name: Windows Post-Exploitation id: 992899b7-a5cf-4bcd-bb0d-cf81762188ba version: 1 date: '2022-11-30' author: Teoderick Contreras, Splunk description: This analytic story identifies popular Windows post exploitation tools for example winpeas.bat, winpeas.exe, WinPrivCheck.bat and many more. narrative: These tools allow operators to find possible exploits or paths for privilege escalation and persistence on a targeted host. Ransomware operator like the "Prestige ransomware" also used or abuses these post exploitation tools such as winPEAS to scan for possible avenue to gain privileges and persistence to a targeted Windows Operating System. references: - https://www.microsoft.com/en-us/security/blog/2022/10/14/new-prestige-ransomware-impacts-organizations-in-ukraine-and-poland/ tags: analytic_story: Windows Post-Exploitation category: - Adversary Tactics product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud usecase: Security Monitoring