Files
splunk-security_content/lookups/csv/malicious_powershell_strings.csv

29 KiB

1commandtoolkitmatchdescription
2*Invoke-BitlockerCheck*PrivescCheckInvoke-BitlockerCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
3*Invoke-CredentialGuardCheck*PrivescCheckInvoke-CredentialGuardCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
4*Invoke-DllHijackingCheck*PrivescCheckInvoke-DllHijackingCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
5*Invoke-DriverCoInstallersCheck*PrivescCheckInvoke-DriverCoInstallersCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
6*Invoke-GPPPasswordCheck*PrivescCheckInvoke-GPPPasswordCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
7*Invoke-HardenedUNCPathCheck*PrivescCheckInvoke-HardenedUNCPathCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
8*Invoke-HijackableDllsCheck*PrivescCheckInvoke-HijackableDllsCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
9*Invoke-HotFixCheck*PrivescCheckInvoke-HotFixCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
10*Invoke-PrintNightmareCheck*PrivescCheckInvoke-PrintNightmareCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
11*Invoke-RegistryAlwaysInstallElevatedCheck*PrivescCheckInvoke-RegistryAlwaysInstallElevatedCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
12*Invoke-SccmCacheFolderCheck -Info*PrivescCheckInvoke-SccmCacheFolderCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
13*Invoke-SCMPermissionsCheck*PrivescCheckInvoke-SCMPermissionsCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
14*Invoke-SensitiveHiveFileAccessCheck*PrivescCheckInvoke-SensitiveHiveFileAccessCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
15*Invoke-SensitiveHiveShadowCopyCheck*PrivescCheckInvoke-SensitiveHiveShadowCopyCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
16*Invoke-ServicesUnquotedPathCheck*PrivescCheckInvoke-ServicesUnquotedPathCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
17*Invoke-UnattendFilesCheck*PrivescCheckInvoke-UnattendFilesCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
18*Invoke-WinlogonCheck*PrivescCheckInvoke-WinlogonCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
19*Invoke-WsusConfigCheck*PrivescCheckInvoke-WsusConfigCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
20*[mimikittenz.MemProcInspector]::*Mimikittenz[mimikittenz.MemProcInspector]::post-exploitation powershell tool that utilizes the Windows function ReadProcessMemory() in order to extract plain-text passwords from various target processes.
21*Add-Exfiltration*NishangAdd-ExfiltrationAdd data exfiltration capability to Gmail, Pastebin, a web server, and DNS to any script.
22*Add-Persistence*PowerSploitAdd-PersistenceAdd persistence capabilities to a script.
23*Add-RegBackdoor*NishangAdd-RegBackdoorA backdoor which uses well known Debugger trick to execute payload with Sticky keys and Utilman (Windows key + U).
24*Add-ScrnSaveBackdoor*NishangAdd-ScrnSaveBackdoorA backdoor which can use Windows screen saver for remote command and script execution.
25*Antak*NishangAntakExecute PowerShell scripts in memory, run commands, and download and upload files using this webshell.
26*Connect-PowerCat*PowerCatConnect-PowerCatConnects a client to a listener/server.
27*DNS_TXT_Pwnage*NishangDNS_TXT_PwnageA backdoor which can receive commands and PowerShell scripts from DNS TXT queries, execute them on a target, and be remotely controlled using the queries.
28*Download_Execute*NishangDownload_ExecuteDownload an executable in text format, convert it to an executable, and execute.
29*Download-Execute-PS*NishangDownload-Execute-PSDownload and execute a PowerShell script in memory.
30*Enable-DuplicateToken*NishangEnable-DuplicateTokenWhen SYSTEM privileges are required.
31*Execute-Command-MSSQL*NishangExecute-Command-MSSQLRun PowerShell commands, native commands, or SQL commands on a MSSQL Server with sufficient privileges.
32*Execute-DNSTXT-Code*NishangExecute-DNSTXT-CodeExecute shellcode in memory using DNS TXT queries.
33*Execute-OnTime*NishangExecute-OnTimeA backdoor which can execute PowerShell scripts at a given time on a target.
