.. / CL_Invocation.ps1
Star

Aero diagnostics script


Paths:


Resources:


Acknowledgement:
Jimmy - @bohops
Pierre-Alexandre Braeken - @pabraeken


Detection:



Execute

Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.
. C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1   \nSyncInvoke  [args]
Usecase:Proxy execution
Privileges required:User
OS:Windows 10
Mitre:T1216