# No-Code Malware: Windows at Your Service > BSides Orlando 2022, 2022-11-19. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-11-19-bsides-orlando-no-code-malware-windows-at-your-service/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/slides.pdf) - [Recording](https://www.youtube.com/watch?v=e1Re2nbPQv4) - [Source code](https://github.com/mbrg/power-pwn/wiki/Modules:-No%E2%80%90Code-Malware) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-11-19-bsides-orlando-no-code-malware-windows-at-your-service.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate Desktop, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines, executed successfully and reports back to the cloud. You can probably already see where this is going.. In this presentation, we will show how Power Automate Desktop can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works, what attack surface it exposes on the machine and in the cloud, and how Microsoft managed to enable it across their customer base without explicit user consent. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official agenda abstract for this talk, sourced from BSides Vienna 0x7E6](https://cfp.bsidesvienna.at/bsidesvienna-2022/talk/EAKWZL/)_ ## Transcript > AI generated from recording. ### Introduction and Context [00:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=0s) **Presenter:** Welcome to No-Code Malware Windows 11 at Your Service. [00:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=8s) **Presenter:** Hello BSides Orlando. [00:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=21s) **Presenter:** Hi everyone, I'm excited to be here at BSides Orlando and welcome to No-Code Malware Windows at Your Service. [00:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=30s) **Presenter:** focusing on how do you use, how do you take Microsoft signed executables, [00:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=36s) **Presenter:** services and cloud services and turn them into your own malware operations. [00:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=49s) **Presenter:** Hi everyone, I'm really excited to be here at VisHeads Orlando. [00:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=57s) **Presenter:** Hi everyone, I'm really excited to be presenting this talk in Visas Orlando even though it's [01:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=62s) **Presenter:** virtual. This talk is going to be fun. We're going to show you how you can take Microsoft [01:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=68s) **Presenter:** signed executables, local services and cloud services and turn them into your own malware [01:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=74s) **Presenter:** operation. A little bit about myself. I've been in this space of low-code, no-code security [01:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=83s) **Presenter:** for the last four years now. [01:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=86s) **Presenter:** About two years ago, I co-founded Zenity, [01:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=88s) **Presenter:** where a company focused on security for low-code, no-code apps. [01:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=92s) **Presenter:** I've spent a bunch of time at Microsoft, [01:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=95s) **Presenter:** really all around security with IoT and API [01:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=99s) **Presenter:** and infrastructure and code application security. [01:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=102s) **Presenter:** I also lead a project, an OWASP project, [01:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=105s) **Presenter:** dedicated to low-code, no-code risks. [01:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=107s) **Presenter:** And so you can find us out there. [01:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=110s) **Presenter:** There's a whole bunch of information we are putting forth. [01:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=113s) **Presenter:** And I write in dark reading again about low code. [01:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=117s) **Presenter:** If you find the subjects of this talk interesting, [02:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=120s) **Presenter:** if you want to talk more, please reach out to me on Twitter. [02:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=124s) **Presenter:** I'd be happy to chat. [02:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=126s) **Presenter:** So this slide is important because, of course, we love no code. [02:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=132s) **Presenter:** We think that it's great. [02:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=133s) **Presenter:** It's empowering people to do things that they were not able to do before. [02:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=136s) **Presenter:** But it needs to be done in a secure way, [02:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=139s) **Presenter:** and that's why we are giving this information from the attacker's perspective. [02:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=145s) **Presenter:** So here's what we're going to start with. The idea is we want to create a malware operation. So from the time that you were able to get initial access to some machine to when you have a full blown malware operation operating and working and you can send commands, they come back to you. There's a whole bunch of work you need to do. Let's just figure out what exactly do I mean by malware operation. ### RPA Fundamentals and Threat Landscape [02:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=173s) **Presenter:** So let's say that you got initial access to some victim machine [02:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=178s) **Presenter:** That's really cool, that's the first part [03:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=180s) **Presenter:** But now there's a whole bunch of ops that you need to do [03:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=184s) **Presenter:** In order to actually take advantage of it [03:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=188s) **Presenter:** So this is kind of the real world [03:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=192s) **Presenter:** Where it's fine that you have initial access [03:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=194s) **Presenter:** But there's a lot of things that you need to deal with [03:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=196s) **Presenter:** So you need to be able to actually run something on that machine [03:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=201s) **Presenter:** You need to be able to communicate with the command and control, perhaps through a firewall. [03:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=207s) **Presenter:** You need to be able to exfiltrate data back, again, through a firewall. [03:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=211s) **Presenter:** You need to be able to avoid detection, either by EDR or by network tools [03:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=216s) **Presenter:** or any other thing that security teams are putting forth to block you there. [03:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=221s) **Presenter:** And you also need to remain persistent, because you want to stay where you initially got access to. [03:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=226s) **Presenter:** So all of those things that are not hacking, they're actually grant work. [03:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=232s) **Presenter:** That's a bunch of operations, a bunch of things that you need to do after the initial access [03:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=237s) **Presenter:** that are kind of about engineering and creating this architecture where everything is covered up. [04:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=244s) **Presenter:** The idea behind this talk is to try and find someone else that will solve these things for us, [04:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=253s) **Presenter:** that will solve all of these operation things for us. [04:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=258s) **Presenter:** And in order to do that, let me introduce kind of a service [04:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=264s) **Presenter:** that has been available for quite some time out there, RPA. [04:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=270s) **Presenter:** So I'm not sure if you've heard about this, [04:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=272s) **Presenter:** but RPA is a new product category, relatively new, a few years. [04:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=276s) **Presenter:** And the main value proposition is for users to automate mundane tasks. [04:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=281s) **Presenter:** So this is basically copy and paste integration, processing receipts, onboarding and offboarding users. [04:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=287s) **Presenter:** Basically, there are three components to this technology. [04:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=291s) **Presenter:** One is an agent that sits on people's laptops and it's actually using the, basically emulating a user. [04:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=299s) **Presenter:** So performing keyboard operations or mouse operations. [05:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=304s) **Presenter:** So that's one thing. [05:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=305s) **Presenter:** The second piece is the controller. [05:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=307s) **Presenter:** this is something that is actually able to reach out to the machine, to the user machine, [05:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=313s) **Presenter:** and the agent within it, send out a command to be executed, [05:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=317s) **Presenter:** and then after the command is executed, I get the results back. [05:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=321s) **Presenter:** And of course, there's a management portal that allows you to do this at scale [05:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=324s) **Presenter:** across multiple different machines. [05:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=328s) **Presenter:** Now, the crucial piece about this technology is that every one of these points, [05:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=334s) **Presenter:** points, every one of these services are trusted. [05:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=339s) **Presenter:** The executables, the agent is trusted on the user side. [05:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=343s) **Presenter:** The controller that is able to reach out through the network, send the command and get the results is trusted by network security. [05:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=351s) **Presenter:** And the cloud services are trusted as well. [05:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=354s) **Presenter:** And so this gives you kind of a feeling into what are we going to do next. [05:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=359s) **Presenter:** Now, RPA is really everywhere, specifically in the enterprise. [06:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=365s) **Presenter:** And you're seeing a bunch of different, kind of the leading RPA vendors in this slide. [06:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=371s) **Presenter:** These are technologies that are used across the enterprise, and we'll see this in a moment. [06:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=378s) **Presenter:** But you can expect these agents to be there on almost every enterprise laptop today. [06:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=385s) **Presenter:** We'll see in a moment why. [06:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=387s) **Presenter:** And so most of this [06:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=391s) **Presenter:** Let's continue on [06:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=392s) **Presenter:** And so RPA can handle everything that we just saw for us [06:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=398s) **Presenter:** So it's able to do command and control exfiltration [06:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=401s) **Presenter:** Defense evasion, persistency cleanup ### Technical Deep‑Dive: Power Automate Architecture [06:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=403s) **Presenter:** These are all things that we will show how to accomplish through RPA [06:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=407s) **Presenter:** But it will also provide a bunch of other things that we didn't ask for [06:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=411s) **Presenter:** Like that are about engineering basically [06:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=414s) **Presenter:** supporting different OSs, being able to update, handling errors. [06:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=418s) **Presenter:** And so this is really empowering for us. [07:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=422s) **Presenter:** And it's a very, for hackers, and it's a really good place to leave off the land. [07:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=429s) **Presenter:** So because there's a lot of capabilities and they're trusting. [07:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=433s) **Presenter:** So you already see where this talk is going. [07:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=436s) **Presenter:** So now when we are kind of all on board with what we're going to accomplish, [07:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=440s) **Presenter:** let's look at what we're going to do today. [07:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=444s) **Presenter:** We just talked about malware operations and what this is. [07:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=447s) **Presenter:** We're going to dive deep into what our PA is [07:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=450s) **Presenter:** to just kind of figure out that we're all on the same page [07:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=452s) **Presenter:** and that we understand what this technology does. [07:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=455s) **Presenter:** Next up, we'll do a technical deep dive. [07:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=459s) **Presenter:** How does it work? [07:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=459s) **Presenter:** How does it accomplish what it does [07:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=461s) **Presenter:** in order to be able to take advantage of it? [07:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=463s) **Presenter:** And then we'll switch gear and actually show [07:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=465s) **Presenter:** all the things that we have mentioned [07:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=467s) **Presenter:** that are kind of part of the grant work of malware operations, [07:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=470s) **Presenter:** how you can do them with our PA. [07:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=474s) **Presenter:** that does all of this for you without having to know the complexities of RPA [07:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=477s) **Presenter:** and don't worry I'm going to also send you home with a few points of things that you can do [08:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=483s) **Presenter:** to protect your organization [08:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=487s) **Presenter:** So let's start with RPA [08:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=489s) **Presenter:** In order to figure out what RPA does [08:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=492s) **Presenter:** Let me start off with a story [08:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=494s) **Presenter:** When I was a teenager me and my friends used to play in a very nerdy game called Tibia [08:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=499s) **Presenter:** Basically it's an MMORPG where you basically level up, you play with other characters [08:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=506s) **Presenter:** It's a very kind of social game [08:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=508s) **Presenter:** And we were obsessed with this game, with me and my friends [08:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=514s) **Presenter:** But actually a lot of the things that we had to do in this game, a lot of the day-to-day [08:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=521s) **Presenter:** Involved things like fishing [08:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=523s) **Presenter:** And so what do I mean by fishing? [08:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=525s) **Presenter:** Basically, you take a worm and you click on the pond and you might get a fish. [08:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=531s) **Presenter:** And this kind of leveled up your fishing skills and was important. [08:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=535s) **Presenter:** This was like 90% of my time playing the game. [08:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=538s) **Presenter:** So you click and you get fish and you click and you get fish and you click and you get fish. [09:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=543s) **Presenter:** And I mean, it's nice, but actually it's really boring. [09:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=547s) **Presenter:** Because you are basically transforming virtual worms to virtual fish. [09:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=554s) **Presenter:** this was annoying and kept me away from what I really wanted to do. [09:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=560s) **Presenter:** So I wanted to find basically an advantage, a creative solution to figure out how to do this [09:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=566s) **Presenter:** without having to invest the time. [09:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=568s) **Presenter:** I also wanted to kind of impress my friends and get an advantage over them. [09:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=572s) **Presenter:** And so I came up with this kind of creative solution. [09:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=577s) **Presenter:** And this is true, by the way. [09:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=579s) **Presenter:** I didn't find the real photo, but I used physical automation. [09:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=584s) **Presenter:** And so this is an illustration of how this looks like. [09:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=587s) **Presenter:** Basically, I would put a bunch of books over the keyboard and the mouse overnight. [09:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=592s) **Presenter:** And then I hoped that by the time morning comes, things would still stay there and I would level up. [09:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=599s) **Presenter:** This kind of worked some of the time, but most of the time things fell over. [10:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=604s) **Presenter:** Things didn't behave as I expected. [10:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=606s) **Presenter:** And of course, this was very limited in what I was able to do. [10:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=610s) **Presenter:** And so, but this did trigger my imagination into what is actually possible. [10:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=616s) **Presenter:** And so in the next iteration, I actually found a few kinds of software that were able to record my keyboard and mouse. [10:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=626s) **Presenter:** And then just reiterate those steps over time. [10:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=630s) **Presenter:** And this is kind of, this was very sophisticated for me at the time. [10:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=634s) **Presenter:** Let's see how it looks like. [10:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=636s) **Presenter:** And so you can see that now I am able to do much more than just click. [10:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=640s) **Presenter:** I can move the mouse around. [10:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=642s) **Presenter:** I can move the character around. [10:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=644s) **Presenter:** And so this was a revelation. [10:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=647s) **Presenter:** This made me basically the hero of my friends [10:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=649s) **Presenter:** because more than just being able to do this, [10:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=651s) **Presenter:** I could share it with others. [10:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=653s) **Presenter:** And so this is a nice way to kind of think about RPA. [10:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=659s) **Presenter:** RPA is a technology that has started as a way to create integrations [11:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=664s) **Presenter:** by emulating a user one-to-one. [11:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=666s) **Presenter:** This also means that you can integrate with systems ### Building a Malware Operation with RPA [11:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=670s) **Presenter:** that don't have proper APIs. [11:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=672s) **Presenter:** Think about kind of legacy software in a large enterprise. [11:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=676s) **Presenter:** And so you can just, by being able to use the computer [11:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=683s) **Presenter:** as a user would, you gain access to the same kind of things [11:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=687s) **Presenter:** that the user would be able to do. [11:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=690s) **Presenter:** And so here's a quick summary about what RPA is. [11:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=694s) **Presenter:** The idea is to replace this copy and pasting that users do manually. [11:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=700s) **Presenter:** The building of RPA tasks is very much kind of drag and drop. [11:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=706s) **Presenter:** It's supposed to be easy to do by everyone. [11:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=710s) **Presenter:** You emulate the user actions, and so the mouse and the keyboard. [11:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=714s) **Presenter:** This also means that you run the same way as the user runs, right? [11:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=719s) **Presenter:** You run as the user. [12:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=720s) **Presenter:** So there's no way, unless you're doing some behavioral analytics, to distinguish between a user and an RPA bot. [12:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=727s) **Presenter:** And again, this distinction would be very difficult because this is exactly what the RPA is doing, is emulating user activity. [12:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=734s) **Presenter:** And also, RPA runs either on user machines, so on user laptops, in order to be able to access the same kind of information that they're accessing, or on dedicated servers. [12:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=745s) **Presenter:** And this is actually being used for really heavy lifting within the enterprise. [12:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=750s) **Presenter:** use cases, for example automating off-boarding and onboarding employees, [12:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=755s) **Presenter:** submitting financial reports. So there are a bunch of things that enterprises are [12:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=760s) **Presenter:** doing with RPA that are really creating a lot of value. [12:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=769s) **Presenter:** So now that we understand why RPA exists and why is it used in the enterprise, why [12:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=775s) **Presenter:** today in almost every enterprise you'll find RPA there. Let's kind of dive [13:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=780s) **Presenter:** deep a bit, dive a bit deeper and figure out how it works. So that's [13:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=789s) **Presenter:** what we're going to do right now