Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- git clone https://github.com/olafhartong/sysmon-modular
- cd sysmon-modular
- wget https://download.sysinternals.com/files/Sysmon.zip
- # wget https://live.sysinternals.com/Sysmon.exe
- Set-ExecutionPolicy -Scope CurrentUser Bypass
- . .\Merge-SysmonXml.ps1
- Merge-AllSysmonXml -Path ( Get-ChildItem â[0-9]*\*.xmlâ) -AsString | Out-File sysmonconfig.xml
- ./Sysmon.exe -accepteula -i sysmonconfig.xml
- #Go Open EventViewer
- #DEMO
- #Enable Guest
- Invoke-AtomicTest T1078.001 -ShowDetailsBrief
- Invoke-AtomicTest T1078.001 -ShowDetails
- Invoke-AtomicTest T1078.001 -GetPrereqs
- Invoke-AtomicTest T1078.001
- Invoke-AtomicTest T1078.001 -Cleanup
- #Use Windows Defender to download any file we want
- Invoke-AtomicTest T1105 -TestNumbers 13 -ShowDetailsBrief
- Invoke-AtomicTest T1105 -TestNumbers 13 -ShowDetails
- Invoke-AtomicTest T1105 -TestNumbers 13 -CheckPrereqs
- Invoke-AtomicTest T1105 -TestNumbers 13 -PromptForInputArgs
- ls $env:temp | findstr "MpCmdRun.log"
- ls $env:temp | findstr "Atomic"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement