logo

From Evidence to Advantage: Leveraging Incident Response Artifacts for Red Team Engagements

ID: fc6e50b5-7bb6-5c60-87d7-3c2837823c17

STIX ID: report--fc6e50b5-7bb6-5c60-87d7-3c2837823c17

Feed Name: NVISO Labs

Date Published: 2024-08-02

Date Updated: 2026-04-28

Author: Steffen Rogge

...
...

The post explains how incident response artifacts can be repurposed offensively by red teams and introduces KNOCKOUT, a C# tool that collects Windows user and host artifacts (e.g., Office MRUs, RecentDocs, RunMRU, TypedPaths, USBSTOR, UserAssist, LNK/URL files, Jump Lists) via registry and filesystem queries for rapid situational awareness, including in-memory execution in common C2s. It outlines what the tool gathers, shows example execution, proposes future improvements (e.g., unhooking, structured output, BOF version), and provides defender-oriented detection guidance with file hashes, a YARA rule, touched registry and filesystem paths, and observed WinAPI interactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.