pyppek / motherducker

SecurityLab project
MIT License
0 stars 0 forks source link

Have an overview of all the possible scripts or commands we can execute once backdoor is installed #51

Closed Dilkovak closed 4 years ago

Dwalde commented 4 years ago

Generated a list of Windows Management Instrumentation (WMI) objects we can use to gather (and possibly alter) information from (and on) infected machines, and highlighted some of the more useful properties from each WMI-object. Gathered hardware WMI objects and started analyzing their properties.

Dwalde commented 4 years ago

Hardware WMI objects analyzed. Results are in the "Powershell Command Overview" word document, I have bolded the properties I think we'll find most useful. I'll look into how to make scripts that take properties from different objects and saves them into a hashtable