08.08.2015 Views

Persistent Asynchronous and Fileless Backdoor

us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor

us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

WMI Basics - Architecture• WMI implements the CIM <strong>and</strong> WBEM st<strong>and</strong>ards to do the following:– Provide an object schema to describe “managed components”– Provide a means to populate objects – i.e. WMI providers– Store persistent objects – WMI/CIM repository– Query objects – WQL– Transmit object data – DCOM <strong>and</strong> WinRM– Perform actions on objects – class methods, events, etc.• <strong>Persistent</strong> WMI objects are stored in the WMI repository– %SystemRoot%\System32\wbem\Repository\OBJECTS.DATA– Valuable for forensics yet no parsers exist until now!• WMI Settings– HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM– Win32_WmiSetting class

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!