Technical Information
- %TEMP%\reg99fd.tmp
- <SYSTEM32>\config\envinfo.txt
- <SYSTEM32>\config\localemetadata\wlanautoconfiglog_1033.mta
- %WINDIR%\ServiceProfiles\LocalService\appdata\local\temp\msg1.tmp
- %WINDIR%\ServiceProfiles\LocalService\appdata\local\temp\pub1.tmp
- %WINDIR%\ServiceProfiles\LocalService\appdata\local\temp\evt2.tmp
- <SYSTEM32>\config\wlanautoconfiglog.evtx
- <SYSTEM32>\config\adapterinfo.txt
- <SYSTEM32>\processes.txt
- unc\37l4247e29-32*\mailslot\net\netlogon
- <SYSTEM32>\config\gpresult.txt
- <SYSTEM32>\config\osinfo.txt
- <SYSTEM32>\reg\networkprofiles.reg.txt
- %TEMP%\regb95f.tmp
- unc\kpcxawncxdlq*\mailslot\net\netlogon
- <SYSTEM32>\reg\allcredfilter.reg.txt
- %TEMP%\reg9ff6.tmp
- <SYSTEM32>\reg\allcred.reg.txt
- %TEMP%\reg9d38.tmp
- <SYSTEM32>\reg\notif.reg.txt
- <SYSTEM32>\config\winsockcatalog.txt
- <SYSTEM32>\config\windowsfirewallconfig.txt
- %TEMP%\reg99fd.tmp
- %TEMP%\reg9d38.tmp
- %TEMP%\reg9ff6.tmp
- %TEMP%\regb95f.tmp
- '<SYSTEM32>\cmd.exe' /c gpresult /scope:computer /v 1> config\gpresult.txt 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c arp -a >> config\Neighbors.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo ARP -A: >> config\Neighbors.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh namespace show policy >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NETSH NAMESPACE SHOW POLICY: >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh namespace show effective >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NETSH NAMESPACE SHOW EFFECTIVE: >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ipconfig /displaydns >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo IPCONFIG /DISPLAYDNS: >> config\Dns.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface httpstunnel show statistics >> config\netiostate.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface httpstunnel show interface >> config\netiostate.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface teredo show state > config\netiostate.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall show currentprofile >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wlan show device >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NETSH INT IPV6 SHOW NEIGHBORS: >> config\Neighbors.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ipconfig /all >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc query upnphost >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc query fdrespub >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc query eaphost >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc query wlansvc >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc query wcncsvc >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wlan sho net m=b >> config\wlaninfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wlan show interfaces >> config\wlaninfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wl show d >> config\wlaninfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wl show i >> config\wlaninfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c time /t >> config\wlaninfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c dispdiag -out dispdiag_stop.dat' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c dxdiag /t dxdiag.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters >> config\WcnInfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show firewall >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh int ipv6 show neigh >> config\Neighbors.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupListener config\HomeGroupListener.reg /y /Reg:64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers config\PolicyManager.reg /y /Reg:64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseDataProtection\Policies config\EDPPolicies.reg /y /Reg:64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh.exe winsock show catalog >> config\winsock.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg.exe query "hklm\system\CurrentControlSet\Services\Winsock\Setup Migration" /v "Provider List" >> config\winsock.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg.exe query hklm\system\CurrentControlSet\Services\Winsock\Parameters /v Transports >> config\winsock.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe qc dhcp >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex dhcp >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe qc wlansvc >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex wlansvc >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe qc nativewifip >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex nativewifip >> config\serviceinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic qfe >> config\Hotfixinfo.log' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\VmmsNetworkingLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallConsecLogVerbose.