Use powershell script for system discovery

Installs a powershell script that acts as a Stage-2 payload from the APT29 Modified Sysinternals Toolset. The script is launched to perform a series of WMI discovery functions and local/domain group discovery.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)