Возможно ли бесфайловое боковое движение с помощью mshta,rundll32,regsrv32 и тд.?Как на это реагируют антивирусы?
These processes require files to work withfileless with mshta, rundll32, regsrv32
It will be detectedHow do antiviruses react to this?
No mshta allows u to execute scripts by url, same as rundll and regsrv aloows to execute sct filesThese processes require files to work with
i understand it. Im intrested if AV kills suspicious processes like rundll or mshta with url as argumentNot directly. Can use methods like psexec or remote powershell to run them on another target on the network.
Yes it willif AV kills suspicious processes like rundll or mshta with url as argument