and the rest of this talk from this moment [13:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=792s) **Presenter:** forward is going to be focused on Microsoft's RPA, it's called Power [13:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=796s) **Presenter:** Automate and all of the things that I'm going to show you are very [13:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=802s) **Presenter:** similar across different RPA vendors. [13:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=804s) **Presenter:** It's not really just a Microsoft problem. [13:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=806s) **Presenter:** It's inherent in RPA. [13:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=809s) **Presenter:** But the reason why we focus on Microsoft [13:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=812s) **Presenter:** is because Microsoft's RPA agent [13:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=815s) **Presenter:** comes built in in Windows 11. [13:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=818s) **Presenter:** And so if you open up a Windows 11 machine, [13:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=821s) **Presenter:** a vanilla Windows 11 machine today, [13:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=824s) **Presenter:** a laptop, a server, [13:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=825s) **Presenter:** you'll find Power Automate already there. [13:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=828s) **Presenter:** And that's why it's important [13:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=829s) **Presenter:** because it's kind of available for us to use. [13:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=833s) **Presenter:** Let me show you how this looks like [13:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=835s) **Presenter:** from a user's perspective. [13:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=838s) **Presenter:** And so when you kick off a new vanilla machine, [14:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=842s) **Presenter:** Windows 11, [14:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=843s) **Presenter:** just search for Power Automate. [14:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=845s) **Presenter:** You already find this agent within your machine. [14:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=851s) **Presenter:** Let's see if this works. [14:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=856s) **Presenter:** So I'm going to show you how, [14:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=859s) **Presenter:** when I execute this agent for the first time. [14:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=867s) **Presenter:** Okay, so I'm going to Power Automate. [14:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=870s) **Presenter:** First of all, it's going to ask me for an email address. [14:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=873s) **Presenter:** This is a Microsoft address. [14:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=875s) **Presenter:** And keep in mind, I could plug in any address here. [14:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=878s) **Presenter:** That's important to note here. [14:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=880s) **Presenter:** Once I do that, it connects to Office, [14:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=882s) **Presenter:** and then you can see a whole bunch of information being populated. [14:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=885s) **Presenter:** We'll jump back to it in a moment. [14:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=886s) **Presenter:** I'm going to create a Hello World application and now you're seeing the actual [14:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=892s) **Presenter:** The builder the drag-and-drop interface that allows you to to create our PA bots [14:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=897s) **Presenter:** I'm going to choose the write to file action and just pick the file that I would like to write on and you will see that very [15:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=903s) **Presenter:** Quickly I set up a flow which kind of appends a line into into this file. I click on run it runs and [15:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=911s) **Presenter:** Everything gets executed really easily and the file gets created [15:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=916s) **Presenter:** So you can see that this is pretty easy and that there are a whole bunch of applications I can use. [15:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=921s) **Presenter:** You can also see that there are other tasks that are already available because of the integration with Office. [15:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=927s) **Presenter:** And as you can see, there's a little trigger there that the thing actually worked. [15:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=933s) **Presenter:** And so you notice, and I kind of stressed it a few times, that first of all, when you connected, you had to use some sort of an address. [15:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=946s) **Presenter:** Then afterwards, you got a whole bunch of automations [15:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=950s) **Presenter:** that were already available there. [15:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=951s) **Presenter:** So let's figure out what's going on there. [15:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=955s) **Presenter:** This is actually what we saw, right? [15:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=957s) **Presenter:** So once we plugged into, we added our address [16:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=962s) **Presenter:** or logged in to Power Automate, [16:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=965s) **Presenter:** you saw all of these different automations ### Command & Control, Exfiltration, and Persistence [16:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=967s) **Presenter:** that were already available, and those are my automations. [16:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=971s) **Presenter:** So I created them in advance, but not on the machine. [16:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=974s) **Presenter:** I created them on the office side. [16:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=976s) **Presenter:** see that on the environment widget there, [16:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=981s) **Presenter:** basically, Power Automate is connected to Office, [16:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=984s) **Presenter:** and it drives all of its automation through Office, [16:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=986s) **Presenter:** and that's why you're actually seeing this. [16:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=988s) **Presenter:** So this is synced with the cloud. [16:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=990s) **Presenter:** And so, one thing that you should be asking yourself [16:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=995s) **Presenter:** is how is this possible? [16:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=997s) **Presenter:** So if, let's say that Microsoft is, [16:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1001s) **Presenter:** so we understand that Microsoft is putting this in, [16:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1003s) **Presenter:** by default, this agent, in every Windows 11 installation. [16:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1009s) **Presenter:** And this is connected to Office. [16:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1010s) **Presenter:** But it's not like they asked some network admin in the middle [16:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1013s) **Presenter:** to open up the firewall, right? [16:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1015s) **Presenter:** This is something that needs to work properly. [16:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1019s) **Presenter:** So let's figure out how everything works here. [17:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1024s) **Presenter:** So on one side, we have Power Automate. [17:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1027s) **Presenter:** It runs probably on-prem, but on somebody's machine. [17:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1030s) **Presenter:** On the other side, we have the Office Cloud Services. [17:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1033s) **Presenter:** about the communication, let's just figure out what's actually happening on the user side, on the [17:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1039s) **Presenter:** laptop side. So Power Automate is actually more than just one executable. There's a whole bunch [17:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1045s) **Presenter:** of executables that are available within the Power Automate framework inside Windows 11. [17:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1052s) **Presenter:** The two important ones that I'm showing you right now is the Power Automate executable that [17:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1059s) **Presenter:** It actually runs the command and it runs as the user [17:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1062s) **Presenter:** in the user context. [17:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1064s) **Presenter:** So the same kind of permissions, everything like the user. [17:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1068s) **Presenter:** And the other side is the machine runtime. [17:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1070s) **Presenter:** It runs on a service account created in your machine [17:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1074s) **Presenter:** by Microsoft, again, every Windows 11 machine, [17:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1077s) **Presenter:** and it runs in parallel to the user. [17:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1079s) **Presenter:** And this is going to be the piece [18:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1081s) **Presenter:** that actually connects to Office. [18:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1082s) **Presenter:** We'll see that in a moment. [18:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1084s) **Presenter:** Power Automate is also able to automate a browser. [18:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1089s) **Presenter:** through a whole bunch of browser plugins, [18:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1093s) **Presenter:** and those are available for browser extensions, [18:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1095s) **Presenter:** and those are available to every major browser. [18:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1098s) **Presenter:** So there are dedicated executables that actually handle this, [18:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1103s) **Presenter:** and so I added them to the picture here as well. [18:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1106s) **Presenter:** And just kind of so you know, [18:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1108s) **Presenter:** the only thing that I just showed you right now are these three executables, [18:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1112s) **Presenter:** but actually, as you can see, [18:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1114s) **Presenter:** there are a whole bunch of executables that are available [18:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1116s) **Presenter:** as part of the Power Automate directory, [18:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1119s) **Presenter:** If you're looking for a nice place for research and to dive deep, I really recommend this. [18:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1125s) **Presenter:** There's a whole bunch of work that could be done here. [18:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1128s) **Presenter:** And the one thing that is important is that all of these things, as you can see, it's part of the kind of, it's already there in program files. [18:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1137s) **Presenter:** It's also supported by the EDR, trusted by the EDR. [19:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1142s) **Presenter:** And so because this is part of Windows 11, Microsoft CDR and others as well are trusting