Christophe Tafani-Dereeper

Results 134 comments of Christophe Tafani-Dereeper

Hi, Thanks for reporting. Could you try setting a breakpoint just after `NtQueryInformationProcess` is run, and look at the value of `err.LastDllError`? It should give you an error number that...

Did you end up finding a solution?

Hello, Sorry, I've not been maintaining this code for quite some time. If someone knows of a fix, I gladly take a contribution, thanks!

This would be tremendously useful to have in Terraform. The API docs are here: https://docs.microsoft.com/en-us/graph/api/resources/privilegedidentitymanagement-resources?view=graph-rest-beta (beta)

I believe @vot3k was planning to work on that one

Closing as we lack evidence this is a real-world attack technique (see https://stratus-red-team.cloud/attack-techniques/philosophy/)

Reopened, reference: https://www.vectra.ai/blogpost/abusing-the-replicator-silently-exfiltrating-data-with-the-aws-s3-replication-service cc @KatTraxler who's interested to pick up this issue

Thanks for your input @jonpulsifer, can you clarify what you mean?

Good point for the detection part! Thanks for the input

challenge: might be very noisy and not actionable enough for detection, as the `gcloud compute ssh` seems to do it