Poison Ivy for Incident Responders - FIRST

[Pages:55]Poison Ivy for Incident Responders

Andreas Schuster

Poison Ivy in the Press

What is Poison Ivy?

Poison Ivy is a Powerful RAT

Target platform: Microsoft Windows, 32bit System information and manipulation Keyword search Password collection Shell (cmd.exe) Surveillance Lateral movement: relaying, sharing Administration (update, removal)

Poison Ivy is Free, but Closed Source

Builder ? Step 1

Builder ? Step 2

Builder ? Step 3

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download