Windows11_CommandPrompt_Downgrade

Windows11_CommandPrompt_Downgrade
Download Copy
Title: Windows11_CommandPrompt_Downgrade
Author: 0iphor13

In Windows 11 22H2, the default app used to host console windows has been changed to Windows Terminal. After the October 2022 update, Command Prompt, Windows PowerShell, and other console apps will appear inside an instance of Windows Terminal(Reference). This causes Powershell not using the parameter -WindowStyle hidden properly, resulting in Powershell just minimizing instead of properly hiding itself By default this payload reverts the default app to Conhost, fixing the hidden powershell. You may intergrate this to properly hide your payloads actions again. Other values are also provided for a backup solution or simply to tinker around with it.

Execution is the method of either remotely or locally running code — malicious or otherwise — on a target computer. Execution is typically coupled with other techniques to carry out more complex tasks, like performing reconnaissance, exfiltration or credential harvesting. Execution may be ephemeral, or coupled with persistence techniques used to maintain remote access or continued code execution. See all execution payloads.

This payload is for OMG — a platform built for covert field-use with features that enhance remote execution, stealth and forensics evasion, all while being able to quickly change your tooling on the fly.

Submit your own payload, or browse more featured OMG Payloads.

 

 

Related Payloads

Google Exfil
Google Exfil
This payload runs Powershell script that zips google user data, uses gofile.io api to upload it, and then sends a downlo
Read More
Defend Yourself From CVE-2023-23397
Defend Yourself From CVE-2023-23397
This script sets a Firewall rule that will defend you against CVE-2023-23397.
Read More
The Perfect Stealthy Payload
The Perfect Stealthy Payload
Opens PowerShell as admin, creates a folder in Windows/temp called Cache, adds exclusion in Defender, downloads the payl
Read More