these executables to be okay, to be something that Microsoft has put forth. [19:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1154s) **Presenter:** So now that we understand what's happening on the user side, let's try and understand the network. [19:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1161s) **Presenter:** So how does this communication actually happen? [19:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1163s) **Presenter:** happens. Microsoft did not go out to each network security team and ask them to open up the firewall [19:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1170s) **Presenter:** so every user to be able to directly connect to Office. What exactly is going on here? [19:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1176s) **Presenter:** The way that this is accomplished is with a cool solution called Azure Service Bus. It used to be [19:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1182s) **Presenter:** called Azure Relay. Basically, there's outbound communication going from both sides, from Office [19:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1186s) **Presenter:** and from the machine runtime, which is actually the user's laptop. And there's basically a message [19:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1193s) **Presenter:** with commands that the agent should be executing. [19:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1197s) **Presenter:** And so the agent would go out to this queue [20:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1201s) **Presenter:** once in a while, fetch new commands, [20:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1204s) **Presenter:** and every time there's a result, [20:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1206s) **Presenter:** it would just save it on that queue again. [20:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1209s) **Presenter:** So that's the way that the communication [20:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1210s) **Presenter:** is being established. [20:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1213s) **Presenter:** And so now that we're connected [20:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1215s) **Presenter:** between the agent and the cloud, [20:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1219s) **Presenter:** let's try and figure out how does it look like [20:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1221s) **Presenter:** from the office side. [20:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1223s) **Presenter:** there. So there's a very nice ### Defense, Detection, and Mitigation Strategies — Part 1 [20:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1226s) **Presenter:** layer in Office that allows you to [20:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1228s) **Presenter:** look at these agents, understand [20:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1230s) **Presenter:** what they're doing. You can see all of the machines [20:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1232s) **Presenter:** that I have registered into my [20:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1234s) **Presenter:** malicious tenant. [20:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1235s) **Presenter:** You can see the version of the agent being installed, [20:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1238s) **Presenter:** whether it's working or not. So essentially [20:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1240s) **Presenter:** this is a management [20:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1242s) **Presenter:** portal that allows you to view all of [20:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1244s) **Presenter:** these agents. You can also [20:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1245s) **Presenter:** run commands directly from the cloud. [20:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1248s) **Presenter:** So in the same way that you saw me [20:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1250s) **Presenter:** a moment ago create an automation [20:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1253s) **Presenter:** created somewhere else and then move it to the cloud and trigger it on some other user's machine. [21:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1261s) **Presenter:** You can also view the status of tasks. So you can debug failures, you can check out when things [21:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1270s) **Presenter:** happened last, you can rerun things. So everything that you need in order to actually manage things, [21:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1276s) **Presenter:** manage these agents at scale, is available through Microsoft Cloud. [21:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1281s) **Presenter:** One thing that I still want to touch on [21:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1284s) **Presenter:** Is the trust component here [21:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1286s) **Presenter:** How is trust being established [21:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1288s) **Presenter:** Between office and the users [21:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1291s) **Presenter:** And the user agent [21:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1294s) **Presenter:** Without kind of [21:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1297s) **Presenter:** Other than the authentication [21:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1299s) **Presenter:** So the messages that are put on these [21:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1302s) **Presenter:** So once the registration part happens [21:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1307s) **Presenter:** And you saw me do this a moment ago [21:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1310s) **Presenter:** key being created on the machine side and the public key is being sent through that mechanism [21:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1315s) **Presenter:** to office. And then with this private public key, the Azure service bus, the messages can [22:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1324s) **Presenter:** contain, can be signed. And when they're signed, keep in mind that they have two things. One [22:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1330s) **Presenter:** is the RPA task, which is actually kind of what needs to be done, but they also have [22:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1337s) **Presenter:** local credentials and this is important. This means that the machine runtime agent can run [22:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1343s) **Presenter:** things on behalf of the user that already exists in that machine but [22:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1351s) **Presenter:** it can also run tasks as any other user and so this is how this process is [22:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1358s) **Presenter:** being done in a secure way. And so in a nutshell users can build customer [22:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1367s) **Presenter:** Microsoft. Microsoft then ensures [22:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1369s) **Presenter:** that these processes are distributed [22:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1371s) **Presenter:** across all of the different machines [22:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1373s) **Presenter:** that are registered to [22:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1375s) **Presenter:** your tenant, executed successfully [22:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1377s) **Presenter:** and then report back to the [22:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1379s) **Presenter:** cloud. And so I think you can [23:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1381s) **Presenter:** realize what I'm about to do next [23:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1383s) **Presenter:** so let's just do it. [23:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1385s) **Presenter:** The next part would be [23:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1387s) **Presenter:** how do you take everything that we have learned [23:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1389s) **Presenter:** so far and build a malware [23:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1391s) **Presenter:** operation out of it. [23:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1394s) **Presenter:** And so [23:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1395s) **Presenter:** Let's recall our wish list. These are the things that we wanted to do and we're going to go one by one [23:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1401s) **Presenter:** And achieve each and every one of them with Power Automate. [23:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1405s) **Presenter:** And so let's start. The first thing we need to do is to set up that malicious tenant. We need to set up [23:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1412s) **Presenter:** an office deployment [23:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1414s) **Presenter:** That would be the one we are using to manage all of those agents. And so you can see that very easily here [23:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1420s) **Presenter:** I created a tenant, this is free, you don't need a license, you don't need to provide [23:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1424s) **Presenter:** a credit card, so this is kind of very easy. [23:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1428s) **Presenter:** And once you create a tenant, when you go to the Power Automate interface, you'll see [23:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1434s) **Presenter:** that it points you to install new machines, or basically to onboard new machines in your [23:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1438s) **Presenter:** tenant. [23:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1439s) **Presenter:** So, how exactly is it happening? [24:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1446s) **Presenter:** We actually saw this earlier [24:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1447s) **Presenter:** So there was a quick UI there [24:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1450s) **Presenter:** You sign in and you can add in your own email [24:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1453s) **Presenter:** And remember I alluded to the fact that you can run [24:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1457s) **Presenter:** You can plug in any account here [24:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1459s) **Presenter:** This is exactly the point [24:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1460s) **Presenter:** You can see that I'm inserting an account [24:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1462s) **Presenter:** That is part of my malicious office deployment [24:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1468s) **Presenter:** But of course, doing this with UI is kind of fishy. We don't really need to do that once we have initial access to somebody's machine. We want to hide. [24:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1480s) **Presenter:** And so fortunately for us, Microsoft provides a nice script, silently register a new machine, that allows you through PowerShell or through command line to register a machine to your own tenant. [24:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1495s) **Presenter:** And by the way, even if the machine is already registered to somebody else's tenant, to the actual organization tenant, it doesn't matter. [25:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1502s) **Presenter:** It can be registered to two tenants in the same time and nobody else, and those won't know about each other. [25:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1509s) **Presenter:** And so this is really cool. [25:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1512s) **Presenter:** It kind of solves our problem, right? [25:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1514s) **Presenter:** Once you do that, you will be able to see the Windows, the machine that you've just registered in the Power Automate Management interface. [25:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1525s) **Presenter:** And so this is the way that we onboard new users, i.e. this is the way that we infect a new machine. [25:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1531s) **Presenter:** One