Nishang - Tracking A Windows User

By Nikhil Mittal on 12 Nov 2015 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#windows #red-teaming #endpoint-protection #keylogging
Focus Areas: πŸ›‘οΈ Security Operations & Defense , πŸ’» Endpoint Security , 🦠 Malware Analysis , 🎯 Penetration Testing
This tool demo covers following tools where the speaker has contributed or authored
NISHANG

Abstract

In this demonstration, we will see how scripts based on built-in Windows tools Windows PowerShell PowerShell, VB Script, .Net Framework, native commands, Registry etc. could be used to keep track of a Windows user. In addition to having backdoor access, these tools and scripts provide capabilities like taking pics from user webcam, recording MIC, screen-shot/live-streaming of user screen, logging keys, internet history, location tracking and much more.

All the scripts in the demo would be a part of Nishang framework.