JonLMyers / CCDC_RedTeam

Tools for getting the CCDC team good.
MIT License
3 stars 1 forks source link

Loud Windows Persistence #2

Open JonLMyers opened 7 years ago

JonLMyers commented 7 years ago

I noticed that our RAT is easily detected with netstat. We are going to persist this connection in a rather loud manner until we can get a rootkit to obfuscate the connection in netstat. This persistor will spawn 3 process that are reflectively migrated into 2 different critical processes. These boys will look out for their RAT friend and if he is destroyed the re-spawn him.