README.md

August 2, 2024 · View on GitHub

Powershell Scripts For Hackers and Pentesters


An List of Powershell Scripts, commands and technics for Pentesting Windows Machines
Scripts managed by @Smukx



Pwn windows machines without any Restrictions ⚠️



What is this ?

This Repository is an Collection of Powershell Scripts, Hacks ,Tutorials etc .. These are my complete resoruce that i coded to use it to automate hacks , works etc ..

Usages ?

Enumerate your Powershell hacks , scripts usage (Adv) , to the next level . This Repository contains all kinds of Hacks and Powershell Tricks, from basics to advance powershell commnads and scripts that will help you in day to day life of an IT Sectors , cybersecurity or Windows Automation

Down is an list of series which you can concern for your needs !

Contents

Powershell Script Tier List+ MODULES +Links
Powershell Scripts & CommandsPS-010 (Ping-Play)Look Here
PS-020 (Attacks)Look Here
ps-030 (KEY-STOKES)Look Here
PS-040 (Win-Defender)Look Here
ps-050 (Silent-Installer)Look Here
PS-060 (Basics of Mimikaz)Look Here
PS-070-N (Adv Network Enumeration)Look Here
PS-070-M (Adv System Enumeration)Look Here
Complicated PartSYSTEM32Look Here
REVERSE-SHELLLook Here
SCRIPT-FILES.ps1Look Here
UNDETECTABE-KEYLOGGERLook Here
Exfiltrating data using Powershell & WAVLook Here



