You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
*Execute-OnTime*,Nishang,Execute-OnTime,A backdoor which can execute PowerShell scripts at a given time on a target.,,,
69
69
*Gupt-Backdoor*,Nishang,Gupt-Backdoor,A backdoor which can receive commands and scripts from a WLAN SSID without connecting to it.,,,
70
70
*Add-ScrnSaveBackdoor*,Nishang,Add-ScrnSaveBackdoor,A backdoor which can use Windows screen saver for remote command and script execution.,,,
71
-
*Invoke-ADSBackdoor*,Nishang,Invoke-ADSBackdoor,A backdoor which can use alternate data streams and Windows Registry to achieve persistence.,,,
72
71
*Add-RegBackdoor*,Nishang,Add-RegBackdoor,A backdoor which uses well known Debugger trick to execute payload with Sticky keys and Utilman (Windows key + U).,,,
73
72
*Set-RemoteWMI*,Nishang,Set-RemoteWMI,Modify permissions of DCOM and WMI namespaces to allow access to a non-admin user.,,,
74
73
*Set-RemotePSRemoting*,Nishang,Set-RemotePSRemoting,Modify permissions of PowerShell remoting to allow access to a non-admin user.,,,
*Invoke-PowerShellTcpOneLineBind*,Nishang,Invoke-PowerShellTcpOneLineBind,Bind version of Invoke-PowerShellTcpOneLine.,,,
107
104
*Invoke-PowerShellUdp*,Nishang,Invoke-PowerShellUdp,An interactive PowerShell reverse connect or bind shell over UDP,,,
108
105
*Invoke-PowerShellUdpOneLine*,Nishang,Invoke-PowerShellUdpOneLine,Stripped down version of Invoke-PowerShellUdp.,,,
109
-
*Invoke-PoshRatHttps*,Nishang,Invoke-PoshRatHttps,Reverse interactive PowerShell over HTTPS.,,,
110
-
*Invoke-PoshRatHttp*,Nishang,Invoke-PoshRatHttp,Reverse interactive PowerShell over HTTP.,,,
106
+
*Invoke-PoshRatHttp*,Nishang,Invoke-PoshRatHttp,Reverse interactive PowerShell over HTTP or HTTPS.,,,
111
107
*Remove-PoshRat*,Nishang,Remove-PoshRat,Clean the system after using Invoke-PoshRatHttps,,,
112
108
*Invoke-PowerShellWmi*,Nishang,Invoke-PowerShellWmi,Interactive PowerShell using WMI.,,,
113
109
*Invoke-PowerShellIcmp*,Nishang,Invoke-PowerShellIcmp,An interactive PowerShell reverse shell over ICMP.,,,
114
110
*Invoke-JSRatRundll*,Nishang,Invoke-JSRatRundll,An interactive PowerShell reverse shell over HTTP using rundll32.exe.,,,
115
111
*Invoke-JSRatRegsvr*,Nishang,Invoke-JSRatRegsvr,An interactive PowerShell reverse shell over HTTP using regsvr32.exe.,,,
116
112
*Add-Exfiltration*,Nishang,Add-Exfiltration,"Add data exfiltration capability to Gmail, Pastebin, a web server, and DNS to any script.",,,
117
-
*Add-Persistence*,Nishang,Add-Persistence,Add reboot persistence capability to a script.,,,
118
113
*Remove-Persistence*,Nishang,Remove-Persistence,Remote persistence added by the Add-Persistence script.,,,
119
114
*Invoke-BadPotato*,PowerSharpPack,Invoke-BadPotato,itm4ns Printspoofer in C#.,,,
120
115
*Invoke-BetterSafetyKatz*,PowerSharpPack,Invoke-BetterSafetyKatz,"Fork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime patches signatures and uses SharpSploit DInvoke to PE-Load into memory.",,,
*Invoke-UrbanBishop*,PowerSharpPack,Invoke-UrbanBishop,Creates a local RW section in UrbanBishop and then maps that section as RX into a remote process. Shellcode loading made easy.,,,
196
191
*Invoke-Whisker*,PowerSharpPack,Invoke-Whisker,"Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding Shadow Credentials to the target account.",,,
197
192
*Invoke-WireTap*,PowerSharpPack,Invoke-WireTap,".NET 4.0 Project to interact with video, audio and keyboard hardware.",,,
198
-
*Invoke-winPEAS*,PowerSharpPack,Invoke-winPEAS,Check the Local Windows Privilege Escalation checklist from book.hacktricks.xyz,,,
193
+
*Invoke-winPEAS*,PowerSharpPack,Invoke-winPEAS,Check the Local Windows Privilege Escalation checklist from book.hacktricks.xyz,,,
0 commit comments