This ability downloads a custom dll that can be injected into remote processes. The DLL will make a system() call for
whatever value is stored in the Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Prelude\Operator key with the name `bin_path`
(so bin_path with a string `C:\\Windows\\System32\\cmd.exe` for example). The DLL itself is designed to be injected
into a remote process where it will execute the binary listed in the registry key.
To view this TTPs command, you must be logged in with a professional or enterprise license.
About PreludePrelude hardens an organization's defenses by continuously “asking” it questions through the form of safe cyberattacks. These attacks respond immediately to the latest vulnerabilities and cyber events, turning complex technical descriptions into deployable “questions”.Our mission is to increase the reach, frequency and usage of advanced security for all organizations.