Files
splunk-security_content/stories/windows_post_exploitation.yml
2024-05-08 16:05:40 +00:00

19 lines
945 B
YAML

name: Windows Post-Exploitation
id: 992899b7-a5cf-4bcd-bb0d-cf81762188ba
version: 1
date: '2022-11-30'
author: Teoderick Contreras, Splunk
description: This analytic story identifies popular Windows post exploitation tools for example winpeas.bat, winpeas.exe, WinPrivCheck.bat and many more.
narrative: These tools allow operators to find possible exploits or paths for privilege escalation and persistence on a targeted host.
Ransomware operator like the "Prestige ransomware" also used or abuses these post exploitation tools such as winPEAS to scan for possible avenue to gain privileges and persistence to a targeted
Windows Operating System.
references:
- https://www.microsoft.com/en-us/security/blog/2022/10/14/new-prestige-ransomware-impacts-organizations-in-ukraine-and-poland/
tags:
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Security Monitoring