praetorian-inc / purple-team-attack-automation

Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs
Other
716 stars 118 forks source link

T1004 - Winlogon Helper DLL #28

Open daniel-infosec opened 5 years ago

daniel-infosec commented 5 years ago

Steps to reproduce

Run the winlogon helper DLL module when the keys don't exist

Expected behavior

Success will be reported but it won't modify the keys as they don't exist

Current behavior

Provide an option to create the keys if they don't exist. If the keys don't exist and it fails to create them, report failure