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Neighbors.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl System /q:"*[System[Provider[@Name='Microsoft-Windows-Hyper-V-VmSwitch']]]" config\VmSwitchLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wfp show sysports file=config\sysports.xml 1> config\sysportslog.txt 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wfp show state file=config\wfpstate.xml 1> config\wfpstatelog.txt 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wfp show netevents file=config\netevents.xml 1> config\neteventslog.txt 2>&1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net share >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NET SHARE: >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net config srv >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NET CONFIG SRV: >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net config rdr >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NET CONFIG RDR: >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c nbtstat -c >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NBTSTAT -C: >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo. >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c nbtstat -n >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\VmSwitchLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo NBTSTAT -N: >> config\FileSharing.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose" config\WindowsFirewallConsecLogVerbose.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallLogVerbose.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose" config\WindowsFirewallLogVerbose.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\WcmSvc" Reg\WCMPolicy.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh lan show settings >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh lan show interfaces >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh wlan show all > config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WWANLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-WWAN-SVC-EVENTS/Operational" config\WWANLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WCMLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Wcmsvc/Operational" config\WCMLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WLANAutoConfigLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-WLAN-AutoConfig/Operational" config\WLANAutoConfigLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c tasklist /svc > processes.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powercfg.exe /batteryreport /output config\battery-report.html' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c set u >> config\osinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c systeminfo >> config\osinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupProvider config\HomeGroupProvider.reg /y /Reg:64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh mbn show interfaces >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\NetworkList" Reg\NetworkProfiles.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\Windows\WiredL2\GP_Policy" Reg\L2GP.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKCU\SOFTWARE\Microsoft\dot3svc" Reg\HKCUDot3Svc.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\dot3svc" Reg\HKLMDot3Svc.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Wlansvc" Reg\HKLMWlanSvc.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKCU\SOFTWARE\Microsoft\Wlansvc" Reg\HKCUWlanSvc.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy" Reg\GPT.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters\WlanAPIPermissions" Reg\APIPerm.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\{edd749de-2ef1-4a80-98d1-81f20e6df58e}" Reg\{edd749de-2ef1-4a80-98d1-81f20e6df58e}.reg....' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{33c86cd6-705f-4ba1-9adb-67070b837775}" Reg\{33c86cd6-705f-4ba1-9adb-67070b837775}.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{07AA0886-CC8D-4e19-A410-1C75AF686E62}" Reg\{07AA0886-CC8D-4e19-A410-1C75AF686E62}.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters" Reg\AllCredFilter.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers" Reg\AllCred.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\Notifications" Reg\Notif.reg.txt /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c set processor >> config\osinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Hyper-V-VMMS-Networking" config\VmmsNetworkingLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh mbn show profile name=* interface=* >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ipconfig /all >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh mbn show readyinfo interface=* >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallConsecLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity" config\WindowsFirewallConsecLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" config\WindowsFirewallLog.evtx' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show consec rule name=all >> config\WindowsFirewallEffectiveRules.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Rules currently enforced : >> config\WindowsFirewallEffectiveRules.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show firewall rule name=all >> config\WindowsFirewallEffectiveRules.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo ------------------------------------------------------------------------ >> config\WindowsFirewallEffectiveRules.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Firewall Rules currently enforced : > config\WindowsFirewallEffectiveRules.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall consec show rule name=all verbose >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Rules : >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall show rule name=all verbose >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Firewall Rules : >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh mbn show capability interface=* >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show consec >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh lan show profiles >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Firewall Configuration: >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show currentprofile >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo ------------------------------------------------------------------------ >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Current Profiles: > config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh winsock show catalog > config\WinsockCatalog.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil -v -user -store -silent root >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil -v -enterprise -store -silent NTAuth >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent root >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent -user My >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent My >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c route print >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo ROUTE PRINT: >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo. >> config\envinfo.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Configuration: >> config\WindowsFirewallConfig.txt' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $net_adapter=(Get-NetAdapter -IncludeHidden); $output= ($net_adapter); $output += ($net_adapter | fl *); $output += (Get-NetAdapterAdvancedProperty | fl); $net_adapter_bindings=(Get-Ne...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c gpresult /scope:computer /v 1> config\gpresult.txt 2>&1
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall show currentprofile >> config\WcnInfo.txt
- '<SYSTEM32>\netsh.exe' advfirewall show currentprofile
- '<SYSTEM32>\cmd.exe' /c netsh interface teredo show state > config\netiostate.txt
- '<SYSTEM32>\netsh.exe' interface teredo show state
- '<SYSTEM32>\cmd.exe' /c netsh interface httpstunnel show interface >> config\netiostate.txt
- '<SYSTEM32>\netsh.exe' interface httpstunnel show interface
- '<SYSTEM32>\cmd.exe' /c netsh interface httpstunnel show statistics >> config\netiostate.txt
- '<SYSTEM32>\netsh.exe' interface httpstunnel show statistics
- '<SYSTEM32>\cmd.exe' /c echo IPCONFIG /DISPLAYDNS: >> config\Dns.txt
- '<SYSTEM32>\cmd.exe' /c ipconfig /displaydns >> config\Dns.txt
- '<SYSTEM32>\ipconfig.exe' /displaydns
- '<SYSTEM32>\cmd.exe' /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters >> config\WcnInfo.txt
- '<SYSTEM32>\reg.exe' query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc\Parameters
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Dns.txt
- '<SYSTEM32>\netsh.exe' namespace show effective
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Dns.txt
- '<SYSTEM32>\cmd.exe' /c echo NETSH NAMESPACE SHOW POLICY: >> config\Dns.txt
- '<SYSTEM32>\cmd.exe' /c netsh namespace show policy >> config\Dns.txt
- '<SYSTEM32>\netsh.exe' namespace show policy
- '<SYSTEM32>\cmd.exe' /c echo ARP -A: >> config\Neighbors.txt
- '<SYSTEM32>\cmd.exe' /c arp -a >> config\Neighbors.txt
- '<SYSTEM32>\arp.exe' -a
- '<SYSTEM32>\cmd.exe' /c echo. >> config\Neighbors.txt
- '<SYSTEM32>\cmd.exe' /c echo NETSH INT IPV6 SHOW NEIGHBORS: >> config\Neighbors.txt
- '<SYSTEM32>\cmd.exe' /c netsh int ipv6 show neigh >> config\Neighbors.txt
- '<SYSTEM32>\cmd.exe' /c echo NETSH NAMESPACE SHOW EFFECTIVE: >> config\Dns.txt
- '<SYSTEM32>\cmd.exe' /c netsh namespace show effective >> config\Dns.txt
- '<SYSTEM32>\cmd.exe' /c echo NBTSTAT -N: >> config\FileSharing.txt
- '<SYSTEM32>\netsh.exe' int ipv6 show neigh
- '<SYSTEM32>\cmd.exe' /c ipconfig /all >> config\WcnInfo.txt