34*Find-AVSignature*PowerSploitFind-AVSignatureLocates single Byte AV signatures utilizing the same method as DSplit from class101.
35*FireBuster*NishangFireBusterA pair of scripts for egress testing
36*FireListener*NishangFireListenerA pair of scripts for egress testing
37*Get-GPPAutologon*PowerSploitGet-GPPAutologonRetrieves autologon username and password from registry.xml if pushed through Group Policy Preferences.
38*Get-GPPPassword*PowerSploitGet-GPPPasswordRetrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.
39*Get-HttpStatus*PowerSploitGet-HttpStatusReturns the HTTP Status Codes and full URL for specified paths when provided with a dictionary file.
40*Get-Keystrokes*PowerSploitGet-KeystrokesLogs keys pressed, time and the active window.
41*Get-LSASecret*NishangGet-LSASecretGet LSA Secret from a target.
42*Get-MicrophoneAudio*PowerSploitGet-MicrophoneAudioRecords audio from system microphone and saves to disk
43*Get-PassHashes*NishangGet-PassHashesGet password hashes from a target.
44*Get-PassHints*NishangGet-PassHintsGet password hints of Windows users from a target.
45*Get-SecurityPackages*PowerSploitGet-SecurityPackagesEnumerates all loaded security packages (SSPs).
46*Get-TimedScreenshot*PowerSploitGet-TimedScreenshotA function that takes screenshots at a regular interval and saves them to a folder.
47*Get-VaultCredential*PowerSploitGet-VaultCredentialDisplays Windows vault credential objects including cleartext web credentials.
48*Get-VolumeShadowCopy*PowerSploitGet-VolumeShadowCopyLists the device paths of all local volume shadow copies.
49*Get-WLAN-Keys*NishangGet-WLAN-KeysGet WLAN keys in plain text from a target.
50*GetUserSPNS*MultipleGetUserSPNSEnumerates SPNs for a given AD user
51*Gupt-Backdoor*NishangGupt-BackdoorA backdoor which can receive commands and scripts from a WLAN SSID without connecting to it.
52*HTTP-Backdoor*NishangHTTP-BackdoorA backdoor which can receive instructions from third party websites and execute PowerShell scripts in memory.
53*Install-SSP*PowerSploitInstall-SSPInstalls a security support provider (SSP) dll.
54*Invoke-ADSBackdoor*Alternate Datastreams BackdoorInvoke-ADSBackdoorThis script will obtain persistence on a Windows 7+ machine under both Standard and Administrative accounts by using two Alternate Data Streams.
55*Invoke-AmsiBypass*NishangInvoke-AmsiBypassImplementation of publicly known methods to bypass/avoid AMSI.
56*Invoke-BadPotato*PowerSharpPackInvoke-BadPotatoitm4ns Printspoofer in C#.
57*Invoke-BetterSafetyKatz*PowerSharpPackInvoke-BetterSafetyKatzFork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime patches signatures and uses SharpSploit DInvoke to PE-Load into memory.
58*Invoke-BloodHound*MultipleInvoke-BloodHoundEnumerates AD, powershell version
59*Invoke-CallbackIEX*PowerBreachInvoke-CallbackIEXThe location for the various callback mechanisms. Calls back and executes encoded payload.
60*Invoke-Carbuncle*PowerSharpPackInvoke-CarbuncleTool for interacting with outlook interop during red team engagements
61*Invoke-Certify*PowerSharpPackInvoke-CertifyActive Directory certificate abuse.
62*Invoke-CredentialInjection*PowerSploitInvoke-CredentialInjectionCreate logons with clear-text credentials without triggering a suspicious Event ID 4648 (Explicit Credential Logon).
63*Invoke-CredentialsPhish*NishangInvoke-CredentialsPhishTrick a user into giving credentials in plain text.
64*Invoke-DAFT*PowerSharpPackInvoke-DAFTDAFT: Database Audit Framework & Toolkit
65*Invoke-DeadUserBackdoor*PowerBreachInvoke-DeadUserBackdoorLooks for dead user and calls back when does not exist. Admin-No, Firewall-No
66*Invoke-DinvokeKatz*PowerSharpPackInvoke-DinvokeKatzSharpSploit DInvoke to PE-Load into memory
67*Invoke-DllInjection*PowerSploitInvoke-DllInjectionInjects a Dll into the process ID of your choosing.
