ladislav-zezula/FileTest: Source code for File Test – Interactive File System Test Tool
Posted by jpluimers on 2024/08/14
Cool tool to peek around in the Windows File System API and fiddle around uncharted territory: [Wayback/Archive] ladislav-zezula/FileTest: Source code for File Test – Interactive File System Test Tool.
It is written in C++ using Visual Studio and has build-instructions in [Wayback/Archive] FileTest/README.md at master · ladislav-zezula/FileTest.
Via [Wayback/Archive] “create reparse point” “query reparse point” – Google Search (which also found [Wayback/Archive] Free File Utilities – Free download and software reviews – CNET Download [Wayback download]) after reading a tweet thread having these highlights:
- [Wayback/Archive] Jonas L on Twitter: “A platonic attack surface: Allright, time to invalidate yet another fair assumption- shadow volumes are read only Create this symlink: …”
- [Wayback/Archive] Jonas L on Twitter: “BONUS: This is also how to bypass any file locks easily, on the new drive you can open the shadow files disregarding them being locked on origin drive”
- [Wayback/Archive] Jonas L on Twitter: “this is interesting in regards to antivirus/edr – why would it ever scan a shadow volume? Its possible to make a polyglot hta/hive and run it from the shadow volume”
The full thread is also at [Wayback/Archive] Thread by @jonasLyk on Thread Reader App.
–jeroen







Leave a comment