HandyDandyNotebook
twittergithublinkedin
  • Introduction
  • EDR Evasion
    • Full Remote DLL Unhooking
    • Windows API Without Imports
  • Secret Section
    • THE PowerShell command
  • Threat Emulation
    • Writing a C2 - The Journey
Powered by GitBook
On this page
  1. Secret Section

THE PowerShell command

that THEY don't want you to know about

PreviousWindows API Without ImportsNextWriting a C2 - The Journey

Last updated 2 years ago

powershell -ec ZQBjAGgAbwAgACcAIAAnAAoAJAB0AGUAeAB0ACAAPQAgAAoAQAAnAAoACgAgACAAIAAgAF8AIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIABfAF8AXwAgACAAIAAgACAAIAAgAF8ALgAtAC0ALgAKACAAIAAgACAAXABgAC4AfABcAC4ALgAtAC0ALQAtAC4ALgAuAC0AJwBgACAAIAAgAGAALQAuAF8ALgAtACcAXwAuAC0AJwBgAAoAIAAgACAAIAAvACAAIAAnACAAYAAgACAAIAAgACAAIAAgACAAIAAsACAAIAAgACAAIAAgACAAXwBfAC4ALQAtACcACgAgACAAIAAgACkALwAnACAAXwAvACAAIAAgACAAIABcACAAIAAgAGAALQBfACwAIAAgACAALwAgACAAIAAgACAAIABNAEUATwBXACAATQBFAE8AVwAgAE0ARQBPAFcACgAgACAAIAAgAGAALQAnACIAIABgACIAXABfACAAIAAsAF8ALgAtADsAXwAuAC0AXABfACAAJwAsACAAIAAgACAAIABZAG8AdQAgAGgAYQB2AGUAIABmAG8AdQBuAGQAIABzAGgAZQBsAGwAIABrAGkAdAB0AHkAIQAKACAAIAAgACAAIAAgACAAIABfAC4ALQAnAF8ALgAvACAAIAAgAHsAXwAuACcAIAAgACAAOwAgAC8AIAAgACAAIAAgAFIAdQBuACAAcwBoAGUAbABsACAAawBpAHQAdAB5ACAAbwBuACAANQAgAGMAbwBtAHAAdQB0AGUAcgBzAAoAIAAgACAAIAAgACAAIAB7AF8ALgAtAGAAYAAtACcAIAAgACAAIAAgACAAIAAgACAAewBfAC8AIAAgACAAIAAgACAAYQBuAGQAIAB5AG8AdQAgAHcAaQBsAGwAIABoAGEAdgBlACAAYQAgAHAAdQByAHIAZgBlAGMAdAAgAGQAYQB5AH4AfgB+AAoACgAnAEAACgBlAGMAaABvACAAJAB0AGUAeAB0AA==