July 4, 2023, 10:13 a.m. | István Tóth

InfoSec Write-ups - Medium infosecwriteups.com

Backdooring ClickOnce .NET Apps for Initial Access: A Practical Example

This blogpost is about demonstrating the awesome ClickOnce .NET backdooring technique by Nick Powers (@zyn3rgy) and Steven F (@0xthirteen) presented at Defcon30. Here I tried to recreate the technique based on the written version of the presentation.

About

First of all, without unnecessarily repeating the original presentation and blogpost, ClickOnce is an easy deployment and execute technique (even for regular non-admin users) for applications …

dotnet it security offensive security phishing red team

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC