# No-Code Malware: Windows 11 At Your Service > DEFCON30, 2022-08-13. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-08-13-defcon30-no-code-malware-windows-11-at-your-service/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/slides.pdf) - [Recording](https://www.youtube.com/watch?v=e8PEIOa6W9M) - [Conference agenda](https://info.defcon.org/events/48560/) - [DEFCON30 talk materials](https://github.com/mbrg/defcon30/tree/main/No_Code_Malware) - [Power-Pwn No-Code Malware module](https://github.com/mbrg/power-pwn/wiki/Modules:-No%E2%80%90Code-Malware) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-08-13-defcon30-no-code-malware-windows-11-at-your-service.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines or Office cloud, executed successfully and reports back to the cloud. You can probably already see where this is going.. In this presentation, we will show how Power Automate can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works, what attack surface it exposes on the machine and in the cloud, and how it is enabled by-default and can be used without explicit user consent. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official conference abstract](https://forum.defcon.org/node/241932)_ ## Transcript > AI generated from recording. ### Introduction and Motivation [00:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=0s) **Presenter:** Okay, so, hi everyone. So, you can probably judge from the title, but what we're going to do today is we're going to show how you can use Windows executables, service accounts, and cloud services to basically power your own malware operation. [00:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=19s) **Presenter:** Shortly about me, I've been around cybersecurity for a long time now, spent some time at, sorry. [00:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=34s) **Presenter:** Thank you for that. [00:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=36s) **Presenter:** So I spent a bunch of time at Microsoft on APIs, IoT, cloud. [00:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=42s) **Presenter:** I've been doing low-code, no-code security for like three years now, [00:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=45s) **Presenter:** which is weird because not many people are into it, [00:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=48s) **Presenter:** but you will soon be, so that's cool. [00:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=52s) **Presenter:** I started a company around 18 months ago called Zenity [00:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=56s) **Presenter:** with folks that are sitting right here. [00:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=58s) **Presenter:** We're focused on low-code, no-code security. [01:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=60s) **Presenter:** And again, first time at DEFCON, [01:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=63s) **Presenter:** very excited to be here, as you can probably hear. [01:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=65s) **Presenter:** So thank you for coming. [01:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=67s) **Presenter:** By the way, this talk is going to feature research from Ria Zilberberg, [01:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=71s) **Presenter:** sitting right here, one of our researchers. [01:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=73s) **Presenter:** So give him some love. [01:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=82s) **Presenter:** This one is important. [01:24](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=84s) **Presenter:** Low-code, no-code is a cool thing. [01:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=86s) **Presenter:** We are very much pro the movement. [01:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=89s) **Presenter:** And this talk, I will try to give you an attacker's perspective on that. [01:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=93s) **Presenter:** The reason, of course, is to make sure that this is done in a responsible way. ### RPA Fundamentals and Architecture [01:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=98s) **Presenter:** So what you're going to learn today, use it to educate people around you and let's see where it takes us. [01:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=108s) **Presenter:** Okay, so I'm going to start right now. [01:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=112s) **Presenter:** When I say creating or running your own malware operation, there are a bunch of things that could mean. [01:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=117s) **Presenter:** So let's figure out what exactly I'm meaning that we're going to do today. [02:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=121s) **Presenter:** So you have initial access to some victim machine. [02:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=125s) **Presenter:** there's a lot of other things that you need to do around it [02:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=128s) **Presenter:** in order to really call it a malware operation. [02:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=131s) **Presenter:** You need to be able to, um, okay. [02:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=135s) **Presenter:** So you need to be able to go through a firewall. [02:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=138s) **Presenter:** You need to be able to actually run malware on that machine [02:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=141s) **Presenter:** and be able to bypass DDR. [02:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=143s) **Presenter:** You need to be able to create command and control [02:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=147s) **Presenter:** across that firewall and to exfiltrate data back, [02:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=150s) **Presenter:** back to your, back, uh, backwards outside of the org. [02:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=155s) **Presenter:** avoid detection by a bunch of enterprise tools [02:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=159s) **Presenter:** that are out there in order to catch you. [02:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=161s) **Presenter:** And you need to remain persistent on the actual victim machine [02:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=165s) **Presenter:** when they are obviously trying to kick you out. [02:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=169s) **Presenter:** All of those things are a bunch of grunt work. [02:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=173s) **Presenter:** So what we're gonna do today is we're gonna show how [02:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=177s) **Presenter:** instead of having to do all of that yourself, [03:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=180s) **Presenter:** you can just focus on the initial access [03:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=182s) **Presenter:** and on the last part, which is kind of having fun. [03:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=185s) **Presenter:** And we're going to try and figure out [03:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=188s) **Presenter:** how we can use existing services [03:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=190s) **Presenter:** to take care of all of that ops for us. [03:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=198s) **Presenter:** So here's the service that we're going to use. [03:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=201s) **Presenter:** I'm not sure if you've heard about RPA. [03:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=203s) **Presenter:** This is basically a technology that is out there [03:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=206s) **Presenter:** in every major enterprise today. [03:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=209s) **Presenter:** It's really every world. [03:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=212s) **Presenter:** behind RPA is basically to take mundane processes that business users are doing, so copying [03:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=218s) **Presenter:** and pasting through different softwares that they have on their machine, and basically [03:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=223s) **Presenter:** automating it. And the way that it gets automated is that the users are actually emulated. So [03:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=230s) **Presenter:** the user gets impersonated, they are copying the keyboard and the mouse clicks and then [03:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=236s) **Presenter:** reiterating them, and that's the way that they're using the user's own identity. And [04:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=242s) **Presenter:** basically facilitate integration with old software that has no APIs, which makes it easier. [04:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=249s) **Presenter:** So RPA is built of three main components. The first one is an agent. It sits on somebody's laptop, [04:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=254s) **Presenter:** and it emulates the user, as I've just mentioned. The second part is the controller, which is able [04:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=260s) **Presenter:** to reach out to the machine, send some payload, the payload gets executed, and then the output gets [04:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=268s) **Presenter:** routed back. And there's a management portal which allows you to basically say, okay, here are all [04:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=273s) **Presenter:** my agents, here's the payload I'm going to send to each one of them. The key thing about this [04:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=278s) **Presenter:** technology is that every part here is trusted. And what do I mean by trusted? I mean trusted by [04:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=283s) **Presenter:** the EDR, trusted by network security, trusted by the SOC team. So on the agent side, there are [04:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=289s) **Presenter:** executables that are signed by the vendors themselves. We'll see that in a moment. The [04:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=294s) **Presenter:** the communication, so all of the endpoints, [04:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=296s) **Presenter:** all of the protocols, and the cloud services themselves. [05:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=301s) **Presenter:** And there are a bunch of vendors that are [05:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=305s) **Presenter:** providing these RPA solutions that, as I mentioned, [05:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=308s) **Presenter:** are everywhere in the enterprise. ### Microsoft Power Automate Desktop Overview [05:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=310s) **Presenter:** Today, as you've kind of realized from the talk's title, [05:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=314s) **Presenter:** we're gonna focus on Microsoft, [05:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=316s) **Presenter:** and you'll find out why in a moment, [05:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=318s) **Presenter:** but actually everything that I'm gonna show you today [05:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=320s) **Presenter:** is not specific to Microsoft. [05:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=321s) **Presenter:** but it's actually a problem, [05:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=325s) **Presenter:** it's actually inherent in the way that RPA works. [05:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=331s) **Presenter:** So RPA can take care of all of the malware ops [05:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=336s) **Presenter:** that I just talked about for us. [05:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=339s) **Presenter:** So command and control, [05:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=340s) **Presenter:** exfiltrating data outside of the org, [05:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=344s) **Presenter:** avoiding defense, [05:46](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=346s) **Presenter:** persistency, cleanup, [05:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=348s) **Presenter:** but it also will be able to give us much more. [05:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=352s) **Presenter:** errors, everything that's related to kind of engineering, [05:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=355s) **Presenter:** updating those agents, being able to support any type of [05:59](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=359s) **Presenter:** platform, those are all things that the RPA vendors will do [06:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=363s) **Presenter:** for us. [06:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=364s) **Presenter:** So this is a living of the land attack and we're going to live [06:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=367s) **Presenter:** off the land of RPA and specifically Microsoft RPA to do [06:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=371s) **Presenter:** what we want to do. [06:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=373s) **Presenter:** Here's our agenda for today. [06:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=374s) **Presenter:** So we covered the motivation, next up we're going to drill [06:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=378s) **Presenter:** down a bit more into what RPA is all about. [06:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=381s) **Presenter:** focused on, we'll do a deep dive and understand how it works. [06:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=385s) **Presenter:** Then I will shift gears and show you specifically [06:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=389s) **Presenter:** how do you take RPA and leverage it [06:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=391s) **Presenter:** to your own malware operation. [06:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=393s) **Presenter:** And we'll introduce a tool that will allow you [06:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=395s) **Presenter:** to do that quickly. [06:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=396s) **Presenter:** And don't worry, we'll also send you home [06:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=398s) **Presenter:** with kind of a few things you can do [06:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=399s) **Presenter:** to remain protected or protect your organization. [06:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=404s) **Presenter:** Okay, so in order to understand what RPA is, [06:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=408s) **Presenter:** let's start off with a story. [06:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=411s) **Presenter:** young, when I was a teenager, my friends and I used to play in a game called Tibia. Who [06:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=418s) **Presenter:** knows what Tibia is? Raise your hand. Okay. That's a weird game, weird MMORPG from a long [07:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=427s) **Presenter:** time ago where basically you kind of, you level up your character, you play with other [07:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=432s) **Presenter:** players, and you collaborate, but a lot of the actual time that you get, that you spend [07:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=439s) **Presenter:** of that game is actually doing things like fishing. So you need to improve your fishing [07:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=445s) **Presenter:** skills. In order to do that, you basically go to a pond and then you need to click. So [07:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=451s) **Presenter:** you click and you get some fish and you click and you get more fish and more fish. And this [07:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=456s) **Presenter:** is basically transforming clicks and virtual worms into virtual fish. This is important [07:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=464s) **Presenter:** for the game but it is extremely boring. So of course as a teenager I wanted to take advantage of this. [07:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=473s) **Presenter:** I wanted to basically be better than my friends and impress them. So I tried to find a creative solution [08:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=480s) **Presenter:** for this to work better. I started off with physical automation. I actually looked for a picture of this. [08:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=488s) **Presenter:** I couldn't find any picture. [08:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=490s) **Presenter:** I'm not sure why somebody in my family [08:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=492s) **Presenter:** didn't take the picture. [08:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=494s) **Presenter:** As you can imagine, this didn't work. ### Onboarding Victim Machines Programmatically [08:17](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=497s) **Presenter:** So the book would fall over. [08:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=499s) **Presenter:** I would wake up in the morning [08:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=501s) **Presenter:** and things were not as I expected. [08:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=505s) **Presenter:** So I had to find a better solution. [08:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=508s) **Presenter:** And I actually went with automation, [08:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=512s) **Presenter:** which was basically, there was software [08:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=515s) **Presenter:** that allowed me to basically record my keyboard [08:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=518s) **Presenter:** and my mouse and then replay them. [08:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=520s) **Presenter:** So I had this setup where I walk around the pond [08:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=523s) **Presenter:** and I click on a bunch of fish [08:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=525s) **Presenter:** and when I wake up in the morning, I'm leveled up. [08:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=529s) **Presenter:** So this is what it looks like. [08:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=531s) **Presenter:** I think you're seeing it. [08:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=533s) **Presenter:** And basically, this made me the hero of my friend. [08:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=535s) **Presenter:** So this was my first kind of, [08:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=537s) **Presenter:** the first moment I got some love, [09:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=541s) **Presenter:** kind of across, kind of became a bit popular. [09:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=546s) **Presenter:** And this is funny because this is actually the basis of RPA. [09:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=549s) **Presenter:** So the same technology