last-byte / PersistenceSniper

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
Other
1.83k stars 180 forks source link

Authenticode signature #4

Closed last-byte closed 1 year ago

last-byte commented 1 year ago

Added better checks, @RiccardoAncarani implemented some new properties in the custom object that allow the user to check if the binary used is a builtin one or if it's a lolbin. Also, Windows Services persistence check has been implemented.