p0wnedShell_outputs
Description
p0wnedShell Runspace Post Exploitation Toolkit - from files p0wnedShell.cs, p0wnedShell.cs
Query · yara
strings:
$s1 = "[+] For this attack to succeed, you need to have Admin privileges." fullword ascii
$s2 = "[+] This is not a valid hostname, please try again" fullword ascii
$s3 = "[+] First return the name of our current domain." fullword ascii
condition:
1 of them