thing that you might have noticed there is that this script needs to be run as an administrator, [25:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1540s) **Presenter:** which of course is not that great, right? [25:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1544s) **Presenter:** As a hacker, this is very limiting. [25:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1546s) **Presenter:** And so we try to poke around and see whether we can get it to run as a user and not just as an administrator. [25:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1555s) **Presenter:** And actually it just worked. [25:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1557s) **Presenter:** So we just tried and it worked. [25:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1559s) **Presenter:** And so you can also run this executable as a user. [26:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1565s) **Presenter:** It will register your, [26:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1567s) **Presenter:** and it will still register the machine [26:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1569s) **Presenter:** to the malicious tenant. [26:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1572s) **Presenter:** And so we have, so once we have that, [26:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1576s) **Presenter:** the machine is registered to my malicious organization. [26:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1580s) **Presenter:** And now in order to actually run something [26:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1582s) **Presenter:** on that organization, on that infected machine, [26:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1586s) **Presenter:** here's what I have to do. [26:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1587s) **Presenter:** So I trigger something from the cloud. [26:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1590s) **Presenter:** I create this automation from the cloud [26:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1593s) **Presenter:** that chooses a specific desktop flow [26:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1596s) **Presenter:** that's the name of the payload that I would like to run. [26:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1599s) **Presenter:** It asks me for the credentials, as we've mentioned earlier, [26:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1604s) **Presenter:** the local credentials, which, again, we assume you already have [26:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1607s) **Presenter:** because you have the initial access. [26:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1608s) **Presenter:** And then it distributes the payload [26:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1611s) **Presenter:** Then you basically choose the payload [26:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1613s) **Presenter:** And it will distribute it to the machine [26:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1616s) **Presenter:** And of course you can run this on one machine [26:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1619s) **Presenter:** Or you can run this on many machines [27:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1620s) **Presenter:** One thing that is important to question here [27:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1624s) **Presenter:** Is what about this user, Alex G [27:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1627s) **Presenter:** What happens if they're already logged into their machine? [27:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1630s) **Presenter:** What happens if they're actually using it right now? [27:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1632s) **Presenter:** So how would it look like from the user's machine? [27:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1635s) **Presenter:** From the user's side? [27:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1638s) **Presenter:** RPA has already taken care of this [27:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1640s) **Presenter:** or Microsoft has already taken care of this [27:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1642s) **Presenter:** so there are two versions of RPA [27:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1644s) **Presenter:** attended and unattended ### Defense, Detection, and Mitigation Strategies — Part 2 [27:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1645s) **Presenter:** basically if the [27:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1647s) **Presenter:** attended means that [27:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1649s) **Presenter:** if the user already has a session [27:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1652s) **Presenter:** ongoing within the local machine [27:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1654s) **Presenter:** you just join that session and you run [27:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1656s) **Presenter:** with the user on the same session [27:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1658s) **Presenter:** of course it means that you can steal secrets [27:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1660s) **Presenter:** you can do everything that the user does [27:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1662s) **Presenter:** and the other part is [27:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1664s) **Presenter:** the other option is unattended RPA [27:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1666s) **Presenter:** this creates a new session [27:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1668s) **Presenter:** discards of it when it's done. [27:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1670s) **Presenter:** And so we can do both of these things. [27:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1673s) **Presenter:** And so you can see that RPA has already taken care [27:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1676s) **Presenter:** of many edge cases for us. [27:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1679s) **Presenter:** And even more than that, [28:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1681s) **Presenter:** we have already showed you three things [28:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1683s) **Presenter:** that we wanted to do. [28:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1684s) **Presenter:** So deploying malware, [28:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1686s) **Presenter:** that's just running the script, the Microsoft script. [28:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1688s) **Presenter:** Defense of Asian, well, this is obvious. [28:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1690s) **Presenter:** All of these services, the executables, [28:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1693s) **Presenter:** the cloud services, they are all trusted. [28:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1696s) **Presenter:** They are trusted by Microsoft, [28:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1698s) **Presenter:** by other security vendors, [28:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1700s) **Presenter:** and so the phase evasion is already there. [28:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1702s) **Presenter:** And with persistency, keep in mind, [28:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1704s) **Presenter:** we haven't installed anything new on the machine. [28:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1706s) **Presenter:** This was already there. [28:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1708s) **Presenter:** And so you can always just run the command back [28:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1711s) **Presenter:** from the cloud and run things on the machine, [28:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1714s) **Presenter:** even if somebody tries to kind of, [28:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1718s) **Presenter:** because there's nothing really to remove. [28:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1721s) **Presenter:** So next up, we are going to see command and control. [28:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1726s) **Presenter:** We did see a couple of these of payloads that we sent forth [28:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1730s) **Presenter:** But let's kind of figure out what kind of payloads we can send and how can we make it kind of generic [28:57](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1737s) **Presenter:** So now we're going to see once we already have a machine infected [29:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1742s) **Presenter:** We can already send commands out [29:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1744s) **Presenter:** Let's see what actually we can do [29:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1747s) **Presenter:** So here's just a simple example, data exfiltration [29:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1751s) **Presenter:** So this is a simple automation [29:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1753s) **Presenter:** I'm giving this automation as inputs the target file [29:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1758s) **Presenter:** Some file, some local file I'd like to exfiltrate [29:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1761s) **Presenter:** And then I'm getting back the content of that file [29:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1764s) **Presenter:** And you can see that there's also an error handling here [29:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1766s) **Presenter:** But that's kind of very, very simple [29:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1769s) **Presenter:** Let's just make sure we understand how this works [29:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1772s) **Presenter:** First of all, from the cloud side [29:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1773s) **Presenter:** You can see that I can run this automation [29:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1776s) **Presenter:** I give the input a target file [29:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1779s) **Presenter:** And then I just get it back [29:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1781s) **Presenter:** Let's make sure we understand [29:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1784s) **Presenter:** How exactly does this data exfiltration work [29:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1786s) **Presenter:** To make sure that we won't get caught [29:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1788s) **Presenter:** And so if you recall [29:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1790s) **Presenter:** The architecture [29:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1792s) **Presenter:** Let's [29:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1794s) **Presenter:** Figure out what's happening over this architecture [29:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1796s) **Presenter:** So creating those instructions [29:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1798s) **Presenter:** Basically creating [30:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1800s) **Presenter:** The payload happens [30:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1802s) **Presenter:** With us [30:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1804s) **Presenter:** Directly with office [30:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1805s) **Presenter:** And so we reach out to office [30:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1806s) **Presenter:** We give out this payload [30:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1808s) **Presenter:** And then we give out the command [30:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1811s) **Presenter:** to a specific machine. [30:12](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1812s) **Presenter:** That command goes through the Azure service box, [30:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1815s) **Presenter:** the Azure service bus, this channel of communication [30:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1819s) **Presenter:** between the user machine and office. [30:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1821s) **Presenter:** And it's been executed, it reaches the machine runtime, [30:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1826s) **Presenter:** which will execute it with one of the Power Automate