Windows Event Logs for Red Teams
ID: c8fec95a-2b75-571c-aabd-18ba1059bab0
STIX ID: report--c8fec95a-2b75-571c-aabd-18ba1059bab0
Feed Name: Black Hills Infosec Blog
This blog post details a proof-of-concept technique for storing and retrieving binary payloads in Windows Event Logs to achieve fileless execution and potential persistence: it covers Windows Event Log basics, permission and size constraints, creating entries with Write-EventLog (including RawData), extracting and executing payloads with a C# PoC (demonstrating calc.exe and a Metasploit reverse shell), detection observations with Windows Defender, and references to persistence tooling (SharpEventPersist).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
