Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence (Part 2)
Two weeks ago, I blogged about several “pass-thru” techniques that leveraged the use of INF files (‘.inf’) to “fetch and execute” remote script component files (‘.sct’). In general, instances of these methods could potentially be abused to bypass application whitelisting (AWL) policies (e.g. Default AppLocker policies), deter host-based security products, and achieve ‘hidden’ persistence. Additionally, a few other “fetch and execute” techniques were highlighted for situational awareness, and several defensive considerations were presented. If you have not already done so, I’d highly recommend reviewing Part 1 [Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence] before proceeding as we will revisit a few prior topics before presenting these INF-SCT methods: InfDefaultInstall IExpress IEadvpack.dll (LaunchINFSection) IE4uinit Revisiting Setupapi.dll (InstallHinfSection) and Advpack.dll (LaunchINFSection) Setupapi.dll (InstallHinfSection) – InfDefaultInstall.exe In their DerbyCon 2017 talk – Evading AutoRuns, @KyleHanslovan and @ChrisBisnett of @HuntressLabs presented several INF-SCT techniques
FEATURES
SIMILAR TOOLS
Holistic malware analysis platform with interactive sandbox, static analyzer, and emulation capabilities.
A freeware suite of tools for PE editing and process viewing, including CFF Explorer and Resource Editor.
A project providing open-source YARA rules for malware and malicious file detection
YaraHunter scans container images, running Docker containers, and filesystems to find indicators of malware.
A new age tool for binary analysis that uses statistical visualizations to help find patterns in large amounts of binary data.
A tool for injecting and loading executables with a focus on stealth techniques.
A Windows context menu integration tool that scans files and folders for malware patterns, crypto signatures, and malicious documents using Yara rules and PEID signatures.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.