THREATOPS
THREAT OPSThreat News › Weaponizing Windows Updates with NotWSUSpicious

Weaponizing Windows Updates with NotWSUSpicious

medspecteropsPublished 2026-08-05

<p class="wp-block-paragraph"><em><strong>TL;DR</strong>: <code>NotWSUSpicious</code> is a tool repo to aid in creating custom updates after gaining access to a WSUS database server. The <code>Turning Enterprise Update Servers Into Backdoor Factories (0_o)</code> series covers how the database takeover works. This blog strictly covers how to use the tooling.</em></p>

<p class="wp-block-paragrap

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://specterops.io/blog/2026/08/05/weaponizing-windows-updates-with-notwsuspicious/