Windows Post Exploitation Cmdlets Execution (PowerShell)

Presence

This section focuses on information gathering about the victim host and the network that it’s attached to.

System

[crayon-6a6187e7bd166025523668/]
shows-all-current-environmental-variables-macos

WMI

[crayon-6a6187e7bd16d494659125/]

Networking

[crayon-6a6187e7bd170061679766/]

Users

[crayon-6a6187e7bd173694239740/]

Configs

[crayon-6a6187e7bd175527311211/]

Finding important files

[crayon-6a6187e7bd177272960896/]

Files to pull

[crayon-6a6187e7bd179018296205/]

Remote system access

[crayon-6a6187e7bd17b552091447/]

Software

[crayon-6a6187e7bd17d134827323/]

Auto­Start directories

[crayon-6a6187e7bd17f912064747/]


Persistance

This section focuses on gaining a foothold to re­gain, or re­obtain access to a system through means of authentication, backdoors, etc..

Download

[crayon-6a6187e7bd181889200139/]

Compress or expand ZIP archive

[crayon-6a6187e7bd182809587790/]

Reg command exit

[crayon-6a6187e7bd184751925432/]

Deleting logs

[crayon-6a6187e7bd186808391336/]

Uninstalling software «Antivirus»

[crayon-6a6187e7bd188382655929/]

Invasive or altering commands

[crayon-6a6187e7bd18a978658941/]