Crucial System Files That Can Be Leveraged by Threat Actors(Unexplored LOLBIN)

Post Views: 86 System files are integral to the smooth operation of your Windows operating system. However, when these files fall into the wrong hands, they can be leveraged for malicious purposes. In this blog, we will discuss their capabilities, and the potential threats they pose. ForFiles.exe Location: ‘C:\Windows\System32\forfiles.exe’ Supported Versions: Windows Vista onwards Capabilities: …

Investigating a Data Exfiltration Scenario

Post Views: 231 Hi everyone, today I want to discuss a data exfiltration scenario I recently encountered during an investigation. As a security researcher, it’s crucial to identify and understand how attackers are stealing data. Unusual Network Traffic The initial red flag was unusual network traffic patterns, which often indicate potential data exfiltration. This triggered …