Category: Purple Team
-

Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted process in workstations of developers. Furthermore, threat actors could tamper .tt files and merge…
-

Mandatory User Profile
The file NTUSER.MAN is a Windows user-profile registry hive used with mandatory profiles. It contains pre-defined configuration settings that are loaded into the registry (HKEY_CURRENT_USER) when the user authenticates. Organizations typically use the mandatory profiles in Kiosks and shared workstations. However, threat actors could abuse Mandatory User Profiles to establish…
-

Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse provisioning packages to hide arbitrary payloads and commands within these containers. Furthermore, it could be used in conjunction with social engineering to deliver packages…
-

AMSI Provider
The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However, for functionality purposes Microsoft permits third-party applications to register AMSI providers with the operating system in order to communicate with the…