68*Invoke-EventLogBackdoor*PowerBreachInvoke-EventLogBackdoorMonitors for failed RDP login attempts. Admin-Yes, Firewall-No, Auditing Reqd
69*Invoke-Eyewitness*PowerSharpPackInvoke-EyewitnessEyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
70*Invoke-FakeLogonScreen*PowerSharpPackInvoke-FakeLogonScreenFake Windows logon screen to steal passwords
71*Invoke-Farmer*PowerSharpPackInvoke-FarmerFarmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.
72*Invoke-Get-RBCD-Threaded*PowerSharpPackInvoke-Get-RBCD-ThreadedTool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments
73*Invoke-Gopher*PowerSharpPackInvoke-GopherC# tool to discover low hanging fruits.
74*Invoke-Grouper*PowerSharpPackInvoke-GrouperFind vulnerabilities in AD Group Policy
75*Invoke-HandleKatz*PowerSharpPackInvoke-HandleKatzPIC lsass dumper using cloned handles
76*Invoke-HardenedUNCPathCheck*PrivescCheckInvoke-HardenedUNCPathCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
77*Invoke-Interceptor*NishangInvoke-InterceptorA local HTTPS proxy for MITM attacks.
78*Invoke-Internalmonologue*PowerSharpPackInvoke-InternalmonologueInternal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
79*Invoke-Inveigh*PowerSharpPackInvoke-InveighWindows C# LLMNR/mDNS/NBNS/DNS/DHCPv6 spoofer/man-in-the-middle tool
80*Invoke-InveighRelay*MultipleInvoke-InveighRelayWindows C# LLMNR/mDNS/NBNS/DNS/DHCPv6 spoofer/man-in-the-middle tool
81*Invoke-JSRatRegsvr*NishangInvoke-JSRatRegsvrAn interactive PowerShell reverse shell over HTTP using regsvr32.exe.
82*Invoke-JSRatRundll*NishangInvoke-JSRatRundllAn interactive PowerShell reverse shell over HTTP using rundll32.exe.
83*Invoke-Kerberoast*MultipleInvoke-KerberoastEnumerates all users with SPNs and solicits are Kerberos ticket for service
84*Invoke-KrbRelay*PowerSharpPackInvoke-KrbRelayFramework for Kerberos relaying
85*Invoke-LdapSignCheck*PowerSharpPackInvoke-LdapSignCheckC# project to check LDAP signing.
86*Invoke-Lockless*PowerSharpPackInvoke-LocklessLockless allows for the copying of locked files.
87*Invoke-LoopBackdoor*PowerBreachInvoke-LoopBackdoorCallsback on set interval. Admin-No, Firewall-No
88*Invoke-MalSCCM*PowerSharpPackInvoke-MalSCCMThis tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage. To use this tool your current process must have admin rights over the SCCM server. Typically deployments of SCCM will either have the management server and the primary server on the same host, in which case the host returned from the locate command can be used as the primary server.
89*Invoke-Mimikatz*PowerSploitInvoke-MimikatzReflectively loads Mimikatz 2.0 in memory using PowerShell. Can be used to extract sensitive credentials without writing anything to disk. Can be used for any functionality provided with Mimikatz.
90*Invoke-Mimikittenz*NishangInvoke-MimikittenzExtract juicy information from target process (like browsers) memory using regex.
91*Invoke-NanoDump*PowerSharpPackInvoke-NanoDumpDump LSASS like you mean it
92*Invoke-NetworkRelay *NishangInvoke-NetworkRelay Create network relays between computers.
93*Invoke-Nightmare*PrintNightmareInvoke-NightmareUsed to exploit the PrintNightmare vulnerability
94*Invoke-NinjaCopy*PowerSploitInvoke-NinjaCopyCopies a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.
