Skip to content

Instantly share code, notes, and snippets.

@leveled
Created December 29, 2016 17:27
Show Gist options
  • Save leveled/8fe9042f7197cf632e30615ceda8f775 to your computer and use it in GitHub Desktop.
Save leveled/8fe9042f7197cf632e30615ceda8f775 to your computer and use it in GitHub Desktop.
Blind files worth checking in a Windows post-exploitation scenario
Windows Post Exploitation Files
%SYSTEMDRIVE%\boot.ini
%WINDIR%\win.ini
%SYSTEMROOT%\repair\SAM
%SYSTEMROOT%\System32\config\RegBack\SAM
%SYSTEMROOT%\repair\system
%SYSTEMROOT%\System32\config\RegBack\system
%SYSTEMDRIVE%\autoexec.bat
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment