A plugin detecting the presence of PowerShell Empire. More...
Public Member Functions | |
def | get_vad_base (self, task, address) |
Get the VAD starting address. | |
def | calculate (self) |
def | render_text (self, outfd, data) |
A plugin detecting the presence of PowerShell Empire.
Idally run against a PID of powershell.exe