TopicDescriptionLink
Basic of Windows Systems [Works, Methods etc]Just an Bunch of Theories. If you are a Scirpt Kiddie (New to Hack) then this may help you understand thingsWindows Basics
WINDOWS-BASICSClick Here
WINDOWS-PENTEST-METHODSClick Here
COMMON-PORTS-AND-SERVICEClick Here
BASIC-COMMANDSClick Here
POWERSHELL VS CMDClick Here
JSON-IN-POWERSHELLClick Here
XML-IN-POWERSHELLClick Here
Powershell BlogsAUTOMATED POWERSHELL ATTACKSBlog
HOW KEYLOGGERS WORK ( BASICS ) InDeptBlog
POWERSHELL TURLA SERIESBlog
USING PS1 ON KALI LINUX FOR PENTESTINGBlog
Tracking Powershell based malware attacksBlog
Multi-stage Powershell scriptBlog
APT33 PowerShell MalwareBlog
Lemon Duck Powershell MalwareBlog
Hoaxcalls DDoS BotnetBlog
AgentTesla Delivered via a Malicious PowerPoint Add-InBlog
Machine learning from idea to reality: a PowerShell case studyBlog
Multi-stage PowerShell scriptBLog
Inspecting a PowerShell Cobalt Strike BeaconBlog
Powershell Reflective Loader to inject dllBlog
Windows Triaging with PowershellBlog
Powershell used to drop an REvil RansomwareBlog
PowerShell based attack targets KazakhstanBlog
Exploring Powershell AMSI and logging EvasionBlog
Charming Kitten Updates POWERSTAR with an InterPlanetary TwistBlog
Top-Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy “PowerTrick” Backdoor for High-Value TargetsBlog
Powershell static Analysis and Emote ResultsBlog
PowerPoint Dropper and Cryptocurrency StealerBlog
A border-hopping PlugX USB worm takes its act on the roadBlog
Malicious Powershell Targeting UK Bank CustomersBlog
PowerLess TrojanBlog
An Journey to Uncover New Fully Undetectable PowerShell BackdoorBlog
A case of Powershell, Excel 4 Macros and VB6Blog
Emotet Technical Analysis - Part 1Blog
Emotet Technical Analysis - Part 2Blog
Reversing complete Powershell MalwareBlog
HCrypt Injecting BitRAT using PowerShell, HTAs, and .NETBlog
PowerShell Dropper Delivering FormbookBlog
Reversing Complex PowerShell MalwareBlog
Threat Operation Re-emerges with New LNK and PowerShellBlog
The rise of .NET and Powershell MalwareBlog
MoDi RAT attack pastes PowerShell commandsBlog
Simple DGA Spotted in a Malicious PowerShellBlog
New PowerShell Obfuscation in Emotet MaldocsBlog
From virus alert to PowerShell Encrypted LoaderBlog
Anatomy of a PowerShell AttackBlog
Delivering Ransomware with Powershell Turla SeriesBlog
PRB-Backdoor-A Fully Loaded PowerShell Backdoor with Evil IntentionsBlog
Custom PowerShell RAT targets Germans seeking information about the Ukraine crisisBlog
Top 10 Prevalent MITRE ATT&CK TechniquesBlog
Detecting both ‘offensive’ and obfuscated PowerShell scripts in Splunk using Windows Event LogBlog
Analyzing Modern Malware TechniqueBlog
Emotet_network_protocolBlog
Powershell ConferenceBlackHat-USA-2010-Kennedy-Kelly-PowerShellPPT Link
BlackHat-USA-2017-Robbins-SchroederPPT Link
BlackHat-USA-2021-ProxyLogon is Just the Tip of the IcebergPPT Link
BlackHat-EU-14-Hafif-Reflected-File-Download-A-New-Web-AttackPPT Link
BlackHat-USA-2014-Kazanciyan-Investigating-Powershell-Attacks-wpPPT Link
BlackHat-USA-2017-PowerShell-Obfuscation Detection Using SciencePPT Link
Document
BlackHat-Asia-2016-DSCompromised:A Windows DSC Attack FrameworkPPT Link
BlackHat-USA-2017-INFECTING-THE-ENTERPRISE-ABUSING-OFFICE365+POWERSHELL-FOR-COVERT-C2PPT Link
Splunk-USA-2016-hunting-the-known-unknowns-the-PowerShell-editionPPT Link
BlackHat-USA-2019-PowerShell-module-for-administering-Office-365/Azure-ADPPT Link
PowerShell for Penetration TestersPPT Link
HTTB-SECONF-Exploit-with-Shell-Reverse-Infection-PowerShell-using-VBSPPT Link
Powershell PapersCSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACELink
Cheat Sheets for PowershellCheat Sheet by SanSCheat Sheet
Cheat Sheet by MicrosoftCheat Sheet
Reverse Shell Cheat SheetCheat Sheer
Powershell Books (Worth)Windows Security Internals with PowerShell (Aid. 2024)Redirect
The Complete Ultimate Windows Powershell Beginners Guide (Aid. 2017)Redirect
PowerShell Automation and Scripting for Cybersecurity (Aid. 2023)Redirect
Top Powershell ToolsPowershell EmpireRepo Link
WinPwnRepo Link
PersistenceSniperCode Link
PowerLessShellRepo Link
Free Powershell Books Around the InternetLearning Powershell from Stack Overflow ContributorsPDF Link
Mastering Windows Powershell ScriptingPDF Link
Learn Windows PowerShell In A Month Of LunchesPDF Link
EA - Windows Security Internals with PowerShellPDF Link
Increased use of Powershell AttacksPDF Link
Hands-On Penetration Testing on WindowsPDF Link
ScriptRunner PowerShell Security Ebook 2020PDF Link

RWH-Series

Real-world Series is a blog, where I will write the techniques and methods that Real World Hackers use to harm, breach, and crash data on Govt, Military, citizens, companies, etc ..

Now All the RWH has been linked at the blog category.


ATTENCTION HERE :
This repository consists of several parts PS-010 contains basic commands that are both fun and effective for attacking.

Please Note that Windows's security will change daily and they will try to Improve the Security. So some scripts may or may not work. If Some new scripts don't work! without hesitation notify me at Twitter

Reach out to my Windows Security Blog where I Explained pentesting methods and how you can use this repository to achieve certain Tasks ;) . [Still Writing] Link : Windows Pentest Series

:> Note ⚠️

If you find any wrong code / copyrighted content, please kindly inform me via Email: smukx@proton.me. I will verify and fix the issue, else I will remove the content and create a new one. Thank you !!

:: Cloning This Repo on git will remove some Powershell scripts.

Improvements and Tips

How to use my Repositary as Book

Improving at writing blogs on my website, but at present, I'm on a learning curve so I can't write all the blogs about it :(