08.08.2015 Views

Persistent Asynchronous and Fileless Backdoor

us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor

us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

WMI Event - Filters• The definition of the event to trigger• Takes the form of a WMI query• Be mindful of performance!• These take some practice…• Intrinsic querySELECT * FROM __InstanceOperationEvent WITHIN 30 WHERE((__CLASS = "__InstanceCreationEvent" OR __CLASS ="__InstanceModificationEvent") AND TargetInstance ISA"CIM_DataFile") AND (TargetInstance.Extension = "doc") OR(TargetInstance.Extension = "docx")• Extrinsic querySELECT * FROM Win32_VolumeChangeEvent WHERE EventType = 2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!