- '<SYSTEM32>\cmd.exe' /c dxdiag /t dxdiag.txt
- '<SYSTEM32>\dxdiag.exe' /t dxdiag.txt
- '%WINDIR%\syswow64\dxdiag.exe' /t dxdiag.txt
- '<SYSTEM32>\cmd.exe' /c dispdiag -out dispdiag_stop.dat
- '<SYSTEM32>\dispdiag.exe' -out dispdiag_stop.dat
- '<SYSTEM32>\cmd.exe' /c time /t >> config\wlaninfo.txt
- '<SYSTEM32>\cmd.exe' /c netsh wl show i >> config\wlaninfo.txt
- '<SYSTEM32>\netsh.exe' wl show i
- '<SYSTEM32>\cmd.exe' /c netsh wl show d >> config\wlaninfo.txt
- '<SYSTEM32>\netsh.exe' wl show d
- '<SYSTEM32>\cmd.exe' /c netsh wlan show device >> config\WcnInfo.txt
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallConsecLogVerbose.evtx
- '<SYSTEM32>\netsh.exe' wlan show device
- '<SYSTEM32>\cmd.exe' /c netsh wlan show interfaces >> config\wlaninfo.txt
- '<SYSTEM32>\cmd.exe' /c sc query wcncsvc >> config\WcnInfo.txt
- '<SYSTEM32>\sc.exe' query wcncsvc
- '<SYSTEM32>\cmd.exe' /c sc query wlansvc >> config\WcnInfo.txt
- '<SYSTEM32>\sc.exe' query wlansvc
- '<SYSTEM32>\cmd.exe' /c sc query eaphost >> config\WcnInfo.txt
- '<SYSTEM32>\sc.exe' query eaphost
- '<SYSTEM32>\cmd.exe' /c sc query fdrespub >> config\WcnInfo.txt
- '<SYSTEM32>\sc.exe' query fdrespub
- '<SYSTEM32>\cmd.exe' /c sc query upnphost >> config\WcnInfo.txt
- '<SYSTEM32>\sc.exe' query upnphost
- '<SYSTEM32>\netsh.exe' wlan show interfaces
- '<SYSTEM32>\cmd.exe' /c netsh wlan sho net m=b >> config\wlaninfo.txt
- '<SYSTEM32>\netsh.exe' wlan sho net m=b
- '<SYSTEM32>\cmd.exe' /c netsh mbn show interfaces >> config\envinfo.txt
- '<SYSTEM32>\cmd.exe' /c nbtstat -n >> config\FileSharing.txt
- '<SYSTEM32>\wbem\wmic.exe' qfe
- '<SYSTEM32>\sc.exe' queryex nativewifip
- '<SYSTEM32>\cmd.exe' /c sc.exe qc nativewifip >> config\serviceinfo.log
- '<SYSTEM32>\sc.exe' qc nativewifip
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex wlansvc >> config\serviceinfo.log
- '<SYSTEM32>\sc.exe' queryex wlansvc
- '<SYSTEM32>\cmd.exe' /c sc.exe qc wlansvc >> config\serviceinfo.log
- '<SYSTEM32>\sc.exe' qc wlansvc
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex dhcp >> config\serviceinfo.log
- '<SYSTEM32>\sc.exe' queryex dhcp
- '<SYSTEM32>\cmd.exe' /c sc.exe qc dhcp >> config\serviceinfo.log
- '<SYSTEM32>\cmd.exe' /c wmic qfe >> config\Hotfixinfo.log
- '<SYSTEM32>\sc.exe' qc dhcp
- '<SYSTEM32>\cmd.exe' /c sc.exe queryex nativewifip >> config\serviceinfo.log
- '<SYSTEM32>\reg.exe' query hklm\system\CurrentControlSet\Services\Winsock\Parameters /v Transports
- '<SYSTEM32>\reg.exe' query "hklm\system\CurrentControlSet\Services\Winsock\Setup Migration" /v "Provider List"
- '<SYSTEM32>\cmd.exe' /c netsh.exe winsock show catalog >> config\winsock.log
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseDataProtection\Policies config\EDPPolicies.reg /y /Reg:64
- '<SYSTEM32>\reg.exe' Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseDataProtection\Policies config\EDPPolicies.reg /y /Reg:64
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers config\PolicyManager.reg /y /Reg:64
- '<SYSTEM32>\reg.exe' Export HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers config\PolicyManager.reg /y /Reg:64
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupListener config\HomeGroupListener.reg /y /Reg:64
- '<SYSTEM32>\reg.exe' Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupListener config\HomeGroupListener.reg /y /Reg:64
- '<SYSTEM32>\cmd.exe' /c Reg.exe Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupProvider config\HomeGroupProvider.reg /y /Reg:64
- '<SYSTEM32>\reg.exe' Export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupProvider config\HomeGroupProvider.reg /y /Reg:64
- '<SYSTEM32>\cmd.exe' /c reg.exe query hklm\system\CurrentControlSet\Services\Winsock\Parameters /v Transports >> config\winsock.log
- '<SYSTEM32>\wevtutil.exe' al config\VmmsNetworkingLog.evtx
- '<SYSTEM32>\cmd.exe' /c reg.exe query "hklm\system\CurrentControlSet\Services\Winsock\Setup Migration" /v "Provider List" >> config\winsock.log
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\VmmsNetworkingLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Hyper-V-VMMS-Networking" config\VmmsNetworkingLog.evtx
- '<SYSTEM32>\cmd.exe' /c echo. >> config\FileSharing.txt
- '<SYSTEM32>\cmd.exe' /c nbtstat -c >> config\FileSharing.txt
- '<SYSTEM32>\nbtstat.exe' -c
- '<SYSTEM32>\cmd.exe' /c echo NET CONFIG RDR: >> config\FileSharing.txt
- '<SYSTEM32>\cmd.exe' /c net config rdr >> config\FileSharing.txt
- '<SYSTEM32>\net.exe' config rdr
- '<SYSTEM32>\net1.exe' config rdr
- '<SYSTEM32>\cmd.exe' /c echo NET CONFIG SRV: >> config\FileSharing.txt
- '<SYSTEM32>\cmd.exe' /c net config srv >> config\FileSharing.txt
- '<SYSTEM32>\net.exe' config srv
- '<SYSTEM32>\net1.exe' config srv
- '<SYSTEM32>\cmd.exe' /c echo NET SHARE: >> config\FileSharing.txt
- '<SYSTEM32>\cmd.exe' /c net share >> config\FileSharing.txt
- '<SYSTEM32>\cmd.exe' /c echo NBTSTAT -C: >> config\FileSharing.txt
