Abusing Windows Management Instrumentation (WMI)
Вставка
- Опубліковано 10 лют 2025
- by Matthew Graeber
Imagine a technology that is built into every Windows operating system going back to Windows 95, runs as System, executes arbitrary code, persists across reboots, and does not drop a single file to disk. Such a thing does exist and it's called Windows Management Instrumentation (WMI).
With increased scrutiny from anti-virus and 'next-gen' host endpoints, advanced red teams and attackers already know that the introduction of binaries into a high-security environment is subject to increased scrutiny. WMI enables an attacker practicing a minimalist methodology to blend into their target environment without dropping a single utility to disk. WMI is also unlike other persistence techniques in that rather than executing a payload at a predetermined time, WMI conditionally executes code asynchronously in response to operating system events.
This talk will introduce WMI and demonstrate its offensive uses. We will cover what WMI is, how attackers are currently using it in the wild, how to build a full-featured backdoor, and how to detect and prevent these attacks from occurring.
Great video you are the MAN Matt😁
Great video. Over the past couple months I have been using Empire's invoke_wmi module as a Red Team attack path against my capstone team's environment.
you probably dont give a shit but does anybody know of a method to get back into an instagram account??
I was dumb lost the account password. I love any assistance you can offer me.
bruh
@@vitquack4078 Bro?
it is just breathtaking. wonder why this is so underrated
Thanks for the video =)
Athena Hill
Hi :
Second comment in 4 years hahaha
Smith Charles Wilson Christopher Williams Melissa
Bruh I think this happened tonme
Those “mmmkay” and “oh rite” every 30 seconds are really annoying.
it's a simple way of the mind to put an end on sentence.
there's practice for anyone who'll see this, you can actually overcome these "highlighted" symptom.
when you think you're going to say it, just put in your head, highlighted = False. ;- )