Windows Post Exploitation Cmdlets Execution (PowerShell)
Presence
This section focuses on information gathering about the victim host and the network that it’s attached to.
System
[crayon-6a6187e7bd166025523668/]

WMI
[crayon-6a6187e7bd16d494659125/]
Networking
[crayon-6a6187e7bd170061679766/]
Users
[crayon-6a6187e7bd173694239740/]
Configs
[crayon-6a6187e7bd175527311211/]
Finding important files
[crayon-6a6187e7bd177272960896/]
Files to pull
[crayon-6a6187e7bd179018296205/]
Remote system access
[crayon-6a6187e7bd17b552091447/]
Software
[crayon-6a6187e7bd17d134827323/]
AutoStart directories
[crayon-6a6187e7bd17f912064747/]
Persistance
This section focuses on gaining a foothold to regain, or reobtain access to a system through means of authentication, backdoors, etc..
Download
[crayon-6a6187e7bd181889200139/]
Compress or expand ZIP archive
[crayon-6a6187e7bd182809587790/]
Reg command exit
[crayon-6a6187e7bd184751925432/]
Deleting logs
[crayon-6a6187e7bd186808391336/]
Uninstalling software «Antivirus»
[crayon-6a6187e7bd188382655929/]
Invasive or altering commands
[crayon-6a6187e7bd18a978658941/]