
An incident response reveals itself as GhostShell tool, ShellClient. [Research Saturday]
CyberWire Daily
00:00
The Shock Riant - What Kind of Commands Does It Have?
The shock riant can do various types of commands from querying the host name for ample, check which type of version of shell plant is actually running. It's able to extract the ip address of the machine, or actually to ping in external ip services and install other things. So it has very robust capabilities when it comes to enabling the thread actor to run various operations. And even have some command that enables it to run lateral movement using w now, one of the interesting aspects of your research here is that you you explored if this was a, how old a version of this is,. trying to determine how far back this goes.
Play episode from 09:20
Transcript


