cribb-it 3904f165d9
Added new payload WIN_PoSH_HKU_RegBackUp (#424)
* Add files via upload

* Update readme.md

* Update payload.txt

* Update readme.md

* Update readme.md

* Update readme.md

* Update readme.md

* Update readme.md

* Add files via upload

* Update readme.md

* Update readme.md

* Add Payload WIN_PoSH_HKU_RegBackUp

* Update readme.md

* Update payload.txt

* Change for admin shell

* Update readme.md

* Update payload.txt

* Update payload.txt

* Update readme.md

* Added payload WIN_PoSH_SaveSecurityHive

Added new payload to exfiltration that saves the HKLM security hive to the bunny
2020-12-14 23:53:42 +00:00
..

Save security hive

  • Author: Cribbit
  • Version: 1.0
  • Target: Windows 10 (Creators Update) (Powershell)
  • Category: Exfiltration
  • Attackmode: HID & STORAGE
  • Props: Ben Clark (RTFM)

Change Log

Version Changes
1.0 Initial release

Description

Uses PowerShell, to run Reg.exe to save security hive to the bunny.

Configuration

Usesful Reg.exe save parameters:

  • /y Force overwriting the existing file without prompt.
  • /reg:32 Specifies the key should be accessed using the 32-bit registry view.
  • /reg:64 Specifies the key should be accessed using the 64-bit registry view.

Colors

Status Color Description
SETUP Magenta solid Setting attack mode
ATTACK Yellow single blink Injecting Powershell script
FINISH Green blink followed by SOLID Script is finished