logo

Well that escalated quickly: How a red team went from domain user to kernel memory

ID: e2ec90c0-cf6b-502c-8e8d-209760a7302d

STIX ID: report--e2ec90c0-cf6b-502c-8e8d-209760a7302d

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2021-07-28

Date Updated: 2026-04-27

Author: Britton Manahan

...
...

This report describes a red-team engagement in which a domain user with physical access to a host used PowerShell reconnaissance, compiled .NET modules, DLL load-order hijacking to create a local admin, and exploited a vulnerable signed Intel driver (CVE-2015-2291) to bypass driver signing and install a custom kernel-mode rootkit that disabled EDR and enabled credential theft; the detection, timeline, and investigation by the security team are documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.