Create a random XOR byte and ingress and XOR a SharpHound payload to a temporary file on the target system. Bypass AMSI, load, and then run the XOR'd SharpHound payload in memory.

Execute this chain

Ingress payload to XOR'd file
Create an XOR byte
Bypass AMSI, load, and run XOR'd SharpHound payload

User-Set Custom Variables

  • payload.uri: 8c53e8a7a9e5a272029f65194540ec2490101a48/SharpHound.exe