that I used as a kid like 20 years ago [09:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=553s) **Presenter:** is being used in the enterprise today to do very serious things. [09:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=559s) **Presenter:** So RPA, as a quick recap, [09:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=563s) **Presenter:** it's about replacing copy and paste integration. [09:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=565s) **Presenter:** It's a drag and drop builder. [09:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=567s) **Presenter:** You'll see it in a moment. [09:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=568s) **Presenter:** And the people, and it's used, [09:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=572s) **Presenter:** the people that are building these RPA bots, [09:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=575s) **Presenter:** they can be in IT, but they can also be business users. [09:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=578s) **Presenter:** It emulates the user's own actions, [09:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=580s) **Presenter:** so it operates as the user with their own identity. [09:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=583s) **Presenter:** There's no way to distinguish those clearly. [09:46](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=586s) **Presenter:** And it runs on the user's machines. [09:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=588s) **Presenter:** And on the use cases side, [09:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=590s) **Presenter:** enterprises are really using it for serious things. [09:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=592s) **Presenter:** So customer services, financial services, [09:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=597s) **Presenter:** onboarding and offboarding, HR. [10:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=600s) **Presenter:** business sensitive data. [10:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=602s) **Presenter:** Now, we understand what, now that we understand what RPA is, [10:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=606s) **Presenter:** let's drill down technically into how it works [10:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=609s) **Presenter:** and how, and that would also kind of lead us in the way [10:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=612s) **Presenter:** that we're looking for with our malware op. [10:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=616s) **Presenter:** So, we want to use RPA for the malware operation. [10:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=621s) **Presenter:** And this is where we're gonna actually focus on Microsoft [10:24](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=624s) **Presenter:** and this is why. [10:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=625s) **Presenter:** So, Microsoft has released an RPA agent [10:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=627s) **Presenter:** called Power Automate Desktop [10:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=630s) **Presenter:** baked in to every Windows 11 machine. [10:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=632s) **Presenter:** And by baked in I mean that if you take [10:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=635s) **Presenter:** a fresh Windows machine, you'll search for Power Automate, [10:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=638s) **Presenter:** it'll be there. [10:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=639s) **Presenter:** It's also trusted by the EDR and trusted by other EDRs as well. ### Command & Control via Office Cloud [10:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=642s) **Presenter:** So that's why we're going to focus on Microsoft today. [10:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=647s) **Presenter:** Let's start from the user's perspective. [10:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=650s) **Presenter:** So this is a fresh Windows machine, Windows 11 machine. [10:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=654s) **Presenter:** Searching for Power Automate, I immediately find [10:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=656s) **Presenter:** this executable. [11:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=660s) **Presenter:** Let's see if this works. [11:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=667s) **Presenter:** Okay. [11:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=675s) **Presenter:** Okay, it works. [11:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=676s) **Presenter:** So what I'm showing you here is a quick video [11:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=679s) **Presenter:** that is me setting up my connection with that RPA service. [11:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=685s) **Presenter:** The third thing that I'm doing [11:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=687s) **Presenter:** is actually plugging in my office account [11:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=690s) **Presenter:** The crucial thing here is that I could plug in any Office account. [11:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=693s) **Presenter:** So in this example I created a new organization, [11:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=697s) **Presenter:** you'll see that in a moment, and I'm plugging in my credentials [11:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=700s) **Presenter:** with that organization. [11:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=701s) **Presenter:** Once I plug in those credentials I get to this drag and drop [11:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=704s) **Presenter:** builder with a bunch of operations that are available for me [11:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=707s) **Presenter:** and then I'm going to create a low word application [11:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=712s) **Presenter:** that basically writes a low word to a file on disk. [11:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=715s) **Presenter:** The crucial thing here is that this thing is synced [12:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=720s) **Presenter:** not anything to my cloud because I just logged in [12:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=723s) **Presenter:** with my account. [12:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=724s) **Presenter:** And so you'll see in a moment when I kind of finish off [12:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=726s) **Presenter:** with the demonstration here that there's a bunch, [12:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=729s) **Presenter:** so we're seeing it now, there are a bunch of execute, [12:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=732s) **Presenter:** basically bots or processes that are available for me [12:17](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=737s) **Presenter:** to pick and choose from. [12:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=739s) **Presenter:** Those are all things that I set up previously [12:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=743s) **Presenter:** in my office account. [12:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=747s) **Presenter:** So this is what you just saw. [12:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=750s) **Presenter:** plug in your credentials, your office credentials [12:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=752s) **Presenter:** to this Windows executable, [12:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=756s) **Presenter:** you get all of the different payloads that you, [12:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=758s) **Presenter:** or processes that you have created in an office. [12:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=762s) **Presenter:** This is how it looks like, [12:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=765s) **Presenter:** this is how it looks like from an architectural perspective. [12:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=767s) **Presenter:** So on one side you have Power Automate, the RPA agent, [12:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=770s) **Presenter:** and the other side you have Office. [12:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=772s) **Presenter:** One sits in on-prem and another in cloud, [12:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=774s) **Presenter:** and the reason that I'm focusing on that is that [12:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=777s) **Presenter:** Microsoft of course has to be deployed everywhere [13:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=780s) **Presenter:** They need to figure out how, I mean, how is this working? [13:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=783s) **Presenter:** They haven't asked for permission from anybody, right? [13:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=786s) **Presenter:** It's already there. [13:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=787s) **Presenter:** So what we're going to figure out right now, technically, [13:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=790s) **Presenter:** is how is this communicating? [13:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=793s) **Presenter:** So we'll focus first on the left side, [13:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=796s) **Presenter:** which is actually the local side. [13:17](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=797s) **Presenter:** Power Automate is not one executable. [13:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=799s) **Presenter:** There are a bunch of