Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Getting Started with WMI Weaponization – Part 6

Summary

Introduces Invoke-WMIFS, a PowerShell module that abuses a custom WMI class to stash files as Base64 chunks inside the CIM repository, a quota-aware covert storage trick for evasive operations.
Published
Collected

original ↗