Commit Graph

50 Commits

Author SHA1 Message Date
jheysel-r7 bb98e855e1 Merge pull request #20751 from h00die/sticky_keys
update windows sticky keys to persistence mixin
2026-01-08 16:44:04 -08:00
h00die 5ac586a788 Update modules/exploits/windows/persistence/assistive_technology.rb
Co-authored-by: Brendan <bwatters@rapid7.com>
2025-12-19 14:52:34 -05:00
h00die d15d4ca5dc .exe guard clause for assistive_tech persistence 2025-12-18 16:17:50 -05:00
h00die 54d47e72ab sticky keys description update 2025-12-07 07:40:54 -05:00
h00die bd48eda8b2 rename sticky keys module 2025-12-07 07:38:41 -05:00
h00die a2f266068b assistive technology persistence 2025-12-06 13:05:32 -05:00
h00die 54718c7a12 sticky keys as persistence 2025-12-05 07:07:30 -05:00
Brendan 21777b8969 Merge pull request #20685 from msutovsky-r7/persistence/windows/notepad++_persistence
Adds notepad++ persistence module for Windows
2025-11-21 14:28:28 -06:00
Martin Sutovsky 098af341f9 Fix payload name escaping 2025-11-21 13:04:52 +01:00
Martin Sutovsky d904a526ee Shamefully removes pry and pry-byebug 2025-11-20 17:08:28 +01:00
msutovsky-r7 e2097ee1bc Land #20701, adds windows WSL registry persistence module
Windows WSL registry persistence
2025-11-20 15:15:22 +01:00
Martin Sutovsky abaa4e6c7a Fixes cmd_exec call 2025-11-20 11:27:34 +01:00
h00die 9ff3f94bc9 review comments for wsl persistence 2025-11-19 17:37:55 -05:00
Martin Sutovsky 554c952d06 Adds payload name escaping 2025-11-19 15:58:30 +01:00
Martin Sutovsky 6957f73bf5 Adds architecture match check 2025-11-19 08:12:30 +01:00
h00die 58f29548b3 review for windows/persistence/wsl/registry 2025-11-18 18:50:07 -05:00
h00die 7c8fbd1672 rework windows service persistence 2025-11-17 19:02:54 -05:00
h00die a0222d0783 rework windows service persistence 2025-11-17 19:02:53 -05:00
h00die 1ad89ef1ef rewriting service 2025-11-17 19:02:53 -05:00
h00die 8c211b4d4a fix sc commands in windows service persistence 2025-11-17 19:02:53 -05:00
h00die 450e1df340 windows service now with persistence mixin 2025-11-17 19:02:50 -05:00
Martin Sutovsky 8285b433cb Addresses comments 2025-11-17 11:04:28 +01:00
Martin Sutovsky 0e26719cf2 Adds dll_exitprocess 2025-11-17 09:24:09 +01:00
h00die e3560e43cf windows wsl registry persistence 2025-11-16 08:35:44 -05:00
Martin Sutovsky e35bd89033 Expands check method 2025-11-12 10:35:23 +01:00
Diego Ledda 29088b4712 Merge pull request #20576 from msutovsky-r7/modules/persistence/linqpad_deserialization
Moves LINQPad module into persistence category
2025-11-11 16:41:12 +01:00
Martin Sutovsky 9058f6676b Removes if condition 2025-11-11 11:22:31 +01:00
Martin Sutovsky 2cbf32ce40 Adds documentation base 2025-11-10 12:27:13 +01:00
Martin Sutovsky d4283cd17f Adds base for Notepad++ persistence 2025-11-10 10:58:03 +01:00
msutovsky-r7 af5baeb3c6 Land #20660, adds windows task scheduler persistence module
Windows task scheduler persistence
2025-10-31 10:16:19 +01:00
Martin Sutovsky ee3058bf92 Removes moved_from 2025-10-29 15:14:29 +01:00
msutovsky-r7 56480df99f Land #20662, adds windows startup folder persistence module
windows persistence: startup folder
2025-10-29 13:23:35 +01:00
h00die 34b630736a Merge remote-tracking branch 'origin/windows_taskscheduler_persistence' into windows_taskscheduler_persistence 2025-10-29 05:22:55 -04:00
h00die f03b32551a Update modules/exploits/windows/persistence/task_scheduler.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
2025-10-29 05:22:28 -04:00
h00die b48215d9c1 Merge remote-tracking branch 'origin/windows_taskscheduler_persistence' into windows_taskscheduler_persistence 2025-10-29 05:21:45 -04:00
h00die 35f632bc85 windows persistence: task scheduler review 2025-10-29 05:20:57 -04:00
h00die 85fa7e0391 windows persistence: startup folder review 2025-10-29 05:18:20 -04:00
Martin Sutovsky b167a2bc7d Adds moved_from clause 2025-10-29 07:58:50 +01:00
Martin Sutovsky 44c3d9b5db Fixes documentation, removes unused parameters, code cleanup 2025-10-29 07:58:47 +01:00
msutovsky-r7 65f764e8bc Corrects CheckCode from Vulnerable to Appears
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
2025-10-29 07:57:20 +01:00
Martin Sutovsky 5bf842c15e Moves module to persistence category, docs reformat 2025-10-29 07:57:19 +01:00
Martin Sutovsky 547b318848 Moves linqpad deserialization to persistence category 2025-10-29 07:56:49 +01:00
h00die fd6d84df0f Update modules/exploits/windows/persistence/task_scheduler.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
2025-10-27 19:51:32 -04:00
h00die fd04f465eb windows persistence: startup folder 2025-10-27 15:35:52 -04:00
h00die c210a897ac windows persistence: task scheduler 2025-10-26 16:17:16 -04:00
h00die 0f26c9316a registry persistence peer review 2025-10-23 17:44:22 -04:00
h00die bc9bd4b62c windows registry persistence mixin conversion 2025-10-19 09:36:59 -04:00
h00die 81d8d46166 peer review 2025-09-26 15:44:31 -04:00
h00die 915cad72b5 modern persistence for windows image_exec_options 2025-09-23 17:25:27 -04:00
h00die 01a07ac9a1 modernizing windows persistence 2025-09-23 16:39:56 -04:00