From Evidence to Advantage: Leveraging Incident Response Artifacts for Red Team Engagements
ID: fc6e50b5-7bb6-5c60-87d7-3c2837823c17
STIX ID: report--fc6e50b5-7bb6-5c60-87d7-3c2837823c17
Feed Name: NVISO Labs
The post explains how incident response artifacts can be repurposed offensively by red teams and introduces KNOCKOUT, a C# tool that collects Windows user and host artifacts (e.g., Office MRUs, RecentDocs, RunMRU, TypedPaths, USBSTOR, UserAssist, LNK/URL files, Jump Lists) via registry and filesystem queries for rapid situational awareness, including in-memory execution in common C2s. It outlines what the tool gathers, shows example execution, proposes future improvements (e.g., unhooking, structured output, BOF version), and provides defender-oriented detection guidance with file hashes, a YARA rule, touched registry and filesystem paths, and observed WinAPI interactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