those. [13:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=801s) **Presenter:** There's one service that's called Power Automate [13:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=803s) **Presenter:** runs on the user's own account. [13:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=806s) **Presenter:** And there's another service account that's being created [13:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=810s) **Presenter:** that runs with an executable that's called machine runtime [13:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=814s) **Presenter:** and that will be the one that's actually in charge [13:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=816s) **Presenter:** of communicating with Office Cloud. [13:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=818s) **Presenter:** We'll see that in a moment. [13:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=820s) **Presenter:** There's also, Power Automate also allows you [13:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=822s) **Presenter:** to automate the browser. [13:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=824s) **Presenter:** So you can basically, so through an extension [13:46](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=826s) **Presenter:** on all popular browsers, you can change what users [13:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=829s) **Presenter:** are viewing on the browsers and you can also kind of [13:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=831s) **Presenter:** fetch all of the information that they have there. [13:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=833s) **Presenter:** So we'll add that to our architecture as well. [13:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=836s) **Presenter:** As you can see there are kind of, there are these extensions [14:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=840s) **Presenter:** all of the different browsers. [14:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=843s) **Presenter:** This is the, so what you're seeing here [14:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=846s) **Presenter:** is actually that I've only talked about three executables [14:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=849s) **Presenter:** out of about 20 that are built in to Windows 11, again. ### Executing Malware Payloads and Persistence [14:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=855s) **Presenter:** And you're seeing that this is in a trusted, [14:17](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=857s) **Presenter:** this is kind of in a trusted location. [14:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=860s) **Presenter:** So there's plenty of opportunity to do more research here. [14:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=865s) **Presenter:** So if you're looking for a challenge, [14:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=867s) **Presenter:** I recommend checking this out. [14:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=870s) **Presenter:** So let's switch to another direction [14:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=873s) **Presenter:** and talk about the communication. [14:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=875s) **Presenter:** So of course, network boundaries have been, [14:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=878s) **Presenter:** I mean people have been trying to maintain them [14:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=881s) **Presenter:** for a long time and there's a really serious question [14:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=884s) **Presenter:** we should ask ourselves here, [14:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=885s) **Presenter:** which is how is Microsoft able to communicate [14:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=887s) **Presenter:** with Office services without having some IT admin [14:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=890s) **Presenter:** open up a port somewhere. [14:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=892s) **Presenter:** The way that this is done is with a neat service [14:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=897s) **Presenter:** called Azure Service Bus. [15:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=900s) **Presenter:** Azure Relay, basically both sides are creating [15:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=904s) **Presenter:** outbound communication and so this is how the channel [15:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=907s) **Presenter:** gets created. [15:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=909s) **Presenter:** So the agent will reach out to Azure Service Bus [15:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=912s) **Presenter:** every couple of minutes and ask for new tasks [15:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=915s) **Presenter:** that it should pick up and use. [15:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=920s) **Presenter:** Okay, so we're connected, we understand how this thing [15:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=923s) **Presenter:** operates, we understand that it has components [15:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=927s) **Presenter:** that run as the user and components that run [15:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=930s) **Presenter:** as a service account. [15:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=932s) **Presenter:** The crucial thing to note right here, [15:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=935s) **Presenter:** because it's the last time I'm gonna say it, [15:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=936s) **Presenter:** is that all of these things are trusted. [15:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=939s) **Presenter:** The executables are trusted, [15:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=941s) **Presenter:** the service accounts are trusted, [15:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=942s) **Presenter:** the cloud accounts are trusted. [15:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=944s) **Presenter:** They are all in the allow list that you get by default. [15:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=949s) **Presenter:** Once you plug in your machine, [15:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=951s) **Presenter:** this is what you're seeing from the Office side. [15:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=953s) **Presenter:** So Office provides you with kind of a nice way [15:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=955s) **Presenter:** to view all of the machines that are connected to your cloud. [16:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=960s) **Presenter:** run things on the laptop from the cloud. [16:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=964s) **Presenter:** So you trigger, you create some sort of a payload [16:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=969s) **Presenter:** and you can execute it from the cloud on some machine. [16:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=972s) **Presenter:** And then you get status, you can look at history, [16:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=975s) **Presenter:** you can debug things, so all of the kind of convenience [16:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=979s) **Presenter:** layers that you need around it. [16:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=981s) **Presenter:** The last thing that I wanna cover in terms of architecture [16:24](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=984s) **Presenter:** is how is trust being established. [16:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=986s) **Presenter:** So it's not only about connection to the Azure service, [16:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=990s) **Presenter:** bus, actually there needs to be kind of a trusted communication between the two. So when you [16:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=996s) **Presenter:** register your machine with Power Automate that you saw me do a few minutes ago, there's a private [16:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1002s) **Presenter:** key that's being created on your local machine and a public key on the cloud side. And it's being [16:46](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1006s) **Presenter:** used to basically encrypt a message that sends two things to the machine through Azure Service [16:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1013s) **Presenter:** Bus. The first thing is local credentials. So you can run those payloads with whichever [17:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1020s) **Presenter:** would like on the machine. [17:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1022s) **Presenter:** And the second thing is an RPA task, [17:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1024s) **Presenter:** which is the kind of the process that you would like to run. [17:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1027s) **Presenter:** So again, in a summary, in a nutshell, [17:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1032s) **Presenter:** this runs on the, this executes on the user's own, [17:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1036s) **Presenter:** with the user's own credentials, [17:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1038s) **Presenter:** and it constantly goes out to office [17:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1041s) **Presenter:** and asking whether there's something [17:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1043s) **Presenter:** that needs to be running. [17:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1047s) **Presenter:** So what we're gonna do right now [17:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1050s) **Presenter:** switch gears up until now, it was kind of theoretical. [17:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1054s) **Presenter:** We're gonna go to specifics of how you can use this setup [17:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1058s) **Presenter:** to run your malware operation with Power Automate, [17:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1062s) **Presenter:** Microsoft's RPA. [17:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1064s) **Presenter:** So let's remember our wish list. [17:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1067s) **Presenter:** These were the things that we wanted to accomplish [17:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1069s) **Presenter:** when we started this conversation. [17:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1072s) **Presenter:** So all of the things here that are around ops, [17:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1076s) **Presenter:** we'll go through each one and show how they can be done. [18:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1080s) **Presenter:** we need a bit of setup. [18:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1083s) **Presenter:** So what you need in order to use this is basically create, [18:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1087s) **Presenter:** what I'm doing here is creating a new tenant within Microsoft. [18:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1090s) **Presenter:** It's kind of a trial version. [18:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1091s) **Presenter:** You don't need to plug in your credit cards. [18:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1093s) **Presenter:** It won't cost you anything. [18:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1095s) **Presenter:** I'm creating a new organization, [18:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1096s) **Presenter:** and you can see that once it is created, [18:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1101s) **Presenter:** there's a guide here which points me to how do I create, [18:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1105s) **Presenter:** how do I onboard new machines here? ### Automation Toolkit and Defensive Countermeasures — Part 1 [18:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1106s) **Presenter:** So we need to onboard Victor machines [18:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1109s) **Presenter:** into my malicious Microsoft account. [18:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1114s) **Presenter:** You've seen me do this already in the demo, [18:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1117s) **Presenter:** but this was done through UI, [18:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1119s) **Presenter:** which is kind of not what we're after, right, as hackers. [18:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1124s) **Presenter:** So the question is whether we can do it programmatically [18:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1127s) **Presenter:** with some script. [18:49](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1129s) **Presenter:** Fortunately, Microsoft has provided a script for us. [18:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1132s) **Presenter:** Again, signed already in your Windows machines. [18:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1137s) **Presenter:** this silent registration script and you provide it with your [19:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1143s) **Presenter:** organization ID and again the crucial piece here, [19:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1146s) **Presenter:** if you're thinking of detections as well, [19:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1149s) **Presenter:** is that you can plug in any tenant ID here. [19:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1152s) **Presenter:** So of course I'm just saying okay this is my account [19:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1156s) **Presenter:** and I'm pointing this agent to my malicious office tenant. [19:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1162s) **Presenter:** Once I run this script, I go back to the list of machines [19:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1167s) **Presenter:** and the machine is already there and you can see [19:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1169s) **Presenter:** that I have the status of the machine, [19:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1171s) **Presenter:** the version of the agent that's sitting here. [19:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1174s) **Presenter:** So that's kind of cool. [19:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1177s) **Presenter:** That's basically our way to onboard victims [19:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1181s) **Presenter:** to our malware operation. [19:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1184s) **Presenter:** One thing that was problematic about what I just showed you [19:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1188s) **Presenter:** is that this requires an admin privilege [19:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1190s) **Presenter:** on the local site to do this onboarding, [19:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1193s) **Presenter:** which makes this kind of boring, right? [19:56](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1196s) **Presenter:** Fortunately, that's not really the case. [19:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1198s) **Presenter:** So we didn't do anything special here. [20:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1201s) **Presenter:** We just tried. [20:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1202s) **Presenter:** It worked. [20:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1203s) **Presenter:** So, well, why not? [20:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1205s) **Presenter:** So you can just run this, [20:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1206s) **Presenter:** and it will connect the victim's machine to your cloud. [20:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1213s) **Presenter:** Once the victim machine is registered, [20:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1216s) **Presenter:** here's what you need to do [20:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1218s) **Presenter:** from the cloud to the machine. [20:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1223s) **Presenter:** So you create this automation from the cloud side. [20:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1227s) **Presenter:** You create a connection. [20:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1228s) **Presenter:** You basically choose which machine you're going to run on. [20:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1232s) **Presenter:** You choose the local credentials. [20:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1234s) **Presenter:** We saw that this is part of the payload earlier. [20:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1236s) **Presenter:** And you choose a specific payload [20:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1237s) **Presenter:** that you'd like to run. [20:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1238s) **Presenter:** Of course you can create new payloads [20:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1241s) **Presenter:** on your own machine and upload them to Windows. [20:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1244s) **Presenter:** One thing that we need to figure out, [20:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1248s) **Presenter:** we need to provide a user account here. [20:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1251s) **Presenter:** We need to figure out what happens [20:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1252s) **Presenter:** if that user is already logged in to the local account. [20:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1255s) **Presenter:** What would it do to the user session? [20:59](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1259s) **Presenter:** So again, people have already fixed this problem for us. [21:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1263s) **Presenter:** RPA has two versions. [21:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1265s) **Presenter:** Attended RPA, which basically runs in parallel [21:07](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1267s) **Presenter:** to a logged in user. [21:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1269s) **Presenter:** This also means I can take charge of everything [21:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1272s) **Presenter:** that the user is doing. [21:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1273s) **Presenter:** I can open the browser and take their cookies. [21:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1275s) **Presenter:** I can do everything that the user is doing. [21:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1278s) **Presenter:** Siders unattended RPA which basically creates a new session, [21:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1282s) **Presenter:** runs the payload and the scars of the session. [21:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1285s) **Presenter:** So we've seen a bunch of things. [21:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1289s) **Presenter:** From our list of malware operations that we wanted to create, [21:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1294s) **Presenter:** we know that we can deploy malware. [21:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1296s) **Presenter:** We