Operating Inside the Interpreted: Offensive Python
ID: d47a9be3-6078-5f49-a295-759e5083a412
STIX ID: report--d47a9be3-6078-5f49-a295-759e5083a412
Feed Name: TrustedSec blog
Threat Score
This report evaluates Python on Windows as a practical platform for offensive tooling and malware, detailing how to install Python from the Microsoft Store or offline MSIX packages, manage Pip and offline dependencies, and use the ctypes module to call Win32 APIs including examples such as a reflective DLL loader; it also discusses resulting IoCs and why python.exe can be a difficult process to baseline and detect.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
