mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
142 stars 10 forks source link

[New WTFBin]: Windows USB Link-local IP addresses (169.254.0.0/16) on the host PC #6

Closed knightwolfjk closed 2 years ago

knightwolfjk commented 2 years ago
mttaggart commented 2 years ago

@knightwolfjk, thank you so much for the submission! This is really interesting.

Beyond the Microsoft documentation, can you explain a little more about how this looks on the system, and why it appears malicious?

mttaggart commented 2 years ago

@knightwolfjk,

I'm closing this for now because I need additional details as to how it would appear to be malicious during threat hunting or incident response.