95*Invoke-Obfuscation*Invoke-ObfuscationInvoke-ObfuscationProvides various methods of obfuscating powershell commands
96*Invoke-OxidResolver*PowerSharpPackInvoke-OxidResolverIOXIDResolver from AirBus Security/PingCastle
97*Invoke-P0wnedshell*PowerSharpPackInvoke-P0wnedshellPowerShell Runspace Post Exploitation Toolkit
98*Invoke-P0wnedshellx86*PowerSharpPackInvoke-P0wnedshellx86PowerShell Runspace Post Exploitation Toolkit
99*Invoke-PortBindBackdoor*PowerBreachInvoke-PortBindBackdoorBinds to TCP Port. Admin-No, Firewall-Yes
100*Invoke-PortKnockBackdoor*PowerBreachInvoke-PortKnockBackdoorStarts sniffer looking for trigger. Admin-Yes, Firewall-Yes
101*Invoke-Portscan*PowerSploitInvoke-PortscanDoes a simple port scan using regular sockets, based (pretty) loosely on nmap.
102*Invoke-PoshRatHttp*NishangInvoke-PoshRatHttpReverse interactive PowerShell over HTTP or HTTPS.
103*Invoke-Postdump*PowerSharpPackInvoke-PostdumpAnother tool to perform minidump of LSASS process using few technics to avoid detection.
104*Invoke-PowerShellIcmp*NishangInvoke-PowerShellIcmpAn interactive PowerShell reverse shell over ICMP.
105*Invoke-PowerShellTcp*NishangInvoke-PowerShellTcpAn interactive PowerShell reverse connect or bind shell
106*Invoke-PowerShellTcpOneLine*NishangInvoke-PowerShellTcpOneLineStripped down version of Invoke-PowerShellTcp. Also contains, a skeleton version which could fit in two tweets.
107*Invoke-PowerShellTcpOneLineBind*NishangInvoke-PowerShellTcpOneLineBindBind version of Invoke-PowerShellTcpOneLine.
108*Invoke-PowerShellUdp*NishangInvoke-PowerShellUdpAn interactive PowerShell reverse connect or bind shell over UDP
109*Invoke-PowerShellUdpOneLine*NishangInvoke-PowerShellUdpOneLineStripped down version of Invoke-PowerShellUdp.
110*Invoke-PowerShellWmi*NishangInvoke-PowerShellWmiInteractive PowerShell using WMI.
111*Invoke-PPLDump*PowerSharpPackInvoke-PPLDumpDump the memory of a PPL with a userland exploit
112*Invoke-Psexec*MultipleInvoke-PsexecPowershell version of PSExec
113*Invoke-PsGcat*NishangInvoke-PsGcatSend commands and scripts to specifed Gmail account to be executed by Invoke-PsGcatAgent
114*Invoke-PsGcatAgent*NishangInvoke-PsGcatAgentExecute commands and scripts sent by Invoke-PsGcat.
115*Invoke-PsUACme*NishangInvoke-PsUACmeBypass UAC.
116*Invoke-ReflectivePEInjection*PowerSploitInvoke-ReflectivePEInjectionReflectively loads a Windows PE file (DLL/EXE) in to the powershell process, or reflectively injects a DLL in to a remote process.
117*Invoke-ResolverBackdoor*PowerBreachInvoke-ResolverBackdoorResolves name to decide when to callback. Admin-No, Firewall-No
118*Invoke-ReverseDnsLookup*PowerSploitInvoke-ReverseDnsLookupScans an IP address range for DNS PTR records.
119*Invoke-Rubeus*PowerSharpPackInvoke-RubeusRubeus is a C# toolset for raw Kerberos interaction and abuses.
120*Invoke-SafetyKatz*PowerSharpPackInvoke-SafetyKatzSafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subTee's .NET PE Loader I modified this one again with my own obfuscated Mimikatz Version.
121*Invoke-SauronEye*PowerSharpPackInvoke-SauronEyeSearch tool to find specific files containing specific words, i.e. files containing passwords.
122*Invoke-SccmCacheFolderCheck*PrivescCheckInvoke-SccmCacheFolderCheckPrivescCheck is a tool built in Powershell used to enumerate common Windows configuration issues that can be leveraged for local privilege escalation
123*Invoke-SCShell*PowerSharpPackInvoke-SCShellFileless lateral movement tool that relies on ChangeServiceConfigA to run command.
