5e95ba3d40
Abuse of "Windows Problem Steps Recorder" to spy on a user's activities. |
||
---|---|---|
.. | ||
README.md | ||
payload.ps1 | ||
payload.txt |
README.md
"Microsoft Windows" Problem Steps Recorder
- Title: Win_ProblemStepsRecorder
- Author: TW-D
- Version: 1.0
- Target: Microsoft Windows
- Category: Credentials
Description
- Partially avoids "PowerShell Script Block Logging".
- Closing of all windows.
- Hide "PowerShell" window.
- Abuse of "Windows Problem Steps Recorder" to spy on a user's activities.
- Writes the file system cache to disk.
- Safely eject.
Configuration
From "payload.txt" change the values of the following constants :
######## INITIALIZATION ########
readonly BB_LABEL="BashBunny"
readonly RECORDER_TIME=300