Skip to content

Files

Latest commit

0f6776d · Apr 19, 2018

History

History
29 lines (18 loc) · 540 Bytes

Powershell.md

File metadata and controls

29 lines (18 loc) · 540 Bytes

Powershell.exe

  • Functions: Execute, Read ADS
powershell -ep bypass - < c:\temp:ttt    

Acknowledgements:

  • Moriarty - @Moriarty_Meng

Code sample:

Resources:

Full path:

C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Notes: Needs some more examples.... A looooooot can be done with Powershell. It is like the top of the LOLBin chain.... :-)