Added Powershell Execution Example

This commit is contained in:
byt3bl33d3r
2021-03-22 09:04:51 -06:00
parent a22c979a21
commit 49cbc22ef0
3 changed files with 38 additions and 2 deletions
+1 -2
View File
@@ -19,8 +19,7 @@ build: $(BINS) $(DLLS)
rebuild: clean build
clean:
rm -rf bin/*.exe
rm -rf bin/*.dll
rm -rf bin/*.exe bin/*.dll
%.exe : %.nim
nim c $(NIMFLAGS) --app=console --cpu=amd64 --out=bin/$*_64.exe $<
+1
View File
@@ -60,6 +60,7 @@ My experiments in weaponizing [Nim](https://nim-lang.org/) for implant developme
| [shellcode_bin.nim](../master/src/shellcode_bin.nim) | Creates a suspended process and injects shellcode with `VirtualAllocEx`/`CreateRemoteThread`. Also demonstrates the usage of compile time definitions to detect arch, os etc..|
| [shellcode_inline_asm_bin.nim](../master/src/shellcode_inline_asm_bin.nim) | Executes shellcode using inline assembly |
| [syscalls_bin.nim](../master/src/syscalls_bin.nim) | Shows how to make direct system calls |
| [execute_powershell_bin.nim](../master/src/execute_powershell_bin.nim) | Hosts the CLR & executes PowerShell through an un-managed runspace |
| [passfilter_lib.nim](../master/src/passfilter_lib.nim) | Log password changes to a file by (ab)using a password complexity filter |
| [minidump_bin.nim](../master/src/minidump_bin.nim) | Creates a memory dump of lsass using `MiniDumpWriteDump` |
| [http_request_bin.nim](../master/src/http_request_bin.nim) | Demonstrates a couple of ways of making HTTP requests |
+36
View File
@@ -0,0 +1,36 @@
#[
Author: Marcello Salvati, Twitter: @byt3bl33d3r
License: BSD 3-Clause
References:
- https://gist.github.com/cpoDesign/66187c14092ceb559250183abbf9e774
]#
import winim/clr
import sugar
import strformat
var Automation = load("System.Management.Automation")
dump Automation
var RunspaceFactory = Automation.GetType("System.Management.Automation.Runspaces.RunspaceFactory")
dump RunspaceFactory
var runspace = @RunspaceFactory.CreateRunspace()
dump runspace
runspace.Open()
var pipeline = runspace.CreatePipeline()
dump pipeline
pipeline.Commands.AddScript("Get-Process")
pipeline.Commands.Add("Out-String")
var results = pipeline.Invoke()
dump results
echo results.isType()
var t = results.GetType()
dump t
discard readLine(stdin)
echo t.isType()
echo t.unwrap.vt
runspace.Close()