this is literally powershell malware dropper design 101 stuff this is hilarious
this is literally powershell malware dropper design 101 stuff this is hilarious
Me: "OK", *sc start TrustedInstaller* then impersonates the token of the service process.
Windows: "Wait no, not like that" 😆
Me: "OK", *sc start TrustedInstaller* then impersonates the token of the service process.
Windows: "Wait no, not like that" 😆
Run all of these commands below (more in the replies) as TrustedInstaller (e.g., RunAsTI) then reboot:
Reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "CurrentBuild" /t REG_SZ /d "19045" /f
Run all of these commands below (more in the replies) as TrustedInstaller (e.g., RunAsTI) then reboot:
Reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "CurrentBuild" /t REG_SZ /d "19045" /f
the perms needed to access the folder is "trustedinstaller" which is actually higher than admin perms and impossible to obtain without third party tools
the perms needed to access the folder is "trustedinstaller" which is actually higher than admin perms and impossible to obtain without third party tools
www.partitionwizard.com/partitionmag...
www.partitionwizard.com/partitionmag...
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
Windows has significantly more memory usage (both RAM and disk but especially RAM) with a fraction of the utility of Linux or even Mac.
Windows has significantly more memory usage (both RAM and disk but especially RAM) with a fraction of the utility of Linux or even Mac.
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
In this #PSConfEU 25 session, @jborean.bsky.social shows :
⚡ Secure sub-process execution
⚡ Running as SYSTEM or TrustedInstaller
⚡ Avoiding secret leaks via logs & env vars
⚡ Safe credential handling tricks
Windows 11:
Windows 11:
• UAC bypass & TrustedInstaller privilege escalation
• Active Directory (LDAP) network discovery
• Network share enumeration & encryption
• Automatic backup and shadow copy deletion
• UAC bypass & TrustedInstaller privilege escalation
• Active Directory (LDAP) network discovery
• Network share enumeration & encryption
• Automatic backup and shadow copy deletion
open cmd as TrustedInstaller
taskkill /f /im msedge.exe
taskkill /f /im MicrosoftEdgeUpdate.exe
rmdir /s "C:\Program Files (x86)\Microsoft"
y
open cmd as TrustedInstaller
taskkill /f /im msedge.exe
taskkill /f /im MicrosoftEdgeUpdate.exe
rmdir /s "C:\Program Files (x86)\Microsoft"
y
theres also ANOTHER thing above trustedinstaller called system
theres also ANOTHER thing above trustedinstaller called system
Wonder if that'll prevent it from reinstalling itself!
Wonder if that'll prevent it from reinstalling itself!
mac : Im the solution to a problem intentionally put here for other reasons!
windows : WHY MUST THE SYSTEM AND TRUSTEDINSTALLER ACCOUNT EXIST I OWN YOU PIECE OF SHIT UNMOUNT THE DRIVE ALREADY
mac : Im the solution to a problem intentionally put here for other reasons!
windows : WHY MUST THE SYSTEM AND TRUSTEDINSTALLER ACCOUNT EXIST I OWN YOU PIECE OF SHIT UNMOUNT THE DRIVE ALREADY
It would, however, take a microsoft engineer actually thinking of the issue and caring to fix it, though.
It would, however, take a microsoft engineer actually thinking of the issue and caring to fix it, though.
1. It runs as TrustedInstaller, which is _very_ risky
2. I don't have any established trust for that user (if anyone else knows them, reach out)
Not trying to throw shade, just my $0.02
1. It runs as TrustedInstaller, which is _very_ risky
2. I don't have any established trust for that user (if anyone else knows them, reach out)
Not trying to throw shade, just my $0.02