Autorun

Detection

use the sysinternals tool provided called autoruns.exe

ofcourse once it runs we can see something very suspicious

Another tool thats possible to use would be PowerUp's invoke-allchecks

so now we know the program that has autorun on it... we need to see our permissions on it if we can even edit it

accesschk64.exe -wvu

  • w

    • Shows you the write access

  • v

    • Means verbose

  • u

    • Means suppress errors

so now that we know everyone can edit to simple just create a reverse shell and write over the file called program.exe

Full output from powerup

Last updated