Sploitus
New Exploits Target Windows Accounts and PowerShell Scripts
Article Content
Two new exploits have emerged targeting Windows systems and PowerShell scripts. The 'Suborner' exploit allows the creation of hidden local accounts on Windows systems without triggering event logs, affecting all Windows NT versions from XP to 11. It enables attackers to impersonate existing accounts by hijacking their RID after successful authentication. The 'psobf' exploit is a tool for obfuscating PowerShell scripts, making them harder to analyze and detect, useful for Red Teaming and pentesting. It supports multiple obfuscation levels, including AES-256 encryption. Both tools are intended for authorized use only, but their capabilities pose significant risks if misused. The 'Suborner' exploit was first demonstrated at Black Hat USA 2022, while 'psobf' is a newer release aimed at enhancing script security.
Key Points: • Suborner allows creation of hidden Windows accounts, bypassing event logs. • psobf obfuscates PowerShell scripts, complicating detection and analysis. • Both tools are intended for authorized use but pose risks if misused.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.