A locked screen doesn't mean there's not an active session; most people just lock their screen and walk away, they don't usually log out. If the machine is on and you have physical port access, you can get into it, past the lock screen, and into an active session with a variety of attacks. Even if you can't get into it, there's always cold boot attacks. And even without these attacks, you can leave the ducky and code to execute the next time the machine is unlocked and a user present.
If you're going to get close enough to the machine to interface with it I would rather use PoisonTap[1] which tricks the machine to route everything through the poisontap and add in semi-persistence with the use of cached backdoors.
Some will say 'Well what if the corporation uses a webproxy like bluecoat.' There is a simple work around you go buy a domain that is already categorized as something like 'Business/Economy' which most corporations allow.
8 comments
[ 2.9 ms ] story [ 21.5 ms ] thread(1) https://msdn.microsoft.com/en-us/library/windows/desktop/bb7...
Some will say 'Well what if the corporation uses a webproxy like bluecoat.' There is a simple work around you go buy a domain that is already categorized as something like 'Business/Economy' which most corporations allow.
[1]https://samy.pl/poisontap/
https://www.mdsec.co.uk/2017/07/categorisation-is-not-a-secu...