The Praetorian Labs team was tasked with identifying novel and previously undocumented persistence mechanisms for use in red team engagements. Our primary focus was on persistence techniques achievable through modifications in HKCU, allowing for stealthy, user-level persistence without requiring administrative privileges. Unfortunately, while we identified an interesting persistence technique, the method we discuss in this…
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2025/02/leveraging-microsoft-text-services-framework-tsf-for-red-team-operations/