Building an offensive RPC interface
ID: 97012c2d-98a2-5d11-a9c2-bcc958331b5a
STIX ID: report--97012c2d-98a2-5d11-a9c2-bcc958331b5a
Feed Name: SensePost Blog
Technical walkthrough detailing Windows RPC architecture and how to build and interact with a custom RPC interface that spawns a reverse shell, covering endpoint mapping, binding strings, NDR marshalling (with Impacket), and operational considerations such as masquerading with a legitimate UUID, service replacement, and shifting from TCP to named pipes for stealth.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