agents [30:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1828s) **Presenter:** depending on the user. [30:30](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1830s) **Presenter:** Once the information has been collected, [30:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1833s) **Presenter:** it will be written again on the secure communication [30:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1836s) **Presenter:** between Azure service bus. [30:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1838s) **Presenter:** And so you can see that from the enterprise perspective, [30:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1841s) **Presenter:** perspective you really cannot catch this because it's going to Microsoft [30:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1846s) **Presenter:** trusted services. And so what so we I just showed you data exfiltration but [30:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1854s) **Presenter:** actually we want more than that we want to be able to run every command that [30:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1858s) **Presenter:** we would want on the user's machine. Let's see how to do that. So here's the [31:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1864s) **Presenter:** first version of code execution basically there are there's a bunch of [31:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1871s) **Presenter:** utilities within Power Automate that allow you to basically run a command on the machine. So you can see that I'm [31:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1877s) **Presenter:** getting as input a command and I can run it as PowerShell, as Python, as JavaScript, so there are a bunch of options. [31:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1884s) **Presenter:** And so using this I can send any payload that I lack into the machine. [31:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1889s) **Presenter:** The problem is that once I execute this [31:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1893s) **Presenter:** I get caught by the EDR. And why? Well, because I just run a [31:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1899s) **Presenter:** a malicious payload in this example, [31:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1902s) **Presenter:** trying to use Mimikatz. [31:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1904s) **Presenter:** And of course, this can be called by the EDR. [31:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1908s) **Presenter:** I mean, EDRs are monitoring this. [31:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1911s) **Presenter:** Essentially, there are two parts here. [31:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1913s) **Presenter:** So the part that is trusted is this drag and drop interface. [31:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1918s) **Presenter:** What the agent, the ARP agent is actually doing. [32:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1921s) **Presenter:** But once you go to other processes, [32:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1923s) **Presenter:** once you spawn a command prompt, [32:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1925s) **Presenter:** Well, of course, this is something that EDRs are especially worried about, so it makes sense that we get caught. [32:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1934s) **Presenter:** So the question then becomes, what can we do if we stay in this trusted zone? [32:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1942s) **Presenter:** Can we take better advantage of the trusted zone to actually execute what we wanted to execute? [32:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1948s) **Presenter:** Because the trusted zone, what we already have there, does have some logic, right? [32:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1953s) **Presenter:** It needs to choose the right kind of interpreter or compiler [32:38](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1958s) **Presenter:** Or something that we're using to actually run the code [32:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1962s) **Presenter:** And so what can we do to take more advantage of this? [32:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1968s) **Presenter:** And so let's see how it works [32:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1972s) **Presenter:** When we run this [32:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1976s) **Presenter:** When we created this payload [32:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1978s) **Presenter:** You can see that there are a whole bunch of commands [33:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1980s) **Presenter:** Of operations that we used [33:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1983s) **Presenter:** in order to create it. [33:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1985s) **Presenter:** And so the question becomes, what payloads are available? [33:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1989s) **Presenter:** What can we do with them? [33:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1991s) **Presenter:** So this is just a little snapshot of things [33:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1995s) **Presenter:** that are available within, [33:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=1998s) **Presenter:** kind of as ready-made operations. [33:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2000s) **Presenter:** So you can use crypto to encrypt files [33:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2004s) **Presenter:** or to encrypt content. [33:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2009s) **Presenter:** You can trigger HTTP calls, [33:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2011s) **Presenter:** You can communicate with AD, with Windows services, with other processes. [33:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2014s) **Presenter:** You can look at files and folders. [33:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2016s) **Presenter:** You can automate a browser, which we'll see in a moment. [33:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2019s) **Presenter:** You can take screenshots. [33:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2020s) **Presenter:** You can use the mouse and the keyboard and record them. [33:43](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2023s) **Presenter:** So key logging is easy. [33:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2025s) **Presenter:** You can copy the clipboard or change the clipboard. [33:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2028s) **Presenter:** And so I'm sure your mind is racing right now with the kinds of things that you are able to do. [33:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2033s) **Presenter:** Basically, these are all of the primitives that you need to accomplish most of the things that an attacker would like to do. [33:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2038s) **Presenter:** And so let's see a few of those in action. [34:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2041s) **Presenter:** So let's start with a simple example. [34:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2045s) **Presenter:** NoCodeRansomware. [34:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2046s) **Presenter:** So here's this example. [34:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2048s) **Presenter:** I'm basically focused on a specific directory. [34:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2053s) **Presenter:** I'm going to crawl the directory and the subdirectories. [34:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2055s) **Presenter:** And then I'm going to replace each file with an encrypted file. [34:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2059s) **Presenter:** You can see the automation here is, again, pretty simple. ### Defense, Detection, and Mitigation Strategies — Part 3 [34:23](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2063s) **Presenter:** There's a bit of error handling and a bunch of for loops. [34:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2065s) **Presenter:** but basically I just go deeper and deeper [34:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2069s) **Presenter:** into the directory hierarchy [34:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2071s) **Presenter:** and encrypt each one of the files. [34:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2073s) **Presenter:** Let's see a quick demo. [34:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2079s) **Presenter:** So this is the cloud side. [34:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2081s) **Presenter:** I'm providing the encryption key, the directory, [34:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2084s) **Presenter:** and how deep do I want this to actually go. [34:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2088s) **Presenter:** So deep within the directory structure. [34:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2091s) **Presenter:** The flow is running. [34:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2093s) **Presenter:** The command is right now being sent [34:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2095s) **Presenter:** that is going to run this on the infected machine. [34:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2098s) **Presenter:** And you can see that it's already run [35:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2100s) **Presenter:** and it's giving me information about the actual execution. [35:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2104s) **Presenter:** On the machine side, you can see [35:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2107s) **Presenter:** so you can see that the files are actually encrypted. [35:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2111s) **Presenter:** So this is, as you can see, very easy to actually accomplish. [35:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2119s) **Presenter:** Okay. [35:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2120s) **Presenter:** One thing that we haven't discussed so far [35:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2125s) **Presenter:** is the fact that there are a bunch of logs [35:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2127s) **Presenter:** that this agent on the local side is generating. [35:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2131s) **Presenter:** So the agent, the local RPA agent, [35:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2134s) **Presenter:** is generating a bunch of information about what it's doing. [35:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2137s) **Presenter:** Of course, we would like to clean those up. [35:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2139s) **Presenter:** And it's kind of easy because it's very, [35:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2142s) **Presenter:** because we already know where this agent [35:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2144s) **Presenter:** is actually storing information. [35:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2146s) **Presenter:** And so this automation simply cleans up after ourselves. [35:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2151s) **Presenter:** So we just go to every location [35:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2152s) **Presenter:** where we know that the agent is storing information, [35:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2156s) **Presenter:** permanently deleting those files. [35:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2158s) **Presenter:** So we saw data exfiltration, [36:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2161s) **Presenter:** we saw ransomware, [36:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2162s) **Presenter:** and we saw cleanup. [36:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2164s) **Presenter:** One thing that I kind of hinted on earlier [36:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2168s) **Presenter:** is that RPA or Power Automate [36:11](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2171s) **Presenter:** is also able to automate the browser. [36:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2175s) **Presenter:** And so by automating the browser, [36:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2177s) **Presenter:** of course we can jump, [36:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2178s) **Presenter:** we can continue on our attack to other