124*Invoke-Seatbelt*PowerSharpPackInvoke-SeatbeltSeatbelt is a C# project that performs a number of security oriented host-survey safety checks relevant from both offensive and defensive security perspectives.
125*Invoke-SessionGopher*NishangInvoke-SessionGopherIdentify admin jump-boxes and/or computers used to access Unix machines.
126*Invoke-ShadowSpray*PowerSharpPackInvoke-ShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.
127*Invoke-SharpAllowedToAct*PowerSharpPackInvoke-SharpAllowedToActComputer object takeover through Resource-Based Constrained Delegation (msDS-AllowedToActOnBehalfOfOtherIdentity)
128*Invoke-SharpBlock*PowerSharpPackInvoke-SharpBlockA method of bypassing EDR's active projection DLL's by preventing entry point exection.
129*Invoke-SharpBypassUAC*PowerSharpPackInvoke-SharpBypassUACC# tool for UAC bypasses
130*Invoke-SharpChrome*PowerSharpPackInvoke-SharpChromeSharpChrome is a .NET 2.0 CLR project to retrieve data from Google Chrome
131*Invoke-SharpChromium*PowerSharpPackInvoke-SharpChromium.NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins.
132*Invoke-SharpClipboard*PowerSharpPackInvoke-SharpClipboardC# Clipboard Monitor
133*Invoke-SharpCloud*PowerSharpPackInvoke-SharpCloudSimple C# for checking for the existence of credential files related to AWS, Microsoft Azure, and Google Compute.
134*Invoke-SharpDPAPI*PowerSharpPackInvoke-SharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
135*Invoke-SharpDump*PowerSharpPackInvoke-SharpDumpSharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
136*Invoke-SharPersist*PowerSharpPackInvoke-SharPersistWindows persistence toolkit written in C#.
137*Invoke-SharpGPO-RemoteAccessPolicies*PowerSharpPackInvoke-SharpGPO-RemoteAccessPoliciesA C# tool for enumerating remote access policies through group policy.
138*Invoke-SharpGPOAbuse*PowerSharpPackInvoke-SharpGPOAbuseSharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
139*Invoke-SharpHandler*PowerSharpPackInvoke-SharpHandlerThis project reuses open handles to lsass to parse or minidump lsass, therefore you don't need to use your own lsass handle to interact with it.
140*Invoke-SharpHide*PowerSharpPackInvoke-SharpHideTool to create hidden registry keys.
141*Invoke-Sharphound*PowerSharpPackInvoke-SharphoundC# Data Collector for the BloodHound Project
142*Invoke-SharpImpersonation*PowerSharpPackInvoke-SharpImpersonationSharpImpersonation - A User Impersonation tool - via Token or Shellcode injection.
143*Invoke-SharpImpersonationNoSpace*PowerSharpPackInvoke-SharpImpersonationNoSpaceSharpImpersonation - A User Impersonation tool - via Token or Shellcode injection.
144*Invoke-SharpKatz*PowerSharpPackInvoke-SharpKatzC# Port of mimikatz sekurlsa::logonpasswords, sekurlsa::ekeys and lsadump::dcsync commands.
145*Invoke-SharpLdapRelayScan*PowerSharpPackInvoke-SharpLdapRelayScanC# Port of LdapRelayScan
146*Invoke-Sharplocker*PowerSharpPackInvoke-SharplockerSharpLocker helps get current user credentials by popping a fake Windows lock screen, all output is sent to Console which works perfect for Cobalt Strike.
147*Invoke-SharpLoginPrompt*PowerSharpPackInvoke-SharpLoginPromptThis Program creates a login prompt to gather username and password of the current user. This project allows red team to phish username and password of the current user without touching lsass and having adminitrator credentials on the system.
148*Invoke-SharpMove*PowerSharpPackInvoke-SharpMove.NET Project for performing Authenticated Remote Execution.
149*Invoke-SharpPrinter*PowerSharpPackInvoke-SharpPrinterDiscover Printers + check for vulns
150*Invoke-SharpPrintNightmare*PowerSharpPackInvoke-SharpPrintNightmareC# implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
151*Invoke-SharpRDP*PowerSharpPackInvoke-SharpRDPRemote Desktop Protocol .NET Console Application for Authenticated Command Execution.
