Credential Theft Using Procdump or Comsvcs
ManageEngine 2024
| Notes |
|---|
| Local Security Authority Subsystem (LSASS) |
| lateral movement |
| credential dumping |
| procdump |
| comsvcs - comsvcs.dll |
| Sysinternals |
| principle of least privilege |
credentialtheftprocdumpcomsvcs-manageengine2024
2025-02-12
Credential Theft Using Procdump or Comsvcs
ManageEngine 2024
| Notes |
|---|
| Local Security Authority Subsystem (LSASS) |
| lateral movement |
| credential dumping |
| procdump |
| comsvcs - comsvcs.dll |
| Sysinternals |
| principle of least privilege |
Linux Persistence: Modular Software
2025-04-17 DFIR CTF persistence linux persistence apache asterisk
Linux Persistence: Web Shells
2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP
Linux Persistence: Rootkits
2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking
Defanging Linux LKM Rootkits With cleanup_module()
2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit