View Single Post
  #3  
Old 02-19-2017, 04:03
deroko's Avatar
deroko deroko is offline
cr4zyserb
 
Join Date: Nov 2005
Posts: 217
Rept. Given: 13
Rept. Rcvd 30 Times in 14 Posts
Thanks Given: 7
Thanks Rcvd at 33 Times in 16 Posts
deroko Reputation: 30
Actually if I remember correctly, a few years back some guys found bug in windows driver, and managed to store whole exploit/shellcode in wrongly parsed registry key (which driver parsed during boot). This could count as fileless persistent code

I don't remember who did it, or how article or poc was named. Was long time ago, if somebody remembers would be awesome to post link
__________________
http://accessroot.com
Reply With Quote
The Following 3 Users Say Thank You to deroko For This Useful Post:
Nacho_dj (02-19-2017), SinaDiR (05-24-2020), tonyweb (02-19-2017)