Installs a powershell script that acts as a Stage-2 payload from the APT29 Modified Sysinternals Toolset. The script is
launched to perform a series of WMI discovery functions and local/domain group discovery.
View Command
To view this TTPs command, you must be logged in with a professional or enterprise license.