使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。
-
Updated
Jan 18, 2022 - PowerShell
使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。
📚 Large base of PowerShell notes in Russian language (Сheat Sheet & Documentation).
PowerShellUtilities provides various utility commandlets.
Invoke-KleptoKitty - Deploys Payloads and collects credentials
PowerEvents is a PowerShell module that assists in the registration of WMI permanent event subscriptions.
PowerShell Module for managing the MEMCM client
This PowerShell module contains functions for creating and managing WMI Namespaces, Classes and Instances.
Remote Shadow Administrator (GUI form for remote connect to users)
Asynchronous Remote Evidence Retrieval for rapid network-wide threat hunting
This is a collection of all my scripts over a 13+ year time period. Languages: Bash/sh, HTML, JS, SQL, Perl, PHP, Python, PowerShell, CMD(Batch), WMI, Wsh, Docker/docker-compose.yml conf, Nginx (.conf)
This project contains a Powershell module for managing and automating the configuration of an EMC SourceOne environment.
REST API and Web server based on .NET HttpListener and backend PowerShell Core for Windows remote managment via Web browser or curl from Linux
Wrote this for an Enterprise environment that has both Windows 7 and WIndows 10 Computers. It works (atm) for both. Something quick and dirty if I needed to replace a remote client, and wanted to get a list of the installed software.
Drive backup script in PowerShell with Shadow Copy support. Optional Jenkins project included.
Release source code is on BitBucket. Current devel source is on Moviri GH org.
Nothing Special About It
Fetch and print key Windows system info
ProcessBouncer is a simple but effective powershell-based tool for blocking malware with a process-based approach. ProcessBouncer is not comparable to a full-fledged anti virus product but it can act as an additional line of defense.
Add a description, image, and links to the wmi topic page so that developers can more easily learn about it.
To associate your repository with the wmi topic, visit your repo's landing page and select "manage topics."