Skip to content

Latest commit

 

History

History
23 lines (13 loc) · 644 Bytes

File metadata and controls

23 lines (13 loc) · 644 Bytes
description
Sticky keys backdoor.

Sticky Keys

Execution

Replace the originali sethc.exe with a cmd.exe and rename it. You may need to change sethc.exe owner to yourself first as TrustedIntaller may be giving you a hard time:

Hit shift 5 times while on the logon screen to invoke the backdoor:

Observations

If you notice sethc.exe spawning well known windows processes, you may want to investigate the endpoint further: