Windows Post Exploitation Cmdlets Execution (PowerShell)

Presence

This section focuses on information gathering about the victim host and the network that it’s attached to.

System

[crayon-6a9d57434caf4063635166/]
shows-all-current-environmental-variables-macos

WMI

[crayon-6a9d57434cafb134233361/]

Networking

[crayon-6a9d57434cafd498833490/]

Users

[crayon-6a9d57434cb05966691341/]

Configs

[crayon-6a9d57434cb09144479806/]

Finding important files

[crayon-6a9d57434cb0a175541823/]

Files to pull

[crayon-6a9d57434cb0c502239793/]

Remote system access

[crayon-6a9d57434cb0d681715005/]

Software

[crayon-6a9d57434cb0f485394055/]

Auto­Start directories

[crayon-6a9d57434cb12893228303/]


Persistance

This section focuses on gaining a foothold to re­gain, or re­obtain access to a system through means of authentication, backdoors, etc..

Download

[crayon-6a9d57434cb14832340126/]

Compress or expand ZIP archive

[crayon-6a9d57434cb15129419320/]

Reg command exit

[crayon-6a9d57434cb17753808099/]

Deleting logs

[crayon-6a9d57434cb18831980954/]

Uninstalling software «Antivirus»

[crayon-6a9d57434cb1a837729478/]

Invasive or altering commands

[crayon-6a9d57434cb1b594928664/]