sbPSReflect flagged/deleted by McAfee A/V

#46 · closed · 3 comments

View on GitHub ↗

keepwatch

As of PR #41, McAfee Endpoint Security detects `sbPSReflect.ps1` as `HTool-PoshSec` and deletes it from the analyst machine. The module continues to return results, but without the SYSTEM capabilities and with the three error messages included below. The errors interfere with any wrapper scripts as well by triggering try/catch blocks. Would obfuscating this .ps1 on disk be an option? (human) readability suffers but compatible functionality would improve. ``` get-content : Cannot find path 'C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Content \Scriptblock\base\sbPSReflect.ps1' because it does not exist. At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:354 char:72 + ... k]::Create((get-content "$PSScriptRoot\Content\Scriptblock\base\sbPSR ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (C:\Users\<username>...sbPSReflect.ps1:String) [Get-Content], ItemNotFoundEx ception + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetContentCommand Exception calling "Create" with "1" argument(s): "Object reference not set to an instance of an object." At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:354 char:5 + $sbPSReflect = [System.Management.Automation.ScriptBlock]::Create ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [], MethodInvocationException + FullyQualifiedErrorId : NullReferenceException You cannot call a method on a null-valued expression. At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:356 char:5 + $Scriptblock = [ScriptBlock]::Create($Scriptblock.ToString() + $s ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: (:) [], RuntimeException + FullyQualifiedErrorId : InvokeMethodOnNull ```

Comments

mgreen27

Thank you for bringing that up - I was considering this too as I have had varied results with different AV/EDR. On the analyst machine, this is less important as you can whitelist easily but on the target harder. Some ideas: 1) stripping strings MFE is detecting on from the psreflect functions. 2) reverting to manual pinvoke instead of using psreflect which has a lot of detectable strings. 3) failing the above encoding the whole thing or executing via memory based methods (like WinRM remote execution). I will take a look at this over the next few days. Matt

mgreen27

I have stripped identifying strings off the sbPSReflect.ps1. Will keep this open for now but close in a few more days

mgreen27

closing this off as issue resolved!