Hackers make FAKE notifications

Hackers make FAKE notifications

🎙 John Hammond 👥 2.2M 📅 April 7, 2026 ⏱ 22 min 👁 48K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

toast notificationAUMIDPowerShellsocial engineeringWindows security

Summary

In this video, John Hammond demonstrates how attackers can create convincing fake Windows toast notifications using PowerShell. He explains how to enumerate installed applications’ AUMIDs from the registry, then uses PowerShell with WinRT to craft and display notifications that appear to come from legitimate apps like Microsoft Edge or Windows Defender. He shows how to add buttons that trigger actions, such as opening a malicious URL or launching a custom protocol handler for code execution. The video also covers customization options like images, input fields, and progress bars. Hammond credits prior research by brmk and iPurple team, and provides links to Microsoft documentation and tools like BurntToast. He emphasizes that this technique is useful for social engineering and phishing, but notes that it requires initial access. The video includes a sponsor segment for Varonis.

134 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, actionable information for cybersecurity professionals and enthusiasts. It demonstrates a realistic attack vector that could be used in phishing campaigns, and the step-by-step tutorial is clear and well-explained. The argumentation is solid, as Hammond builds on existing research and official documentation, and he also discusses detection opportunities, such as ETW and Sysmon. The inclusion of a proof-of-concept for code execution via custom protocol handlers adds depth. However, the video does not deeply analyze the broader implications or mitigations beyond basic detection, and the sponsor segment interrupts the flow.

101 words

Title / Content Match

The title accurately reflects the content, as the video demonstrates how hackers can create fake notifications on Windows.

Quality & Reliability

8/10

The video is a practical tutorial demonstrating how to create fake Windows toast notifications using PowerShell. It is based on prior research by brmk and iPurple team, and references official Microsoft documentation. The technical content is accurate and reproducible, with clear explanations. However, the video includes a sponsor segment and some subjective commentary, but the core information is reliable.

Key Moments

Cited Sources

Concurring Sources

External References

Contribution & Novelties

The video provides a practical, step-by-step demonstration of creating fake Windows toast notifications, which is a novel and relevant attack vector for social engineering. It builds on existing research and adds a proof-of-concept for code execution via custom protocol handlers. The video also highlights detection opportunities, which is valuable for defenders.

Pour aller plus loin :

80 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level. The video is well-balanced, providing both theoretical and practical aspects, but the technical depth is not extremely advanced, making it accessible to a broad audience.

Reliability 8/10

💬 Positif. Sur les 30 commentaires analysés, la majorité exprime de l'intérêt et de l'appréciation pour la démonstration, certains soulèvent des questions sur l'utilité pratique et la détection, mais le ton général est constructif et enthousiaste.