GrimResource - Microsoft Management Console for initial access and evasion
Elastic Security Labs has discovered a new method for initial access and evasion in the wild, termed GrimResource. It allows attackers to gain full code execution in the context of mmc.exe after a user clicks on a specially crafted MSC file.
GrimResource - Microsoft Management Console for initial access and evasionPop Calc POC:
p/s: I think this is an interesting topic, I would discuss the possibilities and ideas in the telegram chat (your suggestions)
Video demo Attach