locations. [36:21](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2181s) **Presenter:** So let's see how it looks like. [36:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2185s) **Presenter:** is very easy, we'd like to basically steal tokens [36:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2189s) **Presenter:** for authenticated tokens, [36:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2192s) **Presenter:** because we're running as the user from the browser. [36:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2194s) **Presenter:** So here's the idea, we open the browser [36:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2197s) **Presenter:** kind of in a way that the user won't notice, [36:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2199s) **Presenter:** we go to a specific location, in this case, [36:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2202s) **Presenter:** we're going to flow.microsoft.com [36:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2204s) **Presenter:** to steal a Microsoft token for that user, [36:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2206s) **Presenter:** and then we simply extract the token. [36:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2209s) **Presenter:** And so let's see this in action. [36:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2211s) **Presenter:** Here's the automation, so I'm going to launch a new browser, [36:55](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2215s) **Presenter:** send out a few keystrokes to make sure that we get to the right page and that we can kind of [37:02](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2222s) **Presenter:** fetch its content. And then I'm just going to parse the results and fetch the authentication [37:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2227s) **Presenter:** token out of it. And in this case, you're seeing Chrome app opens up on a Microsoft website [37:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2234s) **Presenter:** and the token gets exfetrated back as an output variable. Now, of course, we don't want the [37:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2240s) **Presenter:** browser to pop up in such a way. Remember, we're running as a user in the user session to steal [37:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2246s) **Presenter:** So there's a very easy parameter we can change here [37:29](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2249s) **Presenter:** to have the browser opened in a minimized version [37:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2252s) **Presenter:** so the user won't notice. [37:34](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2254s) **Presenter:** Let's see how it happens from the cloud side. [37:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2257s) **Presenter:** And so from the cloud side, we create a new request [37:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2260s) **Presenter:** that basically sends this payload to the infected machine. [37:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2264s) **Presenter:** Again, you saw this earlier. [37:45](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2265s) **Presenter:** So the payload is being sent through the trusted channel, [37:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2268s) **Presenter:** reaches the agent, the agent's verified [37:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2270s) **Presenter:** that it actually runs successfully. [37:52](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2272s) **Presenter:** and from the infected user side, nothing happens. [37:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2278s) **Presenter:** Because, well, we created this in a way [38:00](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2280s) **Presenter:** that it won't actually do anything on the user side. [38:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2283s) **Presenter:** And so you can see that this is very powerful. [38:08](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2288s) **Presenter:** So there are a whole bunch of things [38:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2290s) **Presenter:** that we can actually do in order to, [38:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2293s) **Presenter:** basically everything that you would have wanted to do [38:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2295s) **Presenter:** with data, as an attacker, [38:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2299s) **Presenter:** you can actually do with no code primitives. [38:22](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2302s) **Presenter:** And so we saw command and control, data exfiltration, cleanup, [38:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2305s) **Presenter:** we saw harvesting credentials through browsers, [38:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2308s) **Presenter:** but there are actually a bunch of other ideas we didn't have time to implement, [38:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2312s) **Presenter:** like creating a keylogger or any other thing. [38:35](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2315s) **Presenter:** So please feel free to kind of play around with it on your own. [38:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2320s) **Presenter:** And in order to make it easier for you to play around with it on your own, [38:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2324s) **Presenter:** let me introduce PowerPoint. [38:47](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2327s) **Presenter:** So PowerPoint is a tool that abstracts away all of the complexities that I've just described [38:54](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2334s) **Presenter:** of how do you affect these machines, how do you send the information out there, how do [38:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2338s) **Presenter:** you set up that office account, so you can use all of these tools as part of your Red [39:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2343s) **Presenter:** Team arsenal. [39:05](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2345s) **Presenter:** PowerPoint also handles a bunch of things for you, so we handle errors for you, we also [39:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2350s) **Presenter:** allow you to create, to run all of these payloads through an HTTP trigger, an HTTP webhook, [39:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2357s) **Presenter:** so an HTTP endpoint, rather than being the need to actually go and log into office. [39:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2365s) **Presenter:** So here's how it looks like. [39:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2367s) **Presenter:** Basically, you post to the HTTP endpoint that is created for you. [39:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2372s) **Presenter:** You choose the infected machine and the user you want to run as. [39:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2380s) **Presenter:** the actual payload that you'd like to run [39:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2381s) **Presenter:** and the parameters, and you'll just get back [39:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2384s) **Presenter:** all of the output as a, [39:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2386s) **Presenter:** all of the results of that payload as output, [39:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2389s) **Presenter:** as the return side of the request. [39:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2393s) **Presenter:** There's also a convenience layer in Python [39:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2396s) **Presenter:** that you can use to make your life even easier, [39:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2398s) **Presenter:** so you can execute commands, [40:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2403s) **Presenter:** and run all of the payloads that you saw here today, [40:06](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2406s) **Presenter:** and actually others as well. [40:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2407s) **Presenter:** We're fortunate enough that there's a kind of a small community that has started to be built around PowerPoint. [40:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2413s) **Presenter:** So check it out. [40:15](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2415s) **Presenter:** You'll also find all of the instructions of how to set it up on your tenant. [40:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2419s) **Presenter:** And of course, the idea here is to use this tool basically to, first of all, to learn yourself about the space. [40:27](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2427s) **Presenter:** After that, to kind of teach others and gain the attention of management. [40:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2431s) **Presenter:** And of course, to build defenses around these capabilities. [40:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2437s) **Presenter:** to what we did today. [40:40](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2440s) **Presenter:** We saw what RPA is. [40:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2442s) **Presenter:** We saw that RPA is available in every organization, [40:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2444s) **Presenter:** and we did a very technical deep dive [40:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2446s) **Presenter:** to figure out how exactly does it work [40:49](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2449s) **Presenter:** and accomplish what it needs to do. [40:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2451s) **Presenter:** And the important thing here is [40:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2453s) **Presenter:** it doesn't require the acceptance of management, [40:58](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2458s) **Presenter:** or it can just be plugged in there [41:01](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2461s) **Presenter:** by the vendors themselves. [41:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2463s) **Presenter:** We saw that you can use RPA [41:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2467s) **Presenter:** to remote code execution as a service [41:10](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2470s) **Presenter:** to take care of all of the grant work for you. [41:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2473s) **Presenter:** You can distribute payloads, execute them, [41:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2476s) **Presenter:** make sure they run successfully, [41:18](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2478s) **Presenter:** and everything works through trusted services, ### Defense, Detection, and Mitigation Strategies — Part 4 [41:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2480s) **Presenter:** trusted executables, we haven't installed anything new, [41:24](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2484s) **Presenter:** and so this would be very difficult to catch. [41:26](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2486s) **Presenter:** You also saw that the no-code primitives [41:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2488s) **Presenter:** that are provided by RPA are actually pretty good, [41:32](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2492s) **Presenter:** so there are a whole bunch of things [41:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2493s) **Presenter:** that you can do with those primitives. [41:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2497s) **Presenter:** which is a way to do all of that, [41:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2499s) **Presenter:** but without having to deal with the complexity of RPA itself. [41:44](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2504s) **Presenter:** And instead you can run with command lines [41:46](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2506s) **Presenter:** and Python interface. [41:48](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2508s) **Presenter:** And the last thing I want to do [41:50](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2510s) **Presenter:** before we finish off this talk, [41:53](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2513s) **Presenter:** is to send you home with a few things [41:56](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2516s) **Presenter:** that you can do to protect your organization