GrimResource - Microsoft Management Console for initial access and evasion
ID: 23a429db-02fd-5af3-8c3f-316d17762d23
STIX ID: report--23a429db-02fd-5af3-8c3f-316d17762d23
Feed Name: Elastic Security Labs
Threat Score
Elastic Security researchers describe 'GrimResource', a novel technique that leverages an XSS issue in apds.dll via crafted MSC files to execute arbitrary JavaScript in mmc.exe, chain into DotNetToJScript and a PASTALOADER .NET loader, and ultimately deploy a Cobalt Strike payload; the report includes behavioral detections (EQL), a YARA rule, and observable hashes for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
