[HN Gopher] LOLDrivers - Living Off the Land Drivers
       ___________________________________________________________________
        
       LOLDrivers - Living Off the Land Drivers
        
       Author : sacrosanct
       Score  : 43 points
       Date   : 2023-04-07 19:57 UTC (3 hours ago)
        
 (HTM) web link (www.loldrivers.io)
 (TXT) w3m dump (www.loldrivers.io)
        
       | SCHiM wrote:
       | This is a webpage collecting a list of (signed?) drivers that may
       | be loaded into the Windows kernel and thereby escalate
       | privileges. Because the Windows kernel doesn't support loading
       | drivers that are not signed by Microsoft, attackers have to
       | resort to exploiting legitimate signed drivers to gain access to
       | the kernel once they've obtained Administrator (root) or SYSTEM
       | (root) privileges.
       | 
       | A central list of exploitable drivers serves as a starting point
       | for both attackers and defenders. Attackers can use it for their
       | research if they want to raise their privileges by loading code
       | into the kernel (rootkits), or attack protected processes (PPL
       | and up, think anti-virus and anti-malware processes, DRM). For
       | defenders it serves as a curated list of drivers to look out for
       | in their environment. For example, to raise alerts if a Lenovo
       | driver is loaded on a Dell system.
       | 
       | A similar site is the LolBAS site, where signed Windows binaries
       | are listed for their ability to serve as trusted "proxy"
       | executables into which attackers can somehow inject or load their
       | code.
        
       | [deleted]
        
       | [deleted]
        
       | 0x69420 wrote:
       | i'm not really a security guy but... is ibm poland ok? that's one
       | hell of an outlier
        
         | thriftwy wrote:
         | Maybe they have published a lot of different revisions of the
         | same vulnerable driver?
        
       | vuln wrote:
       | Nice! LolBAS and gtfobins are great projects. I've used both
       | extensively. I can't wait until Monday to start running this
       | against my environment. Down the rabbit hole I go at 4pm on a
       | Friday! Appreciate the hard work.
        
       | colinsane wrote:
       | what does the name mean ("Living Off the Land")? i expected some
       | homesteading tools or something -- does the phrase have some
       | history in the security world?
        
         | jabroni_salad wrote:
         | LOTL means that the adversary is using tools already present on
         | that computer instead of trying to download even more malware.
         | This strategy is popular because not writing any files makes
         | you immune to filescanners.
        
         | teeray wrote:
         | I honestly thought this was going to be a forum for big rig
         | truckers that also hunted and trapped their own food or
         | something.
        
           | tmtvl wrote:
           | I was also expecting something like survivalists who live in
           | their pickup truck or something.
        
         | ghostpepper wrote:
         | It means essentially that. The alternative is an attacker
         | bringing/installing their own tools post-compromise.
         | 
         | Living off the land is more stealthy because you're using
         | legitimate system tools to do malicious activities
        
         | [deleted]
        
       | ronsor wrote:
       | Ah yes, the venerable MHYProt is included in the list. I do love
       | gaming anticheats; they make loading cheats so easy.
        
       ___________________________________________________________________
       (page generated 2023-04-07 23:01 UTC)