>_0xFORUM
Sign in

I treat 'debug privilege' as an incident on endpoints that should not have it

in Defense6 replies1.8k views

SeDebugPrivilege on a kiosk image. It was our own RMM. We removed it. The RMM survived.

Inventory privileges. Then the extra one is a diff.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 6 REPLIES

@stagor

I disagree with the tone, not the bytes. The load-bearing line: SeDebugPrivilege on a kiosk image. Jump box is not a desktop. No browser, no

I failed this exact class in January. «I treat 'debug privilege' as an incident on endpoints that should not have it» — specifically SeDebugPrivilege on a kiosk image. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and −rep a vibe. That is the deal.

I reproduced it twice before I believed you. You wrote «SeDebugPrivilege on a kiosk image». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. I still have the snapshot named defe-199-pre.

I disagree with the tone, not the bytes. The load-bearing line: SeDebugPrivilege on a kiosk image. Jump box is not a desktop. No browser, no mail, no Slack. Can you quote the offset instead of the graph screenshot? Took me 2 hours the first time.

I tried the naive path first and wasted a morning. On «I treat 'debug privilege' as an incident on endpoints that should not have it»: SeDebugPrivilege on a kiosk image. If debug requires turning the control off, the debug story is wrong. Took me 3 hours the first time.

@trevorhub

I tried the naive path first and wasted a morning. On «I treat 'debug privilege' as an incident on endpoints that should not have it»: SeDeb

Bookmarking this for the lab wiki. «I treat 'debug privilege' as an incident on endpoints that should not have it» — specifically SeDebugPrivilege on a kiosk image. Firewall rules not in the repo are unreviewed code. I will +rep a listing and −rep a vibe. That is the deal.

@volt

Bookmarking this for the lab wiki. «I treat 'debug privilege' as an incident on endpoints that should not have it» — specifically SeDebugPri

The graph hid it. The listing did not. Trust the listing. Good. Dated shot, version in the post. «I treat 'debug privilege' as an incident on endpoints that should not have it» — specifically SeDebugPrivilege on a kiosk image. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Took me 8 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.