Skip to content

Instantly share code, notes, and snippets.

@shiftybitshiftr
Last active April 14, 2023 23:44
Show Gist options
  • Save shiftybitshiftr/afe196c72cb11b5de40ac986ad2ce7cf to your computer and use it in GitHub Desktop.
Save shiftybitshiftr/afe196c72cb11b5de40ac986ad2ce7cf to your computer and use it in GitHub Desktop.
executable code_signature.subject_name code_signature.serial_number
C:\Program Files (x86)\ScreenConnect\Bin\ScreenConnect.Service.exe Connectwise, LLC 0b9360051bccf66642998998d5ba97ce
C:\Program Files (x86)\ScreenConnect\Bin\ScreenConnect.Client.exe Connectwise, LLC 0b9360051bccf66642998998d5ba97ce
C:\Windows\LTSvc\LTSVC.exe Connectwise, LLC
C:\Users\*\Downloads\ConnectWiseControl.Client.exe Connectwise, LLC

Notes:

  • Connectwise Automate / Labtech is a paid tool, whereas Connectwise Control / Screenconnect has a free version.

  • I've seen the former abused when an MSP is breached, whereas the latter is frequently used to blend in with existing tooling.

  • You can install multiple Screenconnect instances on one device, notated by the GUID after the software name shown in appwiz.cpl.

  • Different ScreenConnect instantces can be also differentiated by the domain name the ScreenConnect binary reaches out to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment