Skip to content

itm4n's Priv Esc Check Script which has been decoded and unzipped. Why? Dont want to blindly run PowerShell Scripts on a Corporate Network do we?

Notifications You must be signed in to change notification settings

deeexcee-io/PrivEscCheck-Decoded

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

11 Commits
Β 
Β 
Β 
Β 

Repository files navigation

PrivEscCheck-Decoded

itm4n's Priv Esc Check Script which has been decoded and unzipped. Why? Dont want to blindly run Obfuscated PowerShell Scripts from GitHub on a Corporate Network do we?

Original Script - https://github.com/itm4n/PrivescCheck

Awesome Script πŸ‘©β€πŸš€

For UK Pentesters, if running Build Reviews for ITHCs, this used alongside Nessus or whatever you are using is awesome.

Great Report Layout aswell.

Is the code secure to run? πŸ”’

Im quite confident it is, I've looked through the code and also put it through https://app.any.run/

itm4n is quite well known in the industry with some great blogs etc - https://itm4n.github.io/. The repo is maintained and has over 2k stars.

image

app.any.run results πŸ’€

It has no external connections or http requests

image

And the only potentially "malicious" activity is some registry queries and powershell version downgrade

image

Will this be updated?

If I notice itm4n has updated his script, ill update this one. - #EDIT This is a lie, I dont have time

About

itm4n's Priv Esc Check Script which has been decoded and unzipped. Why? Dont want to blindly run PowerShell Scripts on a Corporate Network do we?

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published