Beyond the MCSE Red Teaming Active Directory
DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory
DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Detecting EXEs Hosting PowerShell<br />
• Event 800: HostApplication not standard<br />
Microsoft tool<br />
• Event 800: Version mismatch between<br />
HostVersion & EngineVersion (maybe).<br />
• System.Management.Automation.dll hosted<br />
in non-standard processes.<br />
• EXEs can natively call .Net & Windows APIs<br />
directly without PowerShell.<br />
| @PryoTek3 | sean @ adsecurity.org |