Get-SecurityDescriptor
1.1
This script reviews the Registry Hive and identifies any scheduled tasks without SD (security descriptor) Value within the Task Key. We recommend that you perform analysis on these tasks as needed. The absence of SecurityDescriptor is a Defense Evasion and Persistence technique as these tasks will remain hidden from regular tasks queries results except an examiner man
This script reviews the Registry Hive and identifies any scheduled tasks without SD (security descriptor) Value within the Task Key. We recommend that you perform analysis on these tasks as needed. The absence of SecurityDescriptor is a Defense Evasion and Persistence technique as these tasks will remain hidden from regular tasks queries results except an examiner manually reviews the registry path
Show more
Installation Options
Owners
Copyright
Copyright (c) 2022 Adebola Ige
Package Details
Author(s)
- adebolaige
Tags
Tarrask malware Hafnium Registry SecurityDescriptor Scheduledtasks tasks Windows MITRE T1036 Persistence T1053 schtasks scheduler
Functions
Dependencies
This script has no dependencies.
FileList
- Get-SecurityDescriptor.nuspec
- Get-SecurityDescriptor.ps1
Version History
Version | Downloads | Last updated |
---|---|---|
1.1 (current version) | 134 | 4/22/2022 |
1.0 | 17 | 4/20/2022 |