Well that escalated quickly: How a red team went from domain user to kernel memory
ID: e2ec90c0-cf6b-502c-8e8d-209760a7302d
STIX ID: report--e2ec90c0-cf6b-502c-8e8d-209760a7302d
Feed Name: Expel Blog
Threat Score
This report describes a red-team engagement in which a domain user with physical access to a host used PowerShell reconnaissance, compiled .NET modules, DLL load-order hijacking to create a local admin, and exploited a vulnerable signed Intel driver (CVE-2015-2291) to bypass driver signing and install a custom kernel-mode rootkit that disabled EDR and enabled credential theft; the detection, timeline, and investigation by the security team are documented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
