<waves hands, but I want to emphasize my access has no standing exceptions> I get PsExec on USB.
Here's bad news.
PsExec replies it doesn't work in Safe Mode. Neither does Task Scheduler.
I'm fucked. But
<waves hands, but I want to emphasize my access has no standing exceptions> I get PsExec on USB.
Here's bad news.
PsExec replies it doesn't work in Safe Mode. Neither does Task Scheduler.
I'm fucked. But
+Guess what. Scheduled Task subsystem doesn't launch in Safe Mode.
Neither does WiFi.
+Guess what. Scheduled Task subsystem doesn't launch in Safe Mode.
Neither does WiFi.
PsExec made my life so much easier as an admin back in the day
PsExec made my life so much easier as an admin back in the day
There's two possibilities. Tools like PSEXEC that can run cmd.exe as SYSTEM or the Scheduled Tasks trick where you set a task to run as SYSTEM then manually invoke it.
However
There's two possibilities. Tools like PSEXEC that can run cmd.exe as SYSTEM or the Scheduled Tasks trick where you set a task to run as SYSTEM then manually invoke it.
However
sensepost.com/blog/2025/ps...
sensepost.com/blog/2025/ps...
He, Michael, and Reino built susinternals that makes use of the Microsoft signed psexec service binary on the host instead of the more easily flagged RemCom.
sensepost.com/blog/2025/ps...
He, Michael, and Reino built susinternals that makes use of the Microsoft signed psexec service binary on the host instead of the more easily flagged RemCom.
sensepost.com/blog/2025/ps...
[New Post] 👉How to Prevent Malware Spread and Remote Attacks by Blocking PsExec and WMI with Intune ASR Rule - www.anoopcnair.com/how-to-preve...
🔊What Is the PsExec and WMI Blocking Rule in Intune?
#Intune #MSIntune #HTMDCommunity
[New Post] 👉How to Prevent Malware Spread and Remote Attacks by Blocking PsExec and WMI with Intune ASR Rule - www.anoopcnair.com/how-to-preve...
🔊What Is the PsExec and WMI Blocking Rule in Intune?
#Intune #MSIntune #HTMDCommunity
Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds.
🔎 Hunt tip: w…
— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2102359836012806148)
Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds.
🔎 Hunt tip: w…
— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2102359836012806148)
👉 (Re)découvrez notre tutoriel pas à pas :
www.it-connect.fr/psexec-un-ou...
💡 Gain de temps, gestion centralisée, flexibilité : un vrai allié du quotidien pour les équipes IT.
#Windows #SysAdmin #ITpro #PsExec
👉 (Re)découvrez notre tutoriel pas à pas :
www.it-connect.fr/psexec-un-ou...
💡 Gain de temps, gestion centralisée, flexibilité : un vrai allié du quotidien pour les équipes IT.
#Windows #SysAdmin #ITpro #PsExec
invoke-CommandAs because my work banned PsExec and it allows me to run stuff as SYSTEM.
invoke-CommandAs because my work banned PsExec and it allows me to run stuff as SYSTEM.
Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)
github.com/pard0p/Remot...
Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)
➡️TTR 7.5 hours
➡️Koadic and Empire for C2
➡️7+ Credential Access techniques
➡️ADRecon, APS, quser, arp, and nltest for Discovery
➡️RDP and PsExec for Lateral Movement
➡️Files exfiltrated
➡️PYSA ransomware for Impact
Report link ⬇️
➡️TTR 7.5 hours
➡️Koadic and Empire for C2
➡️7+ Credential Access techniques
➡️ADRecon, APS, quser, arp, and nltest for Discovery
➡️RDP and PsExec for Lateral Movement
➡️Files exfiltrated
➡️PYSA ransomware for Impact
Report link ⬇️
Ref : Forget PSEXEC: DCOM Upload & Execute Backdoor : www.deepinstinct.com/blog/forget-...
Ref : Forget PSEXEC: DCOM Upload & Execute Backdoor : www.deepinstinct.com/blog/forget-...
Découvrez comment installer et utiliser 𝗣𝘀𝗘𝘅𝗲𝗰 pour exécuter des commandes et des programmes à distance sur des machines 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 🚀
👉 www.youtube.com/watch?v=dgOt...
#SysAdmin #Windows #Outils #IT #PsExec #Astuce #Tutoriel #Sécurité
Look at the replies on those accounts
these are all bots
Look at the replies on those accounts
these are all bots
medium.com/@aminouji23/...
medium.com/@aminouji23/...
psexec -s powershell.exe
cd "C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe"
ren EdgeGameAssist.exe EdgeGameAssist._
exit
@markrussinovich.bsky.social thx for the Sysinternals kit the 1000th time 💜
psexec -s powershell.exe
cd "C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe"
ren EdgeGameAssist.exe EdgeGameAssist._
exit
@markrussinovich.bsky.social thx for the Sysinternals kit the 1000th time 💜
攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
Best part? It could just be a malfunctioning dell utility or something when their app updated. With the psexec file being a red herring
Best part? It could just be a malfunctioning dell utility or something when their app updated. With the psexec file being a red herring
You need to add an exemption to "System32\Dism" for it to work 🙃
You need to add an exemption to "System32\Dism" for it to work 🙃