WEBVTT

00:00:01.440 --> 00:00:04.670
Before we go, I want to share with you a few more resources in case you

00:00:04.670 --> 00:00:08.970
want to learn more about pwncat and persistence. First, and most

00:00:08.970 --> 00:00:12.970
important, check the official documentation from pwncat. In this course,

00:00:12.980 --> 00:00:16.540
we covered just one of the features of the two, but the reality is that

00:00:16.540 --> 00:00:20.550
pwncat has several other features like enumeration scripts and privilege

00:00:20.550 --> 00:00:21.360
escalation modules.

00:00:22.240 --> 00:00:24.530
Also, if you want to improve your red teaming game,

00:00:24.540 --> 00:00:28.490
I recommend to you two courses here from Pluralsight. First, the

00:00:28.490 --> 00:00:31.810
Persistence with Impacket course in which we cover another really

00:00:31.810 --> 00:00:34.160
common persistent technique for writing engagements.

00:00:35.140 --> 00:00:37.690
The other course I recommend is the Post Exploitation with

00:00:37.690 --> 00:00:40.750
Meterpreter, which as the name suggests, covers all the activities

00:00:40.760 --> 00:00:42.550
after getting initial access to a server.

00:00:43.440 --> 00:00:46.300
Also, if you're wondering how you can protect your company against the

00:00:46.300 --> 00:00:49.250
persistence attacks that we're discussing here, I have a few suggestions

00:00:49.250 --> 00:00:54.160
for you. First, adopt security technologies that are able to monitor local

00:00:54.160 --> 00:00:59.020
account changes. Attackers love to use SSH keys and hidden accounts to

00:00:59.020 --> 00:01:00.350
create persistence in a server.

00:01:01.240 --> 00:01:04.800
Also, you could adopt endpoint behavior defense tools to detect

00:01:04.800 --> 00:01:07.260
the changes on local accounts and SSH files.

00:01:07.840 --> 00:01:10.680
The attack that we performed here changes some critical SSH

00:01:10.680 --> 00:01:14.040
files and a good behavior‑based tool would be able to detect

00:01:14.040 --> 00:01:17.210
such changes. So that's it,

00:01:17.220 --> 00:01:20.750
that's the end of our pwncat course. I hope you enjoyed this course and that

00:01:20.750 --> 00:01:24.800
now you have one more persistence technique in your skillset. So thank you for

00:01:24.800 --> 00:01:26.460
watching, and I'll see you in the next course.
