Skip to content

Commit 13d75ef

Browse files
1 parent 345216b commit 13d75ef

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

_lolbas/Binaries/Cipher.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
Name: Cipher.exe
3+
Description: File Encryption Utility
4+
Author: Adetutu Ogunsowo
5+
Created: 2024-11-22
6+
Commands:
7+
- Command: cipher /w:{PATH_ABSOLUTE:folder}
8+
Description: Zero out a file
9+
Usecase: Can be used to forensically erase a file
10+
Category: Tamper
11+
Privileges: User
12+
MitreID: T1485
13+
OperatingSystem: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
14+
Full_Path:
15+
- Path: c:\windows\system32\cipher.exe
16+
- Path: c:\windows\syswow64\cipher.exe
17+
Detection:
18+
- IOC: cipher.exe process with /w on the command line
19+
Resources:
20+
- Link: https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
21+
Acknowledgement:
22+
- Person: Ade Ogunsowo
23+
Handle: "@i_am_tutu"
24+
---

0 commit comments

Comments
 (0)