# Windows RCE as a Service > OWASP Global AppSec US 2022, 2022-11-17. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-11-17-owasp-global-appsec-us-2022-windows-rce-as-a-service/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/slides.pdf) - [Conference agenda](https://owasp2022globalappsecsf.sched.com/event/1BS5H/windows-rce-as-a-service) - [Source code](https://github.com/mbrg/power-pwn/wiki/Modules:-No%E2%80%90Code-Malware) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-11-17-owasp-global-appsec-us-2022-windows-rce-as-a-service.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines or Office cloud, executed successfully and reports back to the cloud. You can probably already see where this is going. In this presentation, we will show how Power Automate can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works, what attack surface it exposes on the machine and in the cloud, and how it is enabled by-default and can be used without explicit user consent. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official conference abstract](https://owasp2022globalappsecsf.sched.com/event/1BS5H/windows-rce-as-a-service)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/fc3e9de9/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Michael Bargury (@mbrg0) Windows RCE as a Service github.com/mbrg/talks Zenity — slide 1 of 86 ### Slide 2 About me CTO and co-founder @ Zenity Ex MSFT cloud security OWASP ‘Top 10 LCNC Security Risks’ project lead Dark Reading columnist @mbrg0 ft. @UZisReal123 bit.ly/ lcsec — slide 2 of 86 ### Slide 3 Disclaimer This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of No Code. No Code is awesome. — slide 3 of 86 ### Slide 4 No Code Malware: Windows RCE as a Service 01 Initial access to full operation : So you want to build a malware op — slide 4 of 86 ### Slide 5 You’re in. Congrats! Victim Hacker Initial access — slide 5 of 86 ### Slide 6 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access — slide 6 of 86 ### Slide 7 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access Run malware — slide 7 of 86 ### Slide 8 In the real world Victim Hacker EDR C&C 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 8 of 86 ### Slide 9 In the real world Victim Hacker EDR C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 9 of 86 ### Slide 10 In the real world Victim Hacker EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 10 of 86 ### Slide 11 In the real world Victim Hacker Initial access Persistency EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Run malware — slide 11 of 86 ### Slide 12 We wanted to do hacking, not ops Initial access Deploy malware C&C Exfiltration Defense evasion Persistency Cleanup … .. Profit Malware Ops — slide 12 of 86 ### Slide 13 Introducing.. Robotic Process Automation (RPA)! https://www.t-plan.com/rpa-architecture/ — slide 13 of 86 ### Slide 14 Introducing.. Robotic Process Automation (RPA)! Trusted executables Trusted cloud services Trusted communication https://www.t-plan.com/rpa-architecture/ — slide 14 of 86 ### Slide 15 RPA is everywhere (in the enterprise) — slide 15 of 86 ### Slide 16 RPA can take care of Ops for us C&C Exfiltration Defense evasion Persistency Cleanup And so much more: Handle errors Support different OS/versions Malware updates Aggregate data across machines … — slide 16 of 86 ### Slide 17 Outline Malware Ops motivation What is RPA? RPA technical deep dive Abusing RPA: RCE as a Service Introducing Power Pwn Defense: 4 things to do when you get home — slide 17 of 86 ### Slide 18 Windows RCE as a Service 0 2 What is RPA? How anyone can automate mundane prcesses — slide 18 of 86 ### Slide 19 Teenage (MMORPG) life — slide 19 of 86 ### Slide 20 Grunt work required — slide 20 of 86 ### Slide 21 Grunt work required — slide 21 of 86 ### Slide 22 Grunt work required — slide 22 of 86 ### Slide 23 Grunt work required — slide 23 of 86 ### Slide 24 Grunt work required — slide 24 of 86 ### Slide 25 Profit! — slide 25 of 86 ### Slide 26 Automation!! — slide 26 of 86 ### Slide 27 Automation for real — slide 27 of 86 ### Slide 28 https://youtube.com/clip/UgkxqPRYueIjN24IqUs5iw13meeh7mm3KdNr Automation for real — slide 28 of 86 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/fc3e9de9/media/automation-for-real.gif) ### Slide 29 Automation via RPA Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 29 of 86 ### Slide 30 Automation in the enterprise Use cases: Customer service routines Finance payments and reporting HR onboarding / offboarding Supply chain keep inventory up to date Procurement invoice processing Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 30 of 86 ### Slide 31 Windows RCE as a Service 0 3 RPA Deep Dive — slide 31 of 86 ### Slide 32 “included in Windows 11” https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ — slide 32 of 86 ### Slide 33 Windows 11 desktop showing Power Automate search results beside Microsoft documentation that Power Automate is preinstalled in Windows 11 — slide 33 of 86 ### Slide 34 youtu.be/Kik9oXu_-bI — slide 34 of 86 - Youtube: [defcon30 Power Automate Desktop](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 35 Synced to cloud — slide 35 of 86 ### Slide 36 Architecture diagram with Power Automate on Windows 11 and Office cloud services separated by the on-premises and Microsoft cloud boundary — slide 36 of 86 ### Slide 37 Architecture diagram showing the UIFlowService user connecting