Chains
TTPs
Blog
Login
Prelude TTP browser
Image File Execution Options Injection: Debugger
Tactic:
Persistence
Community
This is a community level chain. Download Prelude Operator to use this chain for free.
This procedure makes a backup of the sethc.exe utility and modifies a registry key that configures an agent as a "debugger" for sethc.exe providing persistent backdoor access.
View Command
You must be logged in to view this TTPs command.
Login
Authors
bfuzzy1
Tactic
Persistence
Test this TTP
Download Operator (1.7.1)