Nick Tyrer
214
posts
Quick post on how I got set up and hands-on with docker:
Updated my Metasploit module that assists in bypassing Applocker to include WMIC.exe bypass by
@subTeeand Workflow.Compiler.exe by
@mattifestation. Give it a try here: github.com/rapid7/metaspl….
Three part blog post on how I switched to Linux and created a virtual lab using QEMU/KVM, IOMMU and PCI passthrough. Post 1 nickyt8.wordpress.com/2018/07/05/swi… Post 2 nickyt8.wordpress.com/2018/07/05/swi… Post 3 nickyt8.wordpress.com/2018/07/05/swi…
I currently have a pull request for a metasploit module to test various applocker bypasses, check it out here: github.com/rapid7/metaspl… now includes cmstp.exe
CMSTP.exe - remote .sct execution applocker bypass. Built on research by
@Oddvarmoe- oddvar.moe/2017/08/15/res… &
@KyleHanslovan- gist.github.com/KyleHanslovan/… &
@SubTeeFiles Used: gist.github.com/NickTyrer/bbd1…

GIF

