Merge pull request #688 from botlabsDev/patch-0

Add tool 'BadPotato' to clusters/tool.json
pull/692/head v2.4.156
Alexandre Dulaunoy 2022-03-15 12:30:47 +01:00 committed by GitHub
commit 18069ce5f3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 14 additions and 1 deletions

View File

@ -8471,7 +8471,20 @@
},
"uuid": "f3bae23a-ec73-49cb-8149-f93578bb2bff",
"value": "Motnug"
},
{
"description": "BadPotato leaks a system token handle through the MS RPN API, which can be used to get NT AUTHORITY\\SYSTEM access.",
"meta": {
"refs": [
"https://github.com/BeichenDream/BadPotato",
"https://www.mandiant.com/resources/apt41-us-state-governments",
"https://thehackernews.com/2021/06/chinese-hackers-believed-to-be-behind.html",
"https://blog.group-ib.com/colunmtk_apt41"
]
},
"uuid": "f43a3828-a3b6-11ec-80e1-55a8e5815c2c",
"value": "BadPotato"
}
],
"version": 149
"version": 150
}