Forum Discussion
Powershell Deobsfuscation Ep.7
- 9 months ago
Firstly great detail. The last one seems like we've missed something.
The easier thing to do with this lab is remove any way of detonating (removable of shell commands or IEX or Invoke expression and so on) and use powershell to return the data then pipe it to an 'Add-Content -Path command or > NewLayer1.ps1 and continue that way
Happy to jump on a discord chat Mr Hand Grenade#6321
Honestly I learnt so much from this 12 days of Deobfs but there is also another Powershell Deobs that actually shows you how to do it... I wish I had of done that first but learnt so much this way
I am stuck here too. Anyone can help on how to proceed from here?
CyberSharpe and GusC were you guys able to solve it?
- CyberSharpe3 months ago
Silver I
ray96 Apologies for the late reply. Ive been somewhat AFK recently.
remove anything that can run the command. the trim it, and run it without the IEX.