- '<SYSTEM32>\net.exe' share
- '<SYSTEM32>\cmd.exe' /c netsh wfp show netevents file=config\netevents.xml 1> config\neteventslog.txt 2>&1
- '<SYSTEM32>\netsh.exe' wfp show netevents file=config\netevents.xml
- '<SYSTEM32>\cmd.exe' /c netsh wfp show state file=config\wfpstate.xml 1> config\wfpstatelog.txt 2>&1
- '<SYSTEM32>\netsh.exe' wfp show state file=config\wfpstate.xml
- '<SYSTEM32>\cmd.exe' /c netsh wfp show sysports file=config\sysports.xml 1> config\sysportslog.txt 2>&1
- '<SYSTEM32>\netsh.exe' wfp show sysports file=config\sysports.xml
- '<SYSTEM32>\cmd.exe' /c wevtutil epl System /q:"*[System[Provider[@Name='Microsoft-Windows-Hyper-V-VmSwitch']]]" config\VmSwitchLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl System /q:"*[System[Provider[@Name='Microsoft-Windows-Hyper-V-VmSwitch']]]" config\VmSwitchLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\VmSwitchLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\VmSwitchLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Hyper-V-VMMS-Networking" config\VmmsNetworkingLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose" config\WindowsFirewallConsecLogVerbose.evtx
- '<SYSTEM32>\net1.exe' share
- '<SYSTEM32>\wevtutil.exe' al config\WindowsFirewallConsecLogVerbose.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose" config\WindowsFirewallConsecLogVerbose.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WindowsFirewallLogVerbose.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallLogVerbose.evtx
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\cmd.exe' /c set u >> config\osinfo.txt
- '<SYSTEM32>\cmd.exe' /c powercfg.exe /batteryreport /output config\battery-report.html
- '<SYSTEM32>\powercfg.exe' /batteryreport /output config\battery-report.html
- '<SYSTEM32>\cmd.exe' /c tasklist /svc > processes.txt
- '<SYSTEM32>\tasklist.exe' /svc
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-WLAN-AutoConfig/Operational" config\WLANAutoConfigLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-WLAN-AutoConfig/Operational" config\WLANAutoConfigLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WLANAutoConfigLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WLANAutoConfigLog.evtx
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Policies\Microsoft\WcmSvc" Reg\WCMPolicy.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\NetworkList" Reg\NetworkProfiles.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c systeminfo >> config\osinfo.txt
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Wcmsvc/Operational" config\WCMLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-WWAN-SVC-EVENTS/Operational" config\WWANLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-WWAN-SVC-EVENTS/Operational" config\WWANLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WWANLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WWANLog.evtx
- '<SYSTEM32>\cmd.exe' /c netsh wlan show all > config\envinfo.txt
- '<SYSTEM32>\netsh.exe' wlan show all
- '<SYSTEM32>\cmd.exe' /c netsh lan show interfaces >> config\envinfo.txt
- '<SYSTEM32>\netsh.exe' lan show interfaces
- '<SYSTEM32>\cmd.exe' /c netsh lan show settings >> config\envinfo.txt
- '<SYSTEM32>\netsh.exe' lan show settings
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Wcmsvc/Operational" config\WCMLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WCMLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WCMLog.evtx
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\WcmSvc" Reg\WCMPolicy.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\NetworkList" Reg\NetworkProfiles.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c netsh lan show profiles >> config\envinfo.txt
- '<SYSTEM32>\gpresult.exe' /scope:computer /v
- '<SYSTEM32>\reg.exe' export "HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\Notifications" Reg\Notif.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers" Reg\AllCred.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers" Reg\AllCred.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters" Reg\AllCredFilter.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters" Reg\AllCredFilter.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{07AA0886-CC8D-4e19-A410-1C75AF686E62}" Reg\{07AA0886-CC8D-4e19-A410-1C75AF686E62}.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{07AA0886-CC8D-4e19-A410-1C75AF686E62}" Reg\{07AA0886-CC8D-4e19-A410-1C75AF686E62}.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{33c86cd6-705f-4ba1-9adb-67070b837775}" Reg\{33c86cd6-705f-4ba1-9adb-67070b837775}.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{33c86cd6-705f-4ba1-9adb-67070b837775}" Reg\{33c86cd6-705f-4ba1-9adb-67070b837775}.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\{edd749de-2ef1-4a80-98d1-81f20e6df58e}" Reg\{edd749de-2ef1-4a80-98d1-81f20e6df58e}.reg....
