Accessibility features Backdoor
MITRE ATT&CK™ Event Triggered Execution - Accessibility Features - Technique T1546.008
Last updated
Was this helpful?
MITRE ATT&CK™ Event Triggered Execution - Accessibility Features - Technique T1546.008
Last updated
Was this helpful?
The concept here is pretty simple. Windows supports some built in accessibility features like Sticky Keys, Utilman, Narrator, Magnify that are available at pre-logon (at the login screen, either via a physical console or via Remote Desktop). Replacing them by cmd.exe live us with a SYSTEM access at pre-logon.
We can replace the C:\Windows\System32\Utilman.exe
with a cmd.exe and rename it (utilman.exe). You may need to change utilman.exe owner to yourself first as TrustedIntaller may be giving you a hard time.
An other way is just to edit the Image File Execution Options registry
Know, press Windows Key
+U
to spawn an elevated shell