ClickOnce (Twice or Thrice): A Technique for Social Engineering and (Un)trusted Command Execution Logo

ClickOnce (Twice or Thrice): A Technique for Social Engineering and (Un)trusted Command Execution

0
Free
Visit Website

ClickOnce is a Microsoft technology that enables the user to install and run a Windows-based smart client application by clicking a link in a web page. With a little bit of C# coding knowledge, a red teamer or penetration tester has yet another capability to add to their ethical hacker toolkit. What are the requirements for operational use? To get started with ClickOnce, we need to do our homework and get a few things prepared: For social engineering campaigns, Microsoft web browsers (Edge/Internet Explorer) are required to invoke the ClickOnce installer. Additionally, target organizations must have the appropriate version of .NET Framework installed to launch the respective payload.

FEATURES

ALTERNATIVES

Caldera is a cybersecurity framework by MITRE for automated security assessments and adversary emulation.

Fast web spider written in Go

Adversary emulation framework for testing security measures in network environments.

Explore the top million websites, ranked by referring subnets, and gain insights into online influence and popularity.

Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.

Pupy is a cross-platform C2 and post-exploitation framework for remote access and control of compromised systems across various operating systems.

Back-end component for red team operations with crucial design considerations.

A collection of scripts for Turbo Intruder, a penetration testing tool