
DesckVB-RAT
Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain
command-and-controldigital-forensicseducation+8
9

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…