.. / CL_Mutexverifiers.ps1
Star


Paths:


Resources:
https://twitter.com/pabraeken/status/995111125447577600

Acknowledgement:
Pierre-Alexandre Braeken - @pabraeken


Detection:



Execute

Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.
. C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1   \nrunAfterCancelProcess calc.ps1
Usecase:Proxy execution
Privileges required:User
OS:Windows 10
Mitre:T1216