Use powershell script for system discovery

/static/assets/windows-logo.svg
Installs a powershell script that acts as a Stage-2 payload from the APT29 Modified Sysinternals Toolset. The script is launched to perform a series of WMI discovery functions and local/domain group discovery.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)