Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Atomic Chain
- # https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/Indexes/Matrices/windows-matrix.md
- #
- #
- # MalDoc
- Invoke-AtomicTest T1204.002 -TestNumbers 3 -ShowDetailsBrief
- #
- #Enable Guest and add to Administrators group w/RDP capability
- Invoke-AtomicTest T1078.001 -ShowDetailsBrief
- #
- #Add cmd.exe to sethc sticky keys
- Invoke-AtomicTest T1546.008 -PromptForInputArgs
- #
- #Evasion T1070.001 - Clear Windows Event Logs
- Invoke-AtomicTest T1070.001 -TestNumbers 2
- #
- #Dump LSASS
- Invoke-AtomicTest T1003.001 -TestNumbers 2 -CheckPrereqs
- #
- #Look for Network Shares
- Invoke-AtomicTest T1135 -TestNumbers 3 -ShowDetails
- #
- #See what shares are available
- Invoke-AtomicTest T1135 -TestNumbers 4
- #
- #Transfer file or execute C2
- Invoke-AtomicTest T1197 -TestNumbers 2
- #
- #Exfil file
- Invoke-AtomicTest T1020 -ShowDetailsBrief
- #
- #Pass the Hash with Mimikatz
- Invoke-AtomicTest T1550.002 -TestNumbers 1 -PromptForInputArgs
Add Comment
Please, Sign In to add comment