Ghost in the SAM: Stealthy, Robust, and Privileged Persistence through Invisible Accounts


연구 분야: Strategies



학회: CheckMATE '24: Proceedings of the 2024 Workshop on Research on offensive and defensive techniques in the context of Man At The End (MATE) attacks


초록

Persistence attacks allow adversaries to maintain access to compromised systems. Despite their wide use by most threat campaigns, they remain understudied in the academic literature. In this paper, we study the concepts and requirements for local invisible accounts and then show new OS-level attacks by implementing these ideas on Windows. In particular, we propose three general design objectives for successful persistence attack vectors. Then, we show how to implement these objectives by bypassing functionality provided by Windows to manage identities. To do this, we first reverse-engineer parts of Windows's authentication and authorization process and propose two attacks: RID Hijacking and Suborner. We show that these attacks affect all versions of Windows since XP and Server 2003, and in combination, they can create stealthy, robust, and privileged accounts.


Author Profile
Sebastián R Castro

University of California Santa Cruz Santa Cruz California USA

United States
Author Profile
Álvaro A Cárdenas

University of California Santa Cruz Santa Cruz California United States

United States

📄 논문 정보

발행 연도 2024년
인용수 1
출판 국가 United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (72건)