mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
19 lines
945 B
YAML
19 lines
945 B
YAML
name: Windows Post-Exploitation
|
|
id: 992899b7-a5cf-4bcd-bb0d-cf81762188ba
|
|
version: 1
|
|
date: '2022-11-30'
|
|
author: Teoderick Contreras, Splunk
|
|
description: This analytic story identifies popular Windows post exploitation tools for example winpeas.bat, winpeas.exe, WinPrivCheck.bat and many more.
|
|
narrative: These tools allow operators to find possible exploits or paths for privilege escalation and persistence on a targeted host.
|
|
Ransomware operator like the "Prestige ransomware" also used or abuses these post exploitation tools such as winPEAS to scan for possible avenue to gain privileges and persistence to a targeted
|
|
Windows Operating System.
|
|
references:
|
|
- https://www.microsoft.com/en-us/security/blog/2022/10/14/new-prestige-ransomware-impacts-organizations-in-ukraine-and-poland/
|
|
tags:
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring |