Pillaging
Aplicaciones instaladas
Identifying Common Applications
C:\>dir "C:\Program Files"Get Installed Programs via PowerShell & Registry Keys
$INSTALLED = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, InstallLocation
$INSTALLED += Get-ItemProperty HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, InstallLocation
$INSTALLED | ?{ $_.DisplayName -ne $null } | sort-object -Property DisplayName -Unique | Format-Table -AutoSizeAbusing Cookies to Get Access to IM (instant messaging) Clients
Copy Firefox Cookies Database
copy $env:APPDATA\Mozilla\Firefox\Profiles\*.default-release\cookies.sqlite .Extract Slack Cookie from Firefox Cookies Database
PowerShell Script - Invoke-SharpChromium
Copy Cookies to SharpChromium Expected Location
Invoke-SharpChromium Cookies Extraction
Clipboard
Monitor the Clipboard with PowerShell
Capture Credentials from the Clipboard with Invoke-ClipboardLogger
Roles and Services
Attacking Backup Servers
restic - Initialize Backup Directory
restic - Back up a Directory
restic - Back up a Directory with VSS
restic - Check Backups Saved in a Repository
restic - Restore a Backup with ID
Last updated