WinLogon (Elevated)
Last updated
Last updated
Winlogon uses some registry keys under that could be interesting to gain persistence:
Userinit points to userinit.exe, which is in charge of restoring your user profile preferences.
shell points to the system's shell, which is usually explorer.exe
We can modify the string by adding our shellcode path
After doing this, sign out of your current session and log in again, and you should receive a shell