module

Accessibility Features (Sticky Keys) Persistence via Debugger Registry Key

Disclosed
Apr 24, 1995

Description

This module makes it possible to apply the 'sticky keys' hack to a session with appropriate
rights. The hack provides a means to get a SYSTEM shell using UI-level interaction at an RDP
login screen or via a UAC confirmation dialog. The module modifies the Debug registry setting
for certain executables.

The module options allow for this hack to be applied to:

SETHC (sethc.exe is invoked when SHIFT is pressed 5 times),
UTILMAN (Utilman.exe is invoked by pressing WINDOWS+U),
OSK (osk.exe is invoked by pressing WINDOWS+U, then launching the on-screen keyboard),
DISP (DisplaySwitch.exe is invoked by pressing WINDOWS+P),
NARRATOR (Narrator.exe is invoked by pressing WINDOWS+CTR+ENTER),
ATBROKER (AtBroker.exe is invoked by launching accessibility features from the login screen, such as WINDOWS+CTR+ENTER).

Custom payloads and binaries can be run as part of this exploit, but must be manually uploaded
to the target prior to running the module.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.