msutovsky-r7
|
f2262a84cc
|
Land #20841, adds persistence module for Windows feature active setup
active setup persistence
|
2026-02-20 10:46:45 +01:00 |
|
Martin Sutovsky
|
993017d045
|
Rubocopes
|
2026-02-20 09:51:10 +01:00 |
|
h00die
|
855b436235
|
Update modules/exploits/windows/persistence/registry_active_setup.rb
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com>
|
2026-02-19 15:46:33 -05:00 |
|
Diego Ledda
|
8af82dc7eb
|
Merge pull request #20844 from 6a6f656c/userinit
Windows Userinit persistence
|
2026-02-18 06:05:04 -05:00 |
|
h00die
|
1c6fb0d11d
|
fix compatibility with session.sys
|
2026-02-17 16:37:05 -05:00 |
|
Diego Ledda
|
c24c58709d
|
Apply suggestion from @dledda-r7
|
2026-02-17 14:09:02 +01:00 |
|
6a6f656c
|
236fb33b6b
|
Apply suggestion from @dledda-r7
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com>
|
2026-02-17 07:17:42 -05:00 |
|
6a6f656c
|
ab30bd15f0
|
Apply suggestion from @dledda-r7
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com>
|
2026-02-17 07:17:17 -05:00 |
|
h00die
|
f4a195b88a
|
persistence modules cleanup
|
2026-01-14 13:49:29 -05:00 |
|
Diego Ledda
|
e4f8d4fb13
|
Merge pull request #20706 from h00die/windows_wmi_persistence
Update windows wmi to persistence mixin
|
2026-01-14 09:37:20 -05:00 |
|
h00die
|
6731992ddd
|
fix ci pipeline
|
2026-01-14 08:26:11 -05:00 |
|
h00die
|
1d9ecc89c6
|
add attck ref
|
2026-01-11 07:47:03 -05:00 |
|
h00die
|
6491f74d9d
|
wmi persistence improvements
|
2026-01-11 07:25:13 -05:00 |
|
h00die
|
aa5fd40a19
|
add arch to windows modules and triggered execution attck to most persistence
|
2026-01-09 16:21:08 -05:00 |
|
h00die
|
52ad17690f
|
add arch to windows modules and triggered execution attck to most persistence
|
2026-01-09 16:21:07 -05:00 |
|
jheysel-r7
|
bb98e855e1
|
Merge pull request #20751 from h00die/sticky_keys
update windows sticky keys to persistence mixin
|
2026-01-08 16:44:04 -08:00 |
|
h00die
|
428f31fdd3
|
review for wmi persistence
|
2026-01-06 16:36:05 -05:00 |
|
h00die
|
2f4db3bd5f
|
review for wmi persistence
|
2026-01-05 17:06:17 -05:00 |
|
h00die
|
d7d7a318ed
|
Add docs and tidy to userinit persistence
|
2026-01-03 16:27:54 -05:00 |
|
root
|
d2c192e9bf
|
windows persistence userinit v6
|
2026-01-03 15:37:44 -05:00 |
|
root
|
cb7dd50731
|
windows persistence userinit v5
|
2026-01-03 15:21:20 -05:00 |
|
root
|
f6fdbc4fbd
|
windows persistence userinit v4
|
2026-01-03 14:43:50 -05:00 |
|
root
|
beff06b9a4
|
windows persistence userinit v3
|
2026-01-03 11:09:14 -05:00 |
|
h00die
|
c485d9a822
|
active setup persistence
|
2026-01-03 10:39:45 -05:00 |
|
6a6f656c
|
4a3a26e9d9
|
windows persistence userinit v2
|
2026-01-02 09:33:21 -05:00 |
|
6a6f656c
|
9d120c1eeb
|
windows persistence userinit
|
2026-01-02 07:21:05 -05:00 |
|
h00die
|
5ac586a788
|
Update modules/exploits/windows/persistence/assistive_technology.rb
Co-authored-by: Brendan <bwatters@rapid7.com>
|
2025-12-19 14:52:34 -05:00 |
|
h00die
|
d15d4ca5dc
|
.exe guard clause for assistive_tech persistence
|
2025-12-18 16:17:50 -05:00 |
|
h00die
|
f18bdb12b2
|
remove writabledir from wmi persistence
|
2025-12-08 15:41:16 -05:00 |
|
h00die
|
54d47e72ab
|
sticky keys description update
|
2025-12-07 07:40:54 -05:00 |
|
h00die
|
bd48eda8b2
|
rename sticky keys module
|
2025-12-07 07:38:41 -05:00 |
|
h00die
|
a2f266068b
|
assistive technology persistence
|
2025-12-06 13:05:32 -05:00 |
|
h00die
|
54718c7a12
|
sticky keys as persistence
|
2025-12-05 07:07:30 -05:00 |
|
h00die
|
d3ae3e5556
|
wmi persistence docs
|
2025-11-30 10:51:45 -05:00 |
|
h00die
|
45250497d5
|
wmi uptime persistence
|
2025-11-22 09:13:01 -05:00 |
|
Brendan
|
21777b8969
|
Merge pull request #20685 from msutovsky-r7/persistence/windows/notepad++_persistence
Adds notepad++ persistence module for Windows
|
2025-11-21 14:28:28 -06:00 |
|
Martin Sutovsky
|
098af341f9
|
Fix payload name escaping
|
2025-11-21 13:04:52 +01:00 |
|
h00die
|
3251560ebc
|
wmi interval
|
2025-11-20 18:52:22 -05:00 |
|
Martin Sutovsky
|
d904a526ee
|
Shamefully removes pry and pry-byebug
|
2025-11-20 17:08:28 +01:00 |
|
msutovsky-r7
|
e2097ee1bc
|
Land #20701, adds windows WSL registry persistence module
Windows WSL registry persistence
|
2025-11-20 15:15:22 +01:00 |
|
Martin Sutovsky
|
abaa4e6c7a
|
Fixes cmd_exec call
|
2025-11-20 11:27:34 +01:00 |
|
h00die
|
9ff3f94bc9
|
review comments for wsl persistence
|
2025-11-19 17:37:55 -05:00 |
|
Martin Sutovsky
|
554c952d06
|
Adds payload name escaping
|
2025-11-19 15:58:30 +01:00 |
|
Martin Sutovsky
|
6957f73bf5
|
Adds architecture match check
|
2025-11-19 08:12:30 +01:00 |
|
h00die
|
2d41323e78
|
event_log working
|
2025-11-18 19:40:03 -05:00 |
|
h00die
|
58f29548b3
|
review for windows/persistence/wsl/registry
|
2025-11-18 18:50:07 -05:00 |
|
h00die
|
7c8fbd1672
|
rework windows service persistence
|
2025-11-17 19:02:54 -05:00 |
|
h00die
|
a0222d0783
|
rework windows service persistence
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
1ad89ef1ef
|
rewriting service
|
2025-11-17 19:02:53 -05:00 |
|
h00die
|
8c211b4d4a
|
fix sc commands in windows service persistence
|
2025-11-17 19:02:53 -05:00 |
|