06.08.2016 Views

Beyond the MCSE Red Teaming Active Directory

DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory

DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Detecting EXEs Hosting PowerShell<br />

• Event 800: HostApplication not standard<br />

Microsoft tool<br />

• Event 800: Version mismatch between<br />

HostVersion & EngineVersion (maybe).<br />

• System.Management.Automation.dll hosted<br />

in non-standard processes.<br />

• EXEs can natively call .Net & Windows APIs<br />

directly without PowerShell.<br />

| @PryoTek3 | sean @ adsecurity.org |

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!