Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force
- Set-ExecutionPolicy Bypass -Force -ErrorAction Ignore
- # CurrentUser Bypass
- # Set-ExecutionPolicy -Scope CurrentUser Bypass -Force -ErrorAction Ignore
- # Set-MpPreference -DisableRealtimeMonitoring $true -Force -ErrorAction Ignore
- Add-MpPreference -ExclusionPath C:\AtomicRedTeam\
- Install-Module powershell-yaml -Force -ErrorAction Ignore
- Write-Host "INSTALL EXECUTION FRAMEWORK ONLY" -fore green
- IEX (IWR 'https://raw.githubusercontent.com/redcanaryco/invoke-atomicredteam/master/install-atomicredteam.ps1' -UseBasicParsing);
- Install-AtomicRedTeam -Force -ErrorAction Ignore
- Write-Host "Install Execution Framework and Atomics Folder" -fore green
- IEX (IWR 'https://raw.githubusercontent.com/redcanaryco/invoke-atomicredteam/master/install-atomicredteam.ps1' -UseBasicParsing);
- Install-AtomicRedTeam -getAtomics -Force -ErrorAction Ignore
- Write-Host "Import-Module Invoke-AtomicRedTeam.PSD1" -fore green
- Import-Module "C:\AtomicRedTeam\invoke-atomicredteam\Invoke-AtomicRedTeam.psd1" -Force -ErrorAction Ignore
- set-location C:\AtomicRedTeam\atomics
- #
- # Write-Host "Setup $PROFILE to persist PSD" -fore green
- # Ensure module is in profile to use execution framework
- # New-Item -ItemType Directory (split-path $profile) -Force
- # Set-Content $profile 'Import-Module "C:\AtomicRedTeam\invoke-atomicredteam\Invoke-AtomicRedTeam.psd1" -Force'
- #
- # Default Accounts is T1078.001 -Enable Guest Account
- Invoke-AtomicTest T1078.001 -ShowDetailsBrief
- #
- # Write-EventLog Event to warn we are hear
- Write-EventLog -LogName "Application" -Source "SecurityCenter" -EventID 1337 -EntryType Information -Message "AtomicRedTeam was Invoked." -Category 1 -RawData 10,20
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement