FWIW, 100% of #ClickFix attacks I've seen have added some kind of inline comment at the end of the command string like I am not a robot to sell the ruse. Definitely worth a threat hunt on command line history.
Conversation
Notices
-
Embed this notice
Taggart :donor: (mttaggart@infosec.exchange)'s status on Tuesday, 29-Apr-2025 01:46:03 JST Taggart :donor:
-
Embed this notice
Taggart :donor: (mttaggart@infosec.exchange)'s status on Tuesday, 29-Apr-2025 01:46:02 JST Taggart :donor:
@cR0w It's a standard EDR feature? But yes, it costs hella ducats. Sysmon is free, but oh lordy the self-hosted SIEM ain't.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 29-Apr-2025 01:46:02 JST cR0w :cascadia:
@mttaggart My EDR is... an interesting story.
-
Embed this notice
cR0w :cascadia: (cr0w@infosec.exchange)'s status on Tuesday, 29-Apr-2025 01:46:03 JST cR0w :cascadia:
@mttaggart Look at you with your fancy command history logs. 🥲
-
Embed this notice