Bring Your Own Land (BYOL) – A Novel Red Teaming Technique

发布于 2018/06/18 FireEye Blog
Introduction One of most significant recent developments in sophisticated offensive operations is the use of "Living off the Land" (LotL) techniques by attackers. These techniques leverage legitimate tools present on the system, such as the PowerShell scripting language, in order to execute attacks. The popularity of PowerShell as an offensive tool culminated in the development of entire Red Team frameworks based around it, such as Empire and PowerSploit. In addition, the execution of PowerShell can be obfuscated through the use of tools such as "Invoke-Obfuscation".