Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Browse files
Browse the repository at this point in the history
…update-sysmon-v6-autoruns-v13-7-accesschk-v6-1-process-monitor-v3-32-process-explorer-v16-2-livekd-v5-61-and-bginfo-v4-21/ I don't know what "registrations in the WMI\Default namespace" are. I guess it meant to list evil WMI providers that could be registered... Here are some links from https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor.pdf about it: https://gist.github.com/mattifestation/2727b6274e4024fd2481 https://github.com/subTee/EvilWMIProvider https://github.com/jaredcatkinson/EvilNetConnectionWMIProvider On slide 58, why would the EvilWMIProvider be resolved to c:\windows\system32\mscoree.dll?
- Loading branch information