Living Off The Land - Windows Disk Cleaner Persistence

Поделиться
HTML-код
  • Опубликовано: 15 ноя 2024

Комментарии • 33

  • @iam-py-test
    @iam-py-test Год назад +2

    Thanks for making this. My only complaint is that it would be nice for you to link the websites you are talking about in the description.

  • @seclilc
    @seclilc Год назад +7

    Good stuff, John! Love catching the new videos :)

  • @seb_gibbs
    @seb_gibbs Год назад +6

    interesting that I saw the Print Monitor in the list, as this process is often false flagged on many systems I've checked over the years, so maybe its not false.

  • @MrPenguin098
    @MrPenguin098 Год назад +2

    @John Hammond. Great presentation. You must have a photographic memory. All your videos are so smoothly presented. Thanks for your videos. I learn a lot.

    • @MalamIbnMalam
      @MalamIbnMalam Год назад +1

      I think he just speaks naturally, he doesn't try to read off of a script.

  • @angryman9333
    @angryman9333 Год назад

    One of ur best vids, easily

  • @hrishikeshdahale4640
    @hrishikeshdahale4640 Год назад

    Hey John, great video, as always! Could you make a video on Coursera's Google Cybersecurity Professional Certificate and what it is worth to someone with a CompTIA Security+ certificate. Please!!

  • @adrianpetrescu8583
    @adrianpetrescu8583 Год назад

    So what will be a better protection for this type of attack ?
    or how we can protect an system from that ?

  • @elmehdiraya972
    @elmehdiraya972 Год назад +3

    The purpose is start automatic cleanup?

    • @Grave895
      @Grave895 Год назад +1

      Yes. But understand the damage you can cause with that registration access..

    • @elmehdiraya972
      @elmehdiraya972 Год назад

      @@Grave895 thank you!

  • @notafurrysogoaway
    @notafurrysogoaway Год назад +17

    RUclips has apparently unsubbed me.

  • @KA-NV
    @KA-NV Год назад +1

    Excellent presentation as always.
    Can you provide ways to detect this?

  • @jasonwestmoreland7337
    @jasonwestmoreland7337 Год назад +1

    Does this work against a RAM Disk? One that you could create, populate with appropriate files, then run against, then remove after the fact? Seems that might allow you to completely hide the entire process. After all, you already have to have admin privileges to run the cleaner anyway.

    • @Aera223
      @Aera223 Год назад

      Not really. I've run it without admin. Only select files need admin to be cleaned

  • @MassimilianoDalCero
    @MassimilianoDalCero 7 месяцев назад

    Does anyone have the source code shown in the video? :)

  • @Matty100
    @Matty100 Год назад

    Is it living off the land when 2 cmd screens pop up and close instantly when I turn my laptop on??

    • @tomysshadow
      @tomysshadow Год назад +1

      Not necessarily. There could be legitimate reasons that a startup program would show a command prompt window. That alone isn't enough information to determine if it's malicious or benign.

    • @Matty100
      @Matty100 Год назад

      @TOMYSSHADOW thanks man!

  • @Stopinvadingmyhardware
    @Stopinvadingmyhardware Год назад

    Python log in shells.
    That wasn’t funny
    That ginger bounce.

  • @Gemini-_-
    @Gemini-_- Год назад

    This is Patched

  • @metaatschool2207
    @metaatschool2207 Год назад +3

    FIRST LIKE AND COMMENT, PIN? (Also first view)