
Re: "living-off-the-land binaries"
Bitsadmin.exe, rundll32.exe, werfault.exe and others can be invoked to load/side load your red team components without being detected or flagged as malicious by an AV.
Quite effective.
Bitsadmin.exe, rundll32.exe, werfault.exe and others can be invoked to load/side load your red team components without being detected or flagged as malicious by an AV.
Quite effective.
Biting the hand that feeds IT © 1998–2022