Detecting and Preventing Abuse of the Windows SilentCleanup Task
Anvilogic 8.0 is generally available
.svg)
Abuse SilentCleanup Task
Threats + Use Case
May 4, 2021 12:00 AM CST
Online
On-Demand Webinar
Overview of Abuse SilentCleanup Task
There's a task in Windows Task Scheduler called "SilentCleanup" which, while it's executed as Users, automatically runs with elevated privileges. When it runs, it executes the file "%windir%\system32\cleanmgr.exe". Since it runs as Users, and it's possible to control user's environment variables, "%windir%" (normally pointing to C:\Windows) can be changed to point to whatever file an adversary wants, and it'll run as admin. This use case identifies execution of the "SilentCleanup" task.
References
Tags
- Defense Evasion
- Privilege Escalation
- PowerShell
- Splunk
- APT29
- BRONZE BUTLER
- Cobalt Group
- Honeybee
- APT37
- Threat Group-3390
- MuddyWater
- Patchwork
Resources
No items found.