Skip to primary content
Skip to secondary content

Hexacorn

Hexacorn

Main menu

  • Home
  • Services
  • Products & Freebies
  • Case Studies
  • Contact Us

Category Archives: Anti-Forensics

Post navigation

← Older posts
Newer posts →

Beyond good ol’ Run key, Part 118

Posted on 2019-10-04 by adam

In my last post I mentioned mso.dll. This DLL hides a lot of secrets.

One of them is the Microsoft’s own version of AirDrop that is configured via a following Registry entry:

HKLM\SOFTWARE\Microsoft\AirDrop
DllName=<DLL Name>

I have never used / tested it, but it’s yet another location to check.

Posted in Anti-Forensics, Autostart (Persistence)

Beyond good ol’ Run key, Part 117

Posted on 2019-09-28 by adam

This is yet another quickie.

SQL Server Management Studio supports plugins, so it is good to have a look if any of them is dodgy:

  • HKCU or HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\<version>\Tools\Shell\Addins\<entry>=<addin DLL>
Posted in Anti-Forensics, Autostart (Persistence)

Post navigation

← Older posts
Newer posts →
Privacy Policy Proudly powered by WordPress