Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Microsoft Shift F10 bypass + Autopilot privilege escalation
πŸ—£k4m1ll0

Am i missing something, or could you just as easily pop out the harddisk and put it in another machine to remove the DisableCMDRequest.TAG file/do whatever you want?
πŸ‘€Bl00dsoul

There are ways to disable it: https://call4cloud.nl/2022/01/the-oobe-massacre-the-beginning-of-shift-f10/

Another attack vector would be audit mode at beginning of setup. After creating admin accounts or whatever sysprep back to OOBE to continue with autopilot
πŸ‘€HankMardukasNY

This vuln is fairly well-known in the Intune community, but mostly theoretical - great to see a writeup and full attack chain. Do you have any recommendations for mitigating it? I've focused on using preprovisioning to lock down the system and defaultuser0, but being able to alt-tab and modify system state at all seems like a huge attack surface
πŸ‘€Pl4nty


πŸŽ–@malwr
πŸ‘1
Hardware encrypted usb suggestions??
What products are we using for hardware encrypted drives to move data around and store forensic data securely?
πŸ—£dfzachary

I’ve used Aegis and SiForce. I much prefer the latter as they are more reliable and less prone to disconnection due to power consumption issues.
πŸ‘€ucfmsdf

Apricorn Aegis Padlock drives are the best!
πŸ‘€no_sushi_4_u


πŸŽ–@malwr