Going fileless and evading antivirus
Most organizations allow users to access their internal infrastructure on all the network segments or have a flat network. In some organizations, particularly in the banking sector, the networks are segregated, and strict access controls are put in place. As an example, an internal firewall rule may be created to permit only port 80
or 443
as outbound communication and block all the other ports. So, it is recommended to utilize ports 80
or 443
for all listeners during testing. In this section, we will explore some quick wins to bypass security controls and take over a given system.