logo

Playing With Old Hacks

ID: 8cff5349-37f2-58a0-bf1c-26cdcdaa34be

STIX ID: report--8cff5349-37f2-58a0-bf1c-26cdcdaa34be

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

This blog-style report demonstrates how an attacker with physical access can boot from Windows installation media and replace or symlink accessibility/logon binaries (utilman.exe, sethc.exe, narrator.exe, magnify.exe, osk.exe) to execute commands at the logon screen. The author tests multiple replacement binaries, documents Windows Defender signature Win32/AccessibilityEscalation.A blocking some replacements, shows that alternatives like ftp.exe and a third-party cmd can bypass signatures, and concludes that full-disk encryption is the primary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.