Abusing Windows Built-in VPN Providers
ID: d22a8175-2874-5a54-a953-00aa43b0d191
STIX ID: report--d22a8175-2874-5a54-a953-00aa43b0d191
Feed Name: TrustedSec blog
Executive summary: The report demonstrates that Windows' built-in VPN providers can be abused by non‑privileged users to modify the system routing table (via phonebook files, PowerShell/WMI cmdlets, RasMan RPC, etc.) and redirect or intercept network traffic through an attacker-controlled VPN (SoftEther example). It covers methods to push or locally add routes, tunnel all traffic, auto‑connect via application triggers, attack scenarios (dropping traffic to blind EDR/logging or redirecting to a MitM proxy), and detection/prevention recommendations (restrict RasMan/phonebook writes, monitor RasClient events).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