Power Automate to the machine runtime on Windows 11 — slide 37 of 86 ### Slide 38 Architecture diagram with Power Automate browser-extension setup screenshots for Microsoft Edge — slide 38 of 86 ### Slide 39 Architecture diagram showing Power Automate connected to Chrome, Firefox, and Edge through the machine runtime — slide 39 of 86 ### Slide 40 Architecture diagram with Windows Explorer highlighting Power Automate Desktop application executables — slide 40 of 86 ### Slide 41 Corp network boundary 🔥💀🔥💀🔥💀🔥💀 — slide 41 of 86 ### Slide 42 🔥💀🔥💀🔥💀🔥💀 Corp network boundary — slide 42 of 86 ### Slide 43 Architecture diagram showing the machine runtime making an outbound connection through the corporate network boundary to Azure Service Bus and Office cloud services — slide 43 of 86 ### Slide 44 Your machines — slide 44 of 86 ### Slide 45 Run from cloud — slide 45 of 86 ### Slide 46 Task status — slide 46 of 86 ### Slide 47 Architecture diagram showing Power Automate and browsers connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 47 of 86 ### Slide 48 Architecture diagram adding the machine private key and Office cloud public key to the Power Automate connection — slide 48 of 86 ### Slide 49 Architecture diagram adding local credentials and an RPA task to the Azure Service Bus connection — slide 49 of 86 ### Slide 50 Windows RCE as a Service 0 4 RCE as a Service Repurpose RPA to power malware ops — slide 50 of 86 ### Slide 51 Recall our wish list Initial access Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup … .. Profit Malware Ops — slide 51 of 86 ### Slide 52 Hello Pwntoso — slide 52 of 86 ### Slide 53 Register victim machines Can we avoid the UI? — slide 53 of 86 ### Slide 54 Register victim machines https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine Sure! Can we avoid the UI? — slide 54 of 86 ### Slide 55 Hello new machine — slide 55 of 86 ### Slide 56 Admin required https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine 😞 — slide 56 of 86 ### Slide 57 Admin NOT required 🤓 — slide 57 of 86 ### Slide 58 Trigger from cloud Set up connection Distribute payload Cloud setup — slide 58 of 86 ### Slide 59 How to avoid active machine users Attended RPA 💻🙂 Unattended RPA 🤖 Create a new local user session Leverage an existing local user session — slide 59 of 86 ### Slide 60 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup — slide 60 of 86 ### Slide 61 Windows RCE as a Service 0 5 Let the fun being. — slide 61 of 86 ### Slide 62 Data exfil (start simple) Data exfiltrated as flow output — slide 62 of 86 ### Slide 63 Distribute payload, execute and collect output from cloud Input Output — slide 63 of 86 ### Slide 64 Architecture diagram of Power Automate and browsers on Windows 11 connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 64 of 86 ### Slide 65 1.Instructions 2.Payload 3.Output — slide 65 of 86 ### Slide 66 Code execution — slide 66 of 86 ### Slide 67 Oops Code execution — slide 67 of 86 ### Slide 68 Code execution Oops — slide 68 of 86 ### Slide 69 Code execution – try again Untrusted Trusted — slide 69 of 86 ### Slide 70 Code execution– try again What can we do with drag & drop primitives only (No Code)? — slide 70 of 86 ### Slide 71 No Code primitives — slide 71 of 86 ### Slide 72 No Code Ransomware — slide 72 of 86 ### Slide 73 youtu.be/ YDull-krSJI — slide 73 of 86 - Youtube: [defcon30 No Code Ransomware](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 74 No Code Cleanup — slide 74 of 86 ### Slide 75 Machine to Cloud via the browser https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers Open browser minimized Go to flow.microsoft.com Hit CTRL+U Extract access token from header — slide 75 of 86 ### Slide 76 youtu.be/lY_RzV-4BdI — slide 76 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/fc3e9de9/media/steal-browser-token-local.mp4) ### Slide 77 youtu.be/zlF7np18oGI — slide 77 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-17_OWASP-US-2022_Windows_RCE_as_a_Service/fc3e9de9/media/steal-browser-token-cloud.mp4) ### Slide 78 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup And more: Creds access via browser — slide 78 of 86 ### Slide 79 Introducing Power Pwn ! — slide 79 of 86 ### Slide 80 Power Pwn ! Trigger via HTTP Seamlessly handle errors and edge cases — slide 80 of 86 ### Slide 81 One endpoint to rule them all! POST machine=win11ent user= alexg payload=ransomware dir =C:\ encryptionKey =9d0d578115a2734a SUCCESS filesFound =71892 filesProcessed =70497 — slide 81 of 86 ### Slide 82 Convenience layer in Python Set up a free RPA account Register machines Profit github.com/mbrg/power-pwn — slide 82 of 86 ### Slide 83 Summary What is RPA? Available in every major enterprise Technical deep dive Abusing RPA: RCE as a Service Distribute and execute payloads thru trusted services No Code primitives Introducing Power Pwn Defense: 4 things to do when you get home — slide 83 of 86 ### Slide 84 Windows RCE as a Service 0 6 How to Stay Safe? — slide 84 of 86 ### Slide 85 Do these 4 things to reduce your risk Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization Review you own tenant’s Power Automate environment and Microsoft best practice . If you’re a Microsoft shop, your users are probably already using it! Learn more at OWASP , Dark Reading , Zenity blog — slide 85 of 86 ### Slide 86 Michael Bargury (@mbrg0) Windows RCE as a Service github.com/mbrg/talks Zenity — slide 86 of 86