I used WMI Event Subscription back then
Nowadays I go for obscure shit that there is no chance someone writes a detection rule for.

https://wikileaks.org/ciav7p1/cms/page_14587908.html

u fed bruh?  Handsup

hahahah lol u got him
Reply
#12
(Feb 05, 2024, 05:27 PM)Kxd Wrote:
(Feb 03, 2024, 11:01 PM)Nevertheless Wrote: I used WMI Event Subscription back then
Nowadays I go for obscure shit that there is no chance someone writes a detection rule for.

Shit that sounds cool as hell, any tips of where to begin writing my own custom shit? Like to don't need ro rely on already used techniques. Im kinda clueless on where to start doing these type of stuff
Well, if you want to have an original persistence technique, you should look into how Windows works (what it loads at startup, where, how, etc...)
A good start would be to look at file / reg events using Sysmon for example

(Feb 04, 2024, 02:58 PM)red_dot Wrote:
(Feb 03, 2024, 11:01 PM)Nevertheless Wrote: I used WMI Event Subscription back then
Nowadays I go for obscure shit that there is no chance someone writes a detection rule for.

https://wikileaks.org/ciav7p1/cms/page_14587908.html

u fed bruh?  Handsup

:flushed:
Reply
#13
Scheduled tasks, Run keys, and Steam's installscript.vdf
Reply
#14
dll proxying plus some anti-analysis techniques like self-deletion modifying $DATA.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [Go] Using the recycle bin for stealthy persistence (Beginner tutorial) CreateThread 17 1,020 Yesterday, 11:13 PM
Last Post: learn1
  [Sektor7] Full Recent Course Spearr 31 803 Yesterday, 11:11 PM
Last Post: learn1
  [ LIST ] 5 FREE STEALERS WITH PROS/CONS elix 388 15,186 Yesterday, 10:49 PM
Last Post: learn1
  Xordium stealer for Pulsar v2.4.5 nullvex 26 1,069 Yesterday, 08:14 PM
Last Post: Misanotnessa
  Sektor7 - Malware Development Advanced - Vol.1 Sh4d0w1X 424 43,301 Yesterday, 01:31 PM
Last Post: sud0net

Forum Jump:


 Users browsing this forum: 1 Guest(s)