winget: Install ROGUE Software & Packages?

winget: Install ROGUE Software & Packages?

Source: YouTube · John Hammond · published Apr 20, 2023 · 15:57

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates how winget (Windows Package Manager) can be abused as a "living off the land" technique by hackers to download and execute malicious code while appearing to use a legitimate Windows utility 0:50-0:58.

Key Takeaways:
• Winget is a native Windows package manager built into modern Windows systems 0:50-0:58
• Hackers can manipulate winget to download and execute code from remote locations using custom YAML manifest files 1:29-1:33
• The technique requires administrator privileges to enable local manifest file functionality 7:21-7:24
• Winget logs its activities, which can be useful for forensic analysis and detection 4:02-4:04, 13:24-13:26

The winget technique represents another "living off the land" method that could be used for offensive purposes, though it requires admin access and has some detection mechanisms in place 15:30-15:32.

Sources:

  • 0:50-0:58 Introduction to winget as a native Windows package manager
  • 1:29-1:33 How hackers can manipulate winget with YAML manifest files
  • 7:21-7:24 Admin privileges requirement for local manifest functionality
  • 4:02-4:04 Winget logging capabilities
  • 13:24-13:26 Using logs for forensic detection
  • 15:30-15:32 Winget as a blending technique for attackers

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

when a hacker compromises a computer what they do next really tends to vary but it's likely that they're going to end up using some living off the land techniques or using tools utilities and programs and applications that are already on the Target on the victim operating system and computer to do what they might then further do for the Windows operating system a lot of these living off the land binary scripts libraries other techniques tricks and tips you could end up using are publicly available they're online and documented in this low bass GitHub repository and a web page to be able to look through them and of course if you're looking for Linux tips and tricks and techniques you can use the GTFO bins or LOL drivers if you're looking at drivers and how they might be used for this purpos…