CMSTP
Theory
Cmstp.exe is a indows binary that allow administrator to installs or removes a Connection Manager service profile. As a red teamer, we can abuse it to execute code and bypass application whitelisting.
Practice
First, generate a reverse shell as dll
Creating a file that will be loaded by CSMTP.exe binary that will in turn load our evil.dll:
Now, we can invoke the payload:
Resources
Last updated
Was this helpful?