Category: Purple Team
-

Dump Encoding Library
The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic implementation. Threat actors can develop smaller stagers without using crypto code, enabling them to have improved evasion capabilities against endpoint detection…
-

Windows Security Center
The Windows Security Center collects and presents information about the status of the antivirus control (Windows Defender or 3rd party). When a third-party antivirus is installed, Windows Defender transitions to passive mode to avoid scanning collisions. Threat actors can abuse the Windows Security Center (WSC) API to disable Windows Defender…
-

Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted process in workstations of developers. Furthermore, threat actors could tamper .tt files and merge…
-

Mandatory User Profile
The file NTUSER.MAN is a Windows user-profile registry hive used with mandatory profiles. It contains pre-defined configuration settings that are loaded into the registry (HKEY_CURRENT_USER) when the user authenticates. Organizations typically use the mandatory profiles in Kiosks and shared workstations. However, threat actors could abuse Mandatory User Profiles to establish…