saw this with the basically silent registration. [21:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1300s) **Presenter:** We know that this avoids defense. [21:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1302s) **Presenter:** Well this was the premise, everything here is trusted. [21:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1305s) **Presenter:** And we know that you can maintain persistency [21:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1308s) **Presenter:** anything on the laptop, right? I only used Microsoft's own [21:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1313s) **Presenter:** executables. What we're gonna show next is how we'll accomplish [21:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1317s) **Presenter:** all of the things that are left over. Now we've already kind of [22:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1323s) **Presenter:** seen command and control but we only saw specific payloads so [22:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1328s) **Presenter:** let's drill down into it some more. Okay. This is how we're [22:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1338s) **Presenter:** what you can build with this RPA. [22:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1340s) **Presenter:** What can you actually do on the user's machine? [22:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1343s) **Presenter:** So here's a very quick data X field for you. [22:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1347s) **Presenter:** This is an RPA flow that does the following. [22:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1350s) **Presenter:** It gets as an input a file, a path on the hard disk, [22:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1354s) **Presenter:** and it basically, it reads the file, [22:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1356s) **Presenter:** and it sends the file content as an output of that flow. [22:40](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1360s) **Presenter:** Again, this runs with Microsoft's executable. [22:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1364s) **Presenter:** From, and the key thing that we need to think about is [22:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1368s) **Presenter:** the output actually going, so it's going to Microsoft Cloud. [22:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1372s) **Presenter:** I'm triggering it from Office, I'm logging into Office [22:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1374s) **Presenter:** with my malicious account, I'm sending out this payload [22:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1377s) **Presenter:** and I get in response the actual, the content of the file. [23:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1382s) **Presenter:** So recalling the architecture that we saw earlier, [23:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1386s) **Presenter:** let's figure out where does the data move to make sure [23:09](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1389s) **Presenter:** that we don't get caught along the way. [23:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1392s) **Presenter:** So this is the architecture that we saw and these are the [23:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1396s) **Presenter:** three steps that are actually happening. [23:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1398s) **Presenter:** building those instructions on my side [23:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1400s) **Presenter:** on a malicious machine somewhere [23:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1402s) **Presenter:** and I'm uploading the instructions to Office Cloud. [23:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1405s) **Presenter:** Then I'm sending the payload to the machine [23:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1407s) **Presenter:** through the Microsoft trusted communication channel [23:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1410s) **Presenter:** and the output goes through that same channel. [23:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1413s) **Presenter:** So again, completely undetected. [23:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1418s) **Presenter:** So here's another example. [23:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1421s) **Presenter:** We're gonna, so this example goes through code execution. [23:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1425s) **Presenter:** So we saw that you can run specific payloads, but actually I would like to be able to run everything that I want on that laptop. [23:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1435s) **Presenter:** So again, fortunately, the RPA agent provides you with the operations that allow you to execute actual code. [24:04](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1444s) **Presenter:** So command lines, PowerShell, Python, JavaScript. [24:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1448s) **Presenter:** So here's a quick automation. [24:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1451s) **Presenter:** I'm basically sending out a script, [24:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1454s) **Presenter:** telling them which kind of script, [24:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1456s) **Presenter:** how will it be executed, [24:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1458s) **Presenter:** and then I'm exfiltrating outside the STD out and STD error. [24:24](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1464s) **Presenter:** Actually, the problem is that when I run this, [24:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1467s) **Presenter:** it gets flagged by Microsoft EDR. [24:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1471s) **Presenter:** Now why does it get flagged? [24:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1474s) **Presenter:** I mean it gets flagged because I ran a command line. [24:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1477s) **Presenter:** It doesn't really matter who created that command line. [24:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1481s) **Presenter:** the EDR is very focused on looking on those command lines [24:44](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1484s) **Presenter:** that are actually running. [24:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1487s) **Presenter:** So you can see that I basically went out of the trusted part. [24:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1491s) **Presenter:** So there's the trusted part, the RPA agent, [24:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1493s) **Presenter:** which is able to run some sort of code. [24:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1495s) **Presenter:** Like here's a piece of code, run it with this executable [24:59](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1499s) **Presenter:** or that executable. [25:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1500s) **Presenter:** And there's the untrusted part, which is the command line. [25:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1503s) **Presenter:** So the question becomes, what can we do [25:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1505s) **Presenter:** only with this drag and drop primitive? [25:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1508s) **Presenter:** So what kind of malware we can build only with no code? [25:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1513s) **Presenter:** Actually, we can do a whole bunch of things. [25:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1515s) **Presenter:** So these are all things that are provided by the RPA agent. [25:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1519s) **Presenter:** Let me name some of them. [25:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1521s) **Presenter:** You can use the built-in encryption function to encrypt files. [25:24](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1524s) **Presenter:** You can trigger HTTP calls. ### Automation Toolkit and Defensive Countermeasures — Part 2 [25:26](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1526s) **Presenter:** You can communicate with Active Directory in Windows services and processes. [25:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1529s) **Presenter:** You can look at files and folders. [25:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1531s) **Presenter:** You can automate the browser. [25:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1533s) **Presenter:** You can take screenshots. [25:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1534s) **Presenter:** You can automate the mouse and the keyboard. [25:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1537s) **Presenter:** you get it, right? You can do basically everything. So let's do a couple of things. [25:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1545s) **Presenter:** Here's no code ransomware for you. This one is, again, very simple. I'm iterating through the [25:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1554s) **Presenter:** drive, through the local drive. I'm reading the file, encrypting that file with the [26:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1561s) **Presenter:** provided an encryption function, [26:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1563s) **Presenter:** and then [26:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1565s) **Presenter:** stamping that file with, [26:06](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1566s) **Presenter:** replacing it from the original. [26:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1570s) **Presenter:** Here's how this gets [26:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1571s) **Presenter:** triggered