What is Nostr?
Kevin Beaumont /
npub176r…kwlw
2024-12-20 12:27:37

Kevin Beaumont on Nostr: Unfortunately my toot on this from a few weeks ago deleted, but it's pretty ...

Unfortunately my toot on this from a few weeks ago deleted, but it's pretty important.

DeepInstinct published research (and PoC) for a technique called DCOM Upload & Execute. It allows lateral movement and code execution on Windows using built in APIs, so you don't need psexec.

https://www.deepinstinct.com/blog/forget-psexec-dcom-upload-execute-backdoor

Vendors should add robust detection for this. I fully expect crimeware groups to use it, as it avoids psexec blocking etc.

Tried with MDE today, zero detections still.
Author Public Key
npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw