Windows Post Exploitation Cmdlets Execution (PowerShell)
Presence
This section focuses on information gathering about the victim host and the network that it’s attached to.
System
[crayon-6a9d57434caf4063635166/]

WMI
[crayon-6a9d57434cafb134233361/]
Networking
[crayon-6a9d57434cafd498833490/]
Users
[crayon-6a9d57434cb05966691341/]
Configs
[crayon-6a9d57434cb09144479806/]
Finding important files
[crayon-6a9d57434cb0a175541823/]
Files to pull
[crayon-6a9d57434cb0c502239793/]
Remote system access
[crayon-6a9d57434cb0d681715005/]
Software
[crayon-6a9d57434cb0f485394055/]
AutoStart directories
[crayon-6a9d57434cb12893228303/]
Persistance
This section focuses on gaining a foothold to regain, or reobtain access to a system through means of authentication, backdoors, etc..
Download
[crayon-6a9d57434cb14832340126/]
Compress or expand ZIP archive
[crayon-6a9d57434cb15129419320/]
Reg command exit
[crayon-6a9d57434cb17753808099/]
Deleting logs
[crayon-6a9d57434cb18831980954/]
Uninstalling software «Antivirus»
[crayon-6a9d57434cb1a837729478/]
Invasive or altering commands
[crayon-6a9d57434cb1b594928664/]