This PowerShell Backdoor Watches Every New Document You Create

Removing the first script is not enough. Four scheduled tasks, a Startup launcher and two mutually monitored payloads can reconstruct the backdoor.

Removing the first script is not enough. Four scheduled tasks, a Startup launcher and two mutually monitored payloads can reconstruct the backdoor.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

Script Update 12-04-2025 due to Chrome cookie changes (Changed to Firefox) and YT-DLP changes. Watching or listening to Youtube playlists can be very frustrating with all the ads that are being thrown at you and this seems to have gotten…

Over the years I’ve gathered a lot of videos from various sources. Some of these are uncompressed and take up various gigabytes of space, each! Even though storage is getting cheaper, I don’t really want to spend €200,- (each) for…

Why pay for an expensive backup solution in your home-lab when you can install PowerShell for free? The script below will handle simple backups for you. You only have to add it to the Windows Scheduler or create a Cron…

Nowadays, instead of using .zip, .rar or .7z files, I find myself using virtual harddrives (.vhdx) more and more as it’s so much more convenient. However, extracting large amounts of compressed files, can be a very time consuming endeavor. Here…

A PowerShell script to report on all BlueScreen events and stop codes from the Windows Event Log on a specific server can be a useful tool for system administrators to troubleshoot and prevent future system crashes. This script will query…