right now. [41:59](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2519s) **Presenter:** And so, these are concrete things that I encourage you to do. [42:04](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2524s) **Presenter:** First of all, you should monitor for every event of registering this Power Automate agent silently on user machines. [42:14](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2534s) **Presenter:** So there are a couple of executables that I'm stressing out and pointing to here. [42:19](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2539s) **Presenter:** Every usage of those executables should be monitored and logged. [42:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2545s) **Presenter:** And more than that, if you can create a detection that identifies usage of those executables with a tenant ID that is not your own organization's tenant ID, like the malicious tenant that I created for this research, this would be a very critical sign that somebody is actually trying to use these methods to hack your organization. [42:51](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2571s) **Presenter:** I also encourage you to review Microsoft's documentation around Power Automate and try to, there are a whole bunch of things that they are suggesting here to basically try and reduce your risk. [43:03](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2583s) **Presenter:** and there's a bunch of information about no code [43:07](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2587s) **Presenter:** and the risks around them. [43:09](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2589s) **Presenter:** There's a whole bunch of things that I've added here. [43:13](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2593s) **Presenter:** This entire talk was focused on how an attacker [43:16](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2596s) **Presenter:** can take advantage of RPA, [43:17](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2597s) **Presenter:** but actually users that are using RPA [43:20](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2600s) **Presenter:** are also exposing organizations to a whole bunch of risks. [43:25](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2605s) **Presenter:** This is the subject of another talk, [43:28](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2608s) **Presenter:** so I'll leave it for another day. [43:31](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2611s) **Presenter:** thank you very much for listening [43:33](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2613s) **Presenter:** and tuning into this talk [43:36](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2616s) **Presenter:** I'd be very happy to continue [43:37](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2617s) **Presenter:** to make this [43:39](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2619s) **Presenter:** a conversation later on [43:41](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2621s) **Presenter:** so please reach out to me [43:42](https://www.youtube.com/watch?v=e1Re2nbPQv4&t=2622s) **Presenter:** thank you very much and have a great conference ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/2e7905bf/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 No Code Malware: Windows At Your Service Michael Bargury @ Zenity BSides Orlando 2022 Learn more: github.com/mbrg/talks Twitter: @mbrg0 — slide 1 of 86 ### Slide 2 About me CTO and co-founder @ Zenity Ex MSFT cloud security OWASP ‘Top 10 LCNC Security Risks’ project lead Dark Reading columnist @mbrg0 ft. @UZisReal123 bit.ly/ lcsec — slide 2 of 86 ### Slide 3 Disclaimer This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of No Code. No Code is awesome. — slide 3 of 86 ### Slide 4 Initial access to full operation So you want to build a malware op — slide 4 of 86 ### Slide 5 You’re in. Congrats! Victim Hacker Initial access — slide 5 of 86 ### Slide 6 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access — slide 6 of 86 ### Slide 7 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access Run malware — slide 7 of 86 ### Slide 8 In the real world Victim Hacker EDR C&C 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 8 of 86 ### Slide 9 In the real world Victim Hacker EDR C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 9 of 86 ### Slide 10 In the real world Victim Hacker EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 10 of 86 ### Slide 11 In the real world Victim Hacker Initial access Persistency EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Run malware — slide 11 of 86 ### Slide 12 We wanted to do hacking, not ops Initial access Deploy malware C&C Exfiltration Defense evasion Persistency Cleanup … .. Profit Malware Ops — slide 12 of 86 ### Slide 13 Introducing.. Robotic Process Automation (RPA)! https://www.t-plan.com/rpa-architecture/ — slide 13 of 86 ### Slide 14 Introducing.. Robotic Process Automation (RPA)! Trusted executables Trusted cloud services Trusted communication https://www.t-plan.com/rpa-architecture/ — slide 14 of 86 ### Slide 15 RPA is everywhere (in the enterprise) — slide 15 of 86 ### Slide 16 RPA can take care of Ops for us C&C Exfiltration Defense evasion Persistency Cleanup And so much more: Handle errors Support different OS/versions Malware updates Aggregate data across machines … — slide 16 of 86 ### Slide 17 Outline Malware Ops motivation What is RPA? RPA technical deep dive Abusing RPA: RCE as a Service Introducing Power Pwn Defense: 4 things to do when you get home — slide 17 of 86 ### Slide 18 What is RPA? How anyone can automate mundane processes — slide 18 of 86 ### Slide 19 Teenage (MMORPG) life — slide 19 of 86 ### Slide 20 Grunt work required — slide 20 of 86 ### Slide 21 Grunt work required — slide 21 of 86 ### Slide 22 Grunt work required — slide 22 of 86 ### Slide 23 Grunt work required — slide 23 of 86 ### Slide 24 Grunt work required — slide 24 of 86 ### Slide 25 Profit! — slide 25 of 86 ### Slide 26 Automation!! — slide 26 of 86 ### Slide 27 Automation for real — slide 27 of 86 ### Slide 28 https://youtube.com/clip/UgkxqPRYueIjN24IqUs5iw13meeh7mm3KdNr Automation for real — slide 28 of 86 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/2e7905bf/media/automation-for-real.gif) ### Slide 29 Automation via RPA Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 29 of 86 ### Slide 30 Automation in the enterprise Use cases: Customer service routines Finance payments and reporting HR onboarding / offboarding Supply chain keep inventory up to date Procurement invoice processing Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 30 of 86 ### Slide 31 RPA Deep Dive — slide 31 of 86 ### Slide 32 “included in Windows 11” https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ — slide 32 of 86 ### Slide 33 Windows 11 desktop showing Power Automate search results beside Microsoft documentation that Power Automate is preinstalled in Windows 11 — slide 33 of 86 ### Slide 34 youtu.be/Kik9oXu_-bI — slide 34 of 86 - Youtube: [defcon30 Power Automate Desktop](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 35 Synced to cloud — slide 35 of 86 ### Slide 36 Architecture diagram with Power Automate on Windows 11 and Office cloud services separated by the on-premises and Microsoft cloud boundary — slide 36 of 86 ### Slide 37 Architecture diagram showing the UIFlowService user connecting Power Automate to the machine runtime on Windows 11 — slide 37 of 86 ### Slide 38 Architecture diagram with Power Automate browser-extension setup screenshots for Microsoft Edge — slide 38 of 86 ### Slide 39 Architecture diagram showing Power Automate connected to Chrome, Firefox, and Edge through the machine runtime — slide 39 of 86 ### Slide 40 Architecture diagram with Windows Explorer highlighting Power Automate Desktop application executables — slide 40 of 86 ### Slide 41 Corp network boundary 🔥💀🔥💀🔥💀🔥💀 — slide 41 of 86 ### Slide 42 🔥💀🔥💀🔥💀🔥💀 Corp network boundary — slide 42 of 86 ### Slide 43 Architecture diagram showing the machine runtime making an outbound connection through the corporate network boundary to Azure Service Bus and Office cloud services — slide 43 of 86 ### Slide 44 Your machines — slide 44 of 86 ### Slide 45 Run from cloud — slide 45 of 86 ### Slide 46 Task status — slide 46 of 86 ### Slide 47 Architecture diagram showing Power Automate and browsers connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 47 of 86 ### Slide 48 Architecture diagram adding the machine private key and Office cloud public key to the Power Automate connection — slide 48 of 86 ### Slide 49 Architecture diagram adding local credentials and an RPA task to the Azure Service Bus connection — slide 49 of 86 ### Slide 50 RCE as a Service Repurpose RPA to power malware ops — slide 50 of 86 ### Slide 51 Recall our wish list Initial access Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup … .. Profit Malware Ops — slide 51 of 86 ### Slide 52 Hello Pwntoso — slide 52 of 86 ### Slide 53 Register victim machines Can we avoid the UI? — slide 53 of 86 ### Slide 54 Register victim machines https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine Sure! Can we avoid the UI? — slide 54 of 86 ### Slide 55 Hello new machine — slide 55 of 86 ### Slide 56 Admin required https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine 😞 — slide 56 of 86 ### Slide 57 Admin NOT required 🤓 — slide 57 of 86 ### Slide 58 Trigger from cloud Set up connection Distribute payload Cloud setup — slide 58 of 86 ### Slide 59 How to avoid active machine users Attended RPA 💻🙂 Unattended RPA 🤖 Create a new local user session Leverage an existing local user session — slide 59 of 86 ### Slide 60 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup — slide 60 of 86 ### Slide 61 Let the fun begin. — slide 61 of 86 ### Slide 62 Data exfil (start simple) Data exfiltrated as flow output — slide 62 of 86 ### Slide 63 Distribute payload, execute and collect output from cloud Input Output — slide 63 of 86 ### Slide 64 Architecture diagram of Power Automate and browsers on Windows 11 connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 64 of 86 ### Slide 65 1.Instructions 2.Payload 3.Output — slide 65 of 86 ### Slide 66 Code execution — slide 66 of 86 ### Slide 67 Oops Code execution — slide 67 of 86 ### Slide 68 Code execution Oops — slide 68 of 86 ### Slide 69 Code execution – try again Untrusted Trusted — slide 69 of 86 ### Slide 70 Code execution– try again What can we do with drag & drop primitives only (No Code)? — slide 70 of 86 ### Slide 71 No Code primitives — slide 71 of 86 ### Slide 72 No Code Ransomware — slide 72 of 86 ### Slide 73 youtu.be/ YDull-krSJI — slide 73 of 86 - Youtube: [defcon30 No Code Ransomware](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 74 No Code Cleanup — slide 74 of 86 ### Slide 75 Machine to Cloud via the browser https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers Open browser minimized Go to flow.microsoft.com Hit CTRL+U Extract access token from header — slide 75 of 86 ### Slide 76 youtu.be/lY_RzV-4BdI — slide 76 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/2e7905bf/media/steal-browser-token-local.mp4) ### Slide 77 youtu.be/zlF7np18oGI — slide 77 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-19_BSides-Orlando_No_Code_Malware_Windows_At_Your_Service/2e7905bf/media/steal-browser-token-cloud.mp4) ### Slide 78 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup And more: Creds access via browser — slide 78 of 86 ### Slide 79 Introducing Power Pwn ! — slide 79 of 86 ### Slide 80 Power Pwn ! Trigger via HTTP Seamlessly handle errors and edge cases — slide 80 of 86 ### Slide 81 One endpoint to rule them all! POST machine=win11ent user= alexg payload=ransomware dir =C:\ encryptionKey =9d0d578115a2734a SUCCESS filesFound =71892 filesProcessed =70497 — slide 81 of 86 ### Slide 82 Convenience layer in Python Set up a free RPA account Register machines Profit github.com/mbrg/power-pwn — slide 82 of 86 ### Slide 83 Summary What is RPA? Available in every major enterprise Technical deep dive Abusing RPA: RCE as a Service Distribute and execute payloads thru trusted services No Code primitives Introducing Power Pwn Defense: 4 things to do when you get home — slide 83 of 86 ### Slide 84 How To Stay Safe? — slide 84 of 86 ### Slide 85 Do these 4 things to reduce your risk Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization Review you own tenant’s Power Automate environment and Microsoft best practice . If you’re a Microsoft shop, your users are probably already using it! Learn more at OWASP , Dark Reading , Zenity blog — slide 85 of 86 ### Slide 86 No Code Malware: Windows At Your Service Michael Bargury @ Zenity BSides Orlando 2022 Learn more: github.com/mbrg/talks Twitter: @mbrg0 — slide 86 of 86