WMEye is an experimental tool that was developed when exploring about Windows WMI. The tool is developed for performing Lateral Movement using WMI and remote MSBuild Execution. It uploads the encoded/encrypted shellcode into remote targets WMI Class Property, create an event filter that when triggered writes an MSBuild based Payload using a special WMI Class called Log File Event Consumer and finally executes the payload remotely.
Fileless Lateral Movement using WMI, can be used with Cobalt Strike’s Execute-Assembly
Note: This is still in experimental stage and no where near to be used in a real engagement.
Win32_Process Create to call MSbuild remotelyThe MSBuild Payload fetches encoded shellcode from WMI Class Property, decodes and executes it.
Both git fetch and git pull talk to a remote repository, but they do very different things to your…
Sometimes the change you need already exists, just on the wrong branch. A hotfix lands…
Email is still one of the most important communication channels inside modern applications. Password resets,…
Nginx is a high-performance web server and reverse proxy trusted by some of the largest…
ufw (Uncomplicated Firewall) sits on top of iptables (or nftables on newer systems) and replaces…
When you share a server with a team or investigate unexpected activity, the first question…