152*Invoke-SharpSCCM*PowerSharpPackInvoke-SharpSCCMA C# utility for interacting with SCCM
153*Invoke-SharpSecDump*PowerSharpPackInvoke-SharpSecDump.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py.
154*Invoke-Sharpshares*PowerSharpPackInvoke-SharpsharesEnumerate all network shares in the current domain. Also, can resolve names to IP addresses.
155*Invoke-SharpSniper*PowerSharpPackInvoke-SharpSniperFind specific users in active directory via their username and logon IP address
156*Invoke-Sharpsploit_nomimi*PowerSharpPackInvoke-Sharpsploit_nomimiSharpSploit is a .NET post-exploitation library written in C#.
157*Invoke-SharpSploit*PowerSharpPackInvoke-SharpSploitSharpSploit is a .NET post-exploitation library written in C#.
158*Invoke-SharpSpray*PowerSharpPackInvoke-SharpSpraySharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike.
159*Invoke-SharpSSDP*PowerSharpPackInvoke-SharpSSDPSSDP Service Discovery
160*Invoke-SharpStay*PowerSharpPackInvoke-SharpStay.NET project for installing Persistence
161*Invoke-SharpUp*PowerSharpPackInvoke-SharpUpSharpUp is a C# port of various PowerUp functionality.
162*Invoke-Sharpview*PowerSharpPackInvoke-SharpviewC# implementation of harmj0y's PowerView
163*Invoke-SharpWatson*PowerSharpPackInvoke-SharpWatsonEnumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
164*Invoke-Sharpweb*PowerSharpPackInvoke-Sharpweb.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.
165*Invoke-SharpWSUS*PowerSharpPackInvoke-SharpWSUSSharpWSUS is a CSharp tool for lateral movement through WSUS. There is a corresponding blog (https://labs.nettitude.com/blog/introducing-sharpwsus/) which has more detailed information about the tooling, use case and detection.
166*Invoke-Shellcode*PowerSploitInvoke-ShellcodeInjects shellcode into the process ID of your choosing or within PowerShell locally.
167*Invoke-SMBExec*MultipleInvoke-SMBExecProcess execution via SMB
168*Invoke-Snaffler*PowerSharpPackInvoke-SnafflerA tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax ).
169*Invoke-Spoolsample*PowerSharpPackInvoke-SpoolsamplePoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
170*Invoke-SSIDExfil*NishangInvoke-SSIDExfilExfiltrate information like user credentials, using WLAN SSID.
171*Invoke-StandIn*PowerSharpPackInvoke-StandInStandIn is a small .NET35/45 AD post-exploitation toolkit
172*Invoke-StickyNotesExtract*PowerSharpPackInvoke-StickyNotesExtractExtracts data from the Windows Sticky Notes database. Works on Windows 10 Build 1607 and higher. This project doesn't rely on any external dependencies.
173*Invoke-Tater*MultipleInvoke-TaterIf the host is vulnerable to the Hot Potato privilege escalation, will run commands as System, as we will be able to impersonate the SYSTEM account
174*Invoke-Thunderfox*PowerSharpPackInvoke-ThunderfoxRetrieves data (contacts, emails, history, cookies and credentials) from Thunderbird and Firefox.
175*Invoke-TokenManipulation*PowerSploitInvoke-TokenManipulationLists available logon tokens. Creates processes with other users logon tokens, and impersonates logon tokens in the current thread.
176*Invoke-Tokenvator*PowerSharpPackInvoke-TokenvatorA tool to elevate privilege with Windows Tokens
177*Invoke-UrbanBishop*PowerSharpPackInvoke-UrbanBishopCreates a local RW section in UrbanBishop and then maps that section as RX into a remote process. Shellcode loading made easy.
178*Invoke-Whisker*PowerSharpPackInvoke-WhiskerWhisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding Shadow Credentials to the target account.
179*Invoke-winPEAS*PowerSharpPackInvoke-winPEASCheck the Local Windows Privilege Escalation checklist from book.hacktricks.xyz
180*Invoke-WireTap*PowerSharpPackInvoke-WireTap.NET 4.0 Project to interact with video, audio and keyboard hardware.
