RemoteAdmin
Author: Drew Ervin, Mathias Frank, Andrew Rathbun, Phill Moore
description
Composite target for files related to remote administration tools
includes (26)
+
9
more targets
paths
107 pathsfrom 26 targets
› paths use Windows environment syntax
collection commands
# PowerShell Collection Script
# Target: RemoteAdmin (Compound Target)
# Use KAPE for compound target collection:
# kape.exe --tsource C: --tdest D:\Evidence --target RemoteAdmin
Write-Host "For compound targets, use KAPE directly for best results." -ForegroundColor Yellow
› Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1
Note: This is a compound target that references 29 other targets. KAPE will automatically collect all referenced artifacts.