mirror of
https://github.com/Aryma-f4/Ares-mythic.git
synced 2026-06-12 12:14:13 +00:00
first commit
This commit is contained in:
29
documentation-payload/apollo/commands/powerpick.md
Normal file
29
documentation-payload/apollo/commands/powerpick.md
Normal file
@@ -0,0 +1,29 @@
|
||||
+++
|
||||
title = "powerpick"
|
||||
chapter = false
|
||||
weight = 103
|
||||
hidden = false
|
||||
+++
|
||||
|
||||
{{% notice info %}}
|
||||
Artifacts Generated: Process Create, Process Inject, Process Kill
|
||||
{{% /notice %}}
|
||||
|
||||
## Summary
|
||||
Execute PowerShell commands as post-exploitation job. This command will import the most recently registered `*.ps1` file registered using `register_file` and import it into the PowerShell runspace before execution.
|
||||
|
||||
### Arguments (Positional)
|
||||
#### command
|
||||
PowerShell command to be executed.
|
||||
|
||||
## Usage
|
||||
```
|
||||
powerpick [command]
|
||||
powerpick -Command [command]
|
||||
```
|
||||
|
||||
|
||||
## MITRE ATT&CK Mapping
|
||||
|
||||
- T1059
|
||||
- T1562
|
||||
Reference in New Issue
Block a user