181*Invoke-WmiCommand*PowerSploitInvoke-WmiCommandExecutes a PowerShell ScriptBlock on a target computer and returns its formatted output using WMI as a C2 channel.
182*Invoke-WMIExec*MultipleInvoke-WMIExecProcess execution via WMI
183*kerberos::*Multiplekerberos::Mimikatz exploit commands
184*Keylogger*NishangKeyloggerLog keystrokes from a target.
185*lsadump::*Multiplelsadump::Mimikatz exploit commands
186*Mayhem*PowerSploitMayhemCause general mayhem with PowerShell.
187*Mount-VolumeShadowCopy*PowerSploitMount-VolumeShadowCopyMounts a volume shadow copy.
188*New-ElevatedPersistenceOption*PowerSploitNew-ElevatedPersistenceOptionConfigure elevated persistence options for the Add-Persistence function.
189*New-UserPersistenceOption*PowerSploitNew-UserPersistenceOptionConfigure user-level persistence options for the Add-Persistence function.
190*New-VolumeShadowCopy*PowerSploitNew-VolumeShadowCopyCreates a new volume shadow copy.
191*Out-CompressedDll*PowerSploitOut-CompressedDllCompresses, Base-64 encodes, and outputs generated code to load a managed dll in memory.
192*Out-EncodedCommand*PowerSploitOut-EncodedCommandCompresses, Base-64 encodes, and generates command-line output for a PowerShell payload script.
193*Out-EncryptedScript*PowerSploitOut-EncryptedScriptEncrypts text files/scripts.
194*Out-Minidump*PowerSploitOut-MinidumpGenerates a full-memory minidump of a process.
195*Out-RundllCommand*NishangOut-RundllCommandExecute PowerShell commands and scripts or a reverse PowerShell session using rundll32.exe.
196*Powerpreter*NishangPowerpreterPowerpreter
197*PowerUp*PowerSploitPowerUpClearing house of common privilege escalation checks, along with some weaponization vectors.
198*PowerView*PowerSploitPowerViewPowerView is series of functions that performs network and Windows domain enumeration and exploitation.
199*Remove-ADSBackdoor*Alternate Datastreams BackdoorRemove-ADSBackdoorThis script will obtain persistence on a Windows 7+ machine under both Standard and Administrative accounts by using two Alternate Data Streams.
200*Remove-Comment*PowerSploitRemove-CommentStrips comments and extra whitespace from a script.
201*Remove-Persistence*NishangRemove-PersistenceRemote persistence added by the Add-Persistence script.
202*Remove-PoshRat*NishangRemove-PoshRatClean the system after using Invoke-PoshRatHttps
203*Remove-Update*NishangRemove-UpdateIntroduce vulnerabilities by removing patches.
204*Remove-VolumeShadowCopy*PowerSploitRemove-VolumeShadowCopyDeletes a volume shadow copy.
205*Run-EXEonRemote*NishangRun-EXEonRemoteCopy and execute an executable on multiple machines.
206*sekurlsa::*Multiplesekurlsa::Mimikatz exploit commands
207*Set-CriticalProcess*PowerSploitSet-CriticalProcessCauses your machine to blue screen upon exiting PowerShell.
208*Set-DCShadowPermissions*NishangSet-DCShadowPermissionsModify AD objects to provide minimal permissions required for DCShadow.
209*Set-MasterBootRecord*PowerSploitSet-MasterBootRecordProof of concept code that overwrites the master boot record with the message of your choice.
210*Set-RemotePSRemoting*NishangSet-RemotePSRemotingModify permissions of PowerShell remoting to allow access to a non-admin user.
211*Set-RemoteWMI*NishangSet-RemoteWMIModify permissions of DCOM and WMI namespaces to allow access to a non-admin user.
212*Sherlock*MultipleSherlockPowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities
213*Show-TargetScreen*NishangShow-TargetScreenConnect back and Stream target screen using MJPEG.
214*Start-PowerCat*PowerCatStart-PowerCatStarts a listener/server.