mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
142 stars 10 forks source link

[New WTFBin]: OpenVAS runs WMIExec #54

Open mttaggart opened 2 months ago

mttaggart commented 2 months ago

When connecting to Windows hosts, OpenVAS will run impacket-wmiexec against the host. The resulting events look identical to a secretsdump run that you'd hunt for.