from the cloud side. [26:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1578s) **Presenter:** So again, very [26:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1579s) **Presenter:** simple. I'm saying, here's [26:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1581s) **Presenter:** the directory I'd like to encrypt. Here's a private [26:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1583s) **Presenter:** key, and it will just [26:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1585s) **Presenter:** go to the machine, send the [26:27](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1587s) **Presenter:** payload, encrypt the file, and that's [26:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1591s) **Presenter:** here that I don't have a lot of time so I'm gonna, [26:34](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1594s) **Presenter:** I'm gonna skip kind of through it but as you can see [26:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1597s) **Presenter:** this is being triggered from the cloud side [26:39](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1599s) **Presenter:** and when the task gets finished and you saw that [26:42](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1602s) **Presenter:** this already happened, I basically see it, [26:45](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1605s) **Presenter:** I get the results on the cloud and from the machine side [26:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1608s) **Presenter:** of course the files are encrypted, the EDR didn't catch it, [26:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1612s) **Presenter:** this is all being done by the Microsoft executable. [26:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1617s) **Presenter:** Okay. [26:59](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1619s) **Presenter:** Okay, here's another one for you. [27:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1621s) **Presenter:** So we know that this agent is actually creating [27:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1625s) **Presenter:** a whole bunch of logs, the agent that we're actually using. [27:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1628s) **Presenter:** Because every time that it gets called, [27:11](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1631s) **Presenter:** it writes what did it call, what exactly did it do. [27:16](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1636s) **Presenter:** But again, looking at Microsoft documentation, [27:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1639s) **Presenter:** we can figure out where these logs are being maintained [27:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1642s) **Presenter:** and we can just go ahead and delete them. [27:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1645s) **Presenter:** So here's a flow to do that. [27:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1648s) **Presenter:** I'll finish off with one more. [27:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1651s) **Presenter:** We talked about the browser, so here's a quick thing [27:36](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1656s) **Presenter:** that we can do. [27:37](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1657s) **Presenter:** We can open the browser, we can go to some endpoint [27:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1661s) **Presenter:** that we'd like to steal the user's token from, [27:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1663s) **Presenter:** and we just plug in a JavaScript shell inside of that, [27:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1670s) **Presenter:** inside of that browser to basically take home the cookie. [27:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1674s) **Presenter:** So there's a quick demo for that here. [27:57](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1677s) **Presenter:** I'm not sure I have the time, but basically, [28:00](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1680s) **Presenter:** it's really simple. [28:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1682s) **Presenter:** What this does is it opens up the browser, [28:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1685s) **Presenter:** it goes to that location, and it just runs [28:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1688s) **Presenter:** the JavaScript script that I've mentioned. [28:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1692s) **Presenter:** And fortunately, there's a nice property here [28:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1695s) **Presenter:** where you can open the browser in a minimized version, [28:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1698s) **Presenter:** so the user won't know this. [28:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1703s) **Presenter:** Okay. [28:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1703s) **Presenter:** Okay. So a quick recap on everything we did up until now. We saw how you can deploy malware, you can avoid detection, you can remain persistent. We saw how you can create command and control through the office cloud. We saw exfiltration and cleanup. We actually wanted to show a bunch of other things like keylogger and other things, but you can just play around with it and I'm sure you'll find it nice. [28:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1730s) **Presenter:** Um, the one thing that I'm going, the one thing that I have left for you is how do you do all of that as part of your existing arsenal? So you don't want to be playing with UI for Office and those things. So, um, we've introduced this new tool for you. You can, uh, you can go ahead and use it right now. You'll have an address in a moment. [29:12](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1752s) **Presenter:** basically we've covered a bunch of things for you [29:14](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1754s) **Presenter:** so we are handling errors, [29:17](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1757s) **Presenter:** we are creating an HTTP endpoint [29:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1759s) **Presenter:** on the malicious office side [29:21](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1761s) **Presenter:** which you can just call [29:22](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1762s) **Presenter:** and then you do something like you post [29:25](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1765s) **Presenter:** okay here's the machine I'd like to run this payload on, [29:29](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1769s) **Presenter:** here's the payload I'd like to run, [29:31](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1771s) **Presenter:** here are some parameters [29:32](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1772s) **Presenter:** and you get back all of the outputs of that process [29:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1778s) **Presenter:** and all of the things that you saw here in the talk [29:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1781s) **Presenter:** and other payloads as well [29:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1783s) **Presenter:** are available through that tool. [29:46](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1786s) **Presenter:** So this is available right now. [29:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1788s) **Presenter:** There's a convenience layer around it in Python. [29:51](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1791s) **Presenter:** Let me quickly describe how it works. [29:54](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1794s) **Presenter:** You create your Microsoft tenant. [29:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1798s) **Presenter:** There are instructions on how to do that. [30:01](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1801s) **Presenter:** Again, no credit card, free of charge. [30:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1803s) **Presenter:** You run a quick script for setting up the tenant. [30:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1808s) **Presenter:** register with your machines with Microsoft executables, not mine, and then you use this [30:13](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1813s) **Presenter:** nice Python script to do things like run ransomware, run specific commands, and please feel [30:19](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1819s) **Presenter:** free to send out pull requests with new payloads. So, we're about done. Let's do a quick recap. [30:30](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1830s) **Presenter:** We saw what RPA is. We saw it's available on every major enterprise. Check it out back home. [30:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1838s) **Presenter:** We saw how it works and we saw how it can be used to power a model operation. We saw that [30:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1843s) **Presenter:** you can use it with low code primitives that basically allow you to do whatever you want. [30:48](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1848s) **Presenter:** We saw power pawn which is a new tool that you can use right now to play around with [30:52](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1852s) **Presenter:** it and to see how it works. The last thing I'm going to do and I'll do it very quickly [30:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1858s) **Presenter:** is leave you off with a few things you can do to protect yourself, to protect your organization. [31:05](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1865s) **Presenter:** So here's one very, very obvious thing. [31:08](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1868s) **Presenter:** Monitor these executables. [31:10](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1870s) **Presenter:** So as you can see, you need to make sure that, [31:15](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1875s) **Presenter:** basically the number one thing you need to make sure [31:18](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1878s) **Presenter:** is that people are not registering those agents [31:20](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1880s) **Presenter:** to a tenant that is not your own. [31:23](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1883s) **Presenter:** You can also review, this entire talk was focused [31:28](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1888s) **Presenter:** on using the existing tools without talking about [31:33](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1893s) **Presenter:** the organization itself is going to use it. [31:35](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1895s) **Presenter:** So your users might actually be using this. [31:38](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1898s) **Presenter:** If they're using this, there are a bunch of issues [31:41](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1901s) **Presenter:** that can occur, and if that's interesting for you, [31:43](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1903s) **Presenter:** I have another talk here at 4 p.m., same room, [31:47](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1907s) **Presenter:** so if you're not tired of me yet, see you again. [31:50](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1910s) **Presenter:** And there are a bunch of information that you can use here [31:53](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1913s) **Presenter:** to learn more, Microsoft documentation, [31:55](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1915s) **Presenter:** there's an OWASP group that is focused on this area, [31:58](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1918s) **Presenter:** and a bunch of blogs and content. [32:02](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1922s) **Presenter:** Thank you very much. [32:03](https://www.youtube.com/watch?v=e8PEIOa6W9M&t=1923s) **Presenter:** Thank you. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/716c44c7/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 No Code Malware: — Windows 11 At Your Service — Michael Bargury @ Zenity — slide 1 of 86 ### Slide 2 About me — CTO and co-founder @ Zenity — Ex MSFT cloud security — slide 2 of 86 ### Slide 3 Disclaimer — This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of No Code. — No Code is awesome. — slide 3 of 86 ### Slide 4 Initial — access to full — operation — slide 4 of 86 ### Slide 5 You’re in. Congrats! — Victim — Hacker — slide 5 of 86 ### Slide 6 In the real world — Victim — Hacker — slide 6 of 86 ### Slide 7 In the real world — Victim — Hacker — slide 7 of 86 ### Slide 8 In the real world — Victim — Hacker — slide 8 of 86 ### Slide 9 In the real world — Victim — Hacker — slide 9 of 86 ### Slide 10 In the real world — Victim — Hacker — slide 10 of 86 ### Slide 11 In the real world — Victim — Hacker — slide 11 of 86 ### Slide 12 We wanted to do hacking, not ops — Initial access — Deploy malware — slide 12 of 86 ### Slide 13 Introducing.. Robotic Process Automation (RPA)! — https://www.t-plan.com/rpa-architecture/ — slide 13 of 86 ### Slide 14 Introducing.. Robotic Process Automation (RPA)! — Trusted executables — Trusted cloud services — slide 14 of 86 ### Slide 15 RPA is everywhere — (in the enterprise) — slide 15 of 86 ### Slide 16 RPA can take care of Ops for us — C&C — Exfiltration — slide 16 of 86 ### Slide 17 Outline — Malware Ops motivation — What is RPA? — slide 17 of 86 ### Slide 18 What is RPA? — How anyone can automate mundane processes — slide 18 of 86 ### Slide 19 Teenage (MMORPG) life — slide 19 of 86 ### Slide 20 Grunt work required — slide 20 of 86 ### Slide 21 Grunt work required — slide 21 of 86 ### Slide 22 Grunt work required — slide 22 of 86 ### Slide 23 Grunt work required — slide 23 of 86 ### Slide 24 Grunt work required — slide 24 of 86 ### Slide 25 Mouse automation plus Tibia fishing equals in-game profit — slide 25 of 86 ### Slide 26 Automation!! — slide 26 of 86 ### Slide 27 Automation for real — slide 27 of 86 ### Slide 28 Animated Tibia gameplay automation demonstration — slide 28 of 86 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/716c44c7/media/automation-for-real.gif) ### Slide 29 Automation via RPA — Why and How? — Replace “copy-and-paste integration” — slide 29 of 86 ### Slide 30 Automation in the enterprise — Use cases: — Customer service routines — slide 30 of 86 ### Slide 31 RPA Deep Dive — slide 31 of 86 ### Slide 32 “included in Windows 11” — https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ — slide 32 of 86 ### Slide 33 Windows 11 search results showing the preinstalled Power Automate application — slide 33 of 86 ### Slide 34 Demonstration of Microsoft Power Automate Desktop on Windows 11 — slide 34 of 86 - Youtube: [defcon30 Power Automate Desktop](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 35 Synced to cloud — slide 35 of 86 ### Slide 36 Diagram separating local Windows 11 Power Automate from Office cloud services — slide 36 of 86 ### Slide 37 Diagram showing Power Automate communicating with the machine runtime service account — slide 37 of 86 ### Slide 38 Power Automate browser-extension installation shown over the local and cloud architecture — slide 38 of 86 ### Slide 39 Diagram showing Power Automate, the machine runtime, and supported browsers — slide 39 of 86 ### Slide 40 Power Automate Desktop application directory highlighting browser and runtime executables — slide 40 of 86 ### Slide 41 Corp network boundary — 🔥💀🔥💀🔥💀🔥💀 — slide 41 of 86 ### Slide 42 🔥💀🔥💀🔥💀🔥💀 — Corp network boundary — slide 42 of 86 ### Slide 43 Architecture diagram connecting Power Automate machine runtime to Office cloud services through Azure Service Bus — slide 43 of 86 ### Slide 44 Your machines — slide 44 of 86 ### Slide 45 Run from cloud — slide 45 of 86 ### Slide 46 Task status — slide 46 of 86 ### Slide 47 Architecture diagram connecting Power Automate machine runtime to Azure Service Bus — slide 47 of 86 ### Slide 48 Power Automate architecture diagram showing local private and cloud public keys — slide 48 of 86 ### Slide 49 Power Automate architecture diagram showing local credentials and an RPA task sent through Azure Service Bus — slide 49 of 86 ### Slide 50 RCE as a Service — Repurpose RPA to power — malware ops — slide 50 of 86 ### Slide 51 Recall our wish list — Initial access — Deploy malware — slide 51 of 86 ### Slide 52 Hello Pwntoso — slide 52 of 86 ### Slide 53 Register victim machines — Can we avoid the UI? — slide 53 of 86 ### Slide 54 Register victim machines — https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine — Sure! — slide 54 of 86 ### Slide 55 Hello new machine — slide 55 of 86 ### Slide 56 Admin required — https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine — 😞 — slide 56 of 86 ### Slide 57 Admin — NOT — required — slide 57 of 86 ### Slide 58 Trigger from cloud — Set up connection — Distribute payload — slide 58 of 86 ### Slide 59 How to avoid active machine users — Attended RPA — 💻🙂 — slide 59 of 86 ### Slide 60 Recap — Deploy malware — Defense evasion — slide 60 of 86 ### Slide 61 Let the fun begin. — slide 61 of 86 ### Slide 62 Data exfil (start simple) — Data exfiltrated as flow output — slide 62 of 86 ### Slide 63 Distribute payload, execute and collect output from cloud — Input — Output — slide 63 of 86 ### Slide 64 Power Automate architecture from Windows browsers and machine runtime through Azure Service Bus to Office cloud services — slide 64 of 86 ### Slide 65 1.Instructions — 2.Payload — 3.Output — slide 65 of 86 ### Slide 66 Code execution — slide 66 of 86 ### Slide 67 Oops — Code execution — slide 67 of 86 ### Slide 68 Code execution — Oops — slide 68 of 86 ### Slide 69 Code execution – try again — Untrusted — Trusted — slide 69 of 86 ### Slide 70 Code execution– try again — What can we do with drag & drop primitives only (No Code)? — slide 70 of 86 ### Slide 71 No Code primitives — slide 71 of 86 ### Slide 72 No Code Ransomware — slide 72 of 86 ### Slide 73 Demonstration of ransomware implemented through Power Automate — slide 73 of 86 - Youtube: [defcon30 No Code Ransomware](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 74 No Code Cleanup — slide 74 of 86 ### Slide 75 Machine to Cloud via the browser — https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers — Open browser minimized — slide 75 of 86 ### Slide 76 Local demonstration of stealing a browser token with Power Automate Desktop — slide 76 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/716c44c7/media/steal-browser-token-local.mp4) ### Slide 77 Cloud-triggered demonstration of stealing a browser token with Power Automate Desktop — slide 77 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-08-13_DEFCON30_No_Code_Malware/716c44c7/media/steal-browser-token-cloud.mp4) ### Slide 78 Recap — Deploy malware — Defense evasion — slide 78 of 86 ### Slide 79 Introducing — Power — Pwn — slide 79 of 86 ### Slide 80 Power — Pwn — ! — slide 80 of 86 ### Slide 81 One endpoint to rule them all! — POST machine=win11ent user= — alexg — slide 81 of 86 ### Slide 82 Convenience layer in Python — Set up a free RPA account — Register machines — slide 82 of 86 ### Slide 83 Summary — What is RPA? — Available in every major enterprise — slide 83 of 86 ### Slide 84 How To Stay Safe? — slide 84 of 86 ### Slide 85 Do these 4 things to reduce your risk — Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines — Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization — slide 85 of 86 ### Slide 86 No Code Malware: — Windows 11 At Your Service — Michael Bargury @ Zenity — slide 86 of 86