Collected research
Attacking PowerShell CLIXML Deserialization
Analyses PowerShell's CLIXML deserialization, where objects are restored as property bags or rehydrated as live objects, and shows the default rehydrating types supply usable gadgets: a CIM ping type triggering arbitrary DNS lookups, a registry type whose formatter captures Net-NTLMv2 hashes, and a popular third-party module whose converter wraps BinaryFormatter for code execution. PowerShell Remoting and Direct deserialize server-supplied CLIXML, so a guest can attack its Hyper-V host.
Record
- Researcher
- siteadmin and @Truesec
- Published by
- Truesec
- Date
- Topic
- Other
In the archive
Related sources
- How to Break Out of Hyper-V and Compromise your Admins – Truesec
- SEC-T 0x10: Alexander - Attacking PowerShell CLIXML Deserialization
Tags
This page is the archive's own catalogue record. The research is the work of siteadmin and @Truesec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .