با پرداختن به این مقاله ، تکنیک های Persistence و Backdoor با این روش و تکنیک های OpSec مورد استفاده در آن را متوجه میشویم.
در آخر برای شناسایی این تکنیک میتوان مشخص کرد اگر مقدار Shadow در کلید:
HKLM\Software\Policies\Microsoft\Windows NT\Terminal Services
ایجاد یا تغییر کرد هشدار داده شود.
همچنین برای امن سازی آن میتوان به موارد زیر اشاره نمود:
To prevent shadowing altogether, using application whitelisting, it is possible to block the RdpSaUacHelper.exe, RdpSaProxy.exe and RdpSa.exe processes from launching
In the group policy, one can explicitly set the Shadow setting to require the user’s consent before shadowing or controlling the session so the backdoor is less effective; this assumes that an attacker at a later moment does not have sufficient privileges anymore to set the Shadow key in the registry to the value of their liking
The WINSTATION_SHADOW permission can be removed from all entries in the Win32_TSAccount WMI class, although an attacker with administrative permissions can provide themselves this permission again
#RedTeam #RDP
@securation