How to Take Advantage of Weak NTFS Permissions
ID: aabd167a-6585-50a8-96ed-6a5c305c4ab6
STIX ID: report--aabd167a-6585-50a8-96ed-6a5c305c4ab6
Feed Name: Black Hills Infosec Blog
## Executive Summary: This report outlines a technique for abusing weak NTFS and share permissions to achieve credential capture and lateral escalation by writing malicious shortcuts or files to writable network locations (roaming profiles, folder redirection, user home directories). It describes discovery using PowerView and Invoke-ShareFinder, options for payload delivery (malicious macros or backdoored binaries), and the use of Metasploit's SMB capture module to collect NTLM challenge-response hashes via modified file:// links for subsequent offline cracking and privilege escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
