13.07.2013 Views

Protecting Privileged Domain Accounts during Live Response

Protecting Privileged Domain Accounts during Live Response

Protecting Privileged Domain Accounts during Live Response

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Interact with a remote Windows XP (SP2) domain<br />

workstation for analysis/triage<br />

We need the ability to complete several tasks:<br />

Query the machine, with a tool such as WMIC<br />

Run commands on the machine, with a tool like PsExec<br />

Copy files to/from the machine, via the command NET USE<br />

Complete these actions in such a way as to leave<br />

no opportunity for an attacker to steal our domain<br />

credentials<br />

6

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!