Attack Tool(s): Impacket, Seatbelt, SharpUp, PEASS-ng
- Impacket: https://github.com/SecureAuthCorp/impacket
- Seatbelt: https://github.com/GhostPack/Seatbelt
- SharpUp: https://github.com/GhostPack/SharpUp
- PEASS-ng: https://github.com/peass-ng/PEASS-ng
Detection Link(s):
- Endpoint Analysis
- Active Defense and Cyber Deception
- Endpoint Security Protection Analysis
Helpful Blogs (BHIS):
- “PowerShell Without PowerShell” – https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av – Privilege escalation context.