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\{edd749de-2ef1-4a80-98d1-81f20e6df58e}" Reg\{edd749de-2ef1-4a80-98d1-81f20e6df58e}.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\Notifications" Reg\Notif.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters\WlanAPIPermissions" Reg\APIPerm.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy" Reg\GPT.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy" Reg\GPT.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKCU\SOFTWARE\Microsoft\Wlansvc" Reg\HKCUWlanSvc.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKCU\SOFTWARE\Microsoft\Wlansvc" Reg\HKCUWlanSvc.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\Wlansvc" Reg\HKLMWlanSvc.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\Wlansvc" Reg\HKLMWlanSvc.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Microsoft\dot3svc" Reg\HKLMDot3Svc.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Microsoft\dot3svc" Reg\HKLMDot3Svc.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKCU\SOFTWARE\Microsoft\dot3svc" Reg\HKCUDot3Svc.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKCU\SOFTWARE\Microsoft\dot3svc" Reg\HKCUDot3Svc.reg.txt /y
- '<SYSTEM32>\cmd.exe' /c reg export "HKLM\SOFTWARE\Policies\Microsoft\Windows\WiredL2\GP_Policy" Reg\L2GP.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SOFTWARE\Policies\Microsoft\Windows\WiredL2\GP_Policy" Reg\L2GP.reg.txt /y
- '<SYSTEM32>\reg.exe' export "HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters\WlanAPIPermissions" Reg\APIPerm.reg.txt /y
- '<SYSTEM32>\ping.exe' bing.com -4
- '<SYSTEM32>\nbtstat.exe' -n
- '<SYSTEM32>\netsh.exe' lan show profiles
- '<SYSTEM32>\netsh.exe' mbn show profile name=* interface=*
- '<SYSTEM32>\netsh.exe' advfirewall monitor show consec
- '<SYSTEM32>\cmd.exe' /c echo Firewall Rules : >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall show rule name=all verbose >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\netsh.exe' advfirewall firewall show rule name=all verbose
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Rules : >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall consec show rule name=all verbose >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\netsh.exe' advfirewall consec show rule name=all verbose
- '<SYSTEM32>\cmd.exe' /c echo Firewall Rules currently enforced : > config\WindowsFirewallEffectiveRules.txt
- '<SYSTEM32>\cmd.exe' /c echo ------------------------------------------------------------------------ >> config\WindowsFirewallEffectiveRules.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show firewall rule name=all >> config\WindowsFirewallEffectiveRules.txt
- '<SYSTEM32>\netsh.exe' advfirewall monitor show firewall
- '<SYSTEM32>\netsh.exe' advfirewall monitor show firewall rule name=all
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show consec >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show consec rule name=all >> config\WindowsFirewallEffectiveRules.txt
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" config\WindowsFirewallLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" config\WindowsFirewallLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WindowsFirewallLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity" config\WindowsFirewallConsecLog.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity" config\WindowsFirewallConsecLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil al config\WindowsFirewallConsecLog.evtx
- '<SYSTEM32>\wevtutil.exe' al config\WindowsFirewallConsecLog.evtx
- '<SYSTEM32>\cmd.exe' /c wevtutil epl "Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose" config\WindowsFirewallLogVerbose.evtx
- '<SYSTEