Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # 10-08-2021 Jesse Moore dfir-jesseee
- # For NWACC 2021
- #
- # This makes sure you can run scripts on machine
- Set-ExecutionPolicy Bypass -Force -ErrorAction Ignore
- # CurrentUser Bypass
- # Set-ExecutionPolicy -Scope CurrentUser Bypass -Force -ErrorAction Ignore
- #This should disable Defender but doesn't really work well within this script
- # Set-MpPreference -DisableRealtimeMonitoring $true -Force -ErrorAction Ignore
- #Instead of the above I use this to exlude where the Atomics will be with Defender
- Add-MpPreference -ExclusionPath C:\AtomicRedTeam\
- # This installs yaml that is needed for Atomic Red Team atomics to work
- Install-Module powershell-yaml -Force -ErrorAction Ignore
- Write-Host "INSTALL EXECUTION FRAMEWORK ONLY" -fore green
- IEX (IWR 'https://raw.githubusercontent.com/redcanaryco/invoke-atomicredteam/master/install-atomicredteam.ps1' -UseBasicParsing);
- Install-AtomicRedTeam -Force -ErrorAction Ignore
- Write-Host "Install Execution Framework and Atomics Folder" -fore green
- IEX (IWR 'https://raw.githubusercontent.com/redcanaryco/invoke-atomicredteam/master/install-atomicredteam.ps1' -UseBasicParsing);
- Install-AtomicRedTeam -getAtomics -Force -ErrorAction Ignore
- # Write-Host "Setup session $PROFILE to persist PSD" -fore green
- Write-Host "Import-Module Invoke-AtomicRedTeam.PSD1" -fore green
- # Ensure module is in session profile to use execution framework
- $string = 'Import-Module "C:\AtomicRedTeam\invoke-atomicredteam\Invoke-AtomicRedTeam.psd1" -Force; $PSDefaultParameterValues = @{"Invoke-AtomicTest:PathToAtomicsFolder"="C:\AtomicRedTeam\atomics\"}'
- $string | Out-File -FilePath "C:\Users\Administrator\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1" -Append
- # Thsi set the cmd prompt to this location
- set-location C:\AtomicRedTeam\atomics
- # T1070.001-1 Clear Logs
- # This wil run locally
- Invoke-AtomicTest T1070.001 -Testnumber 1-ShowDetailsBrief
- # This is for remotely accessing machine which is identified in $sess variable
- # Invoke-AtomicTest T1070.001 -Session $sess -ShowDetailsBrief
Add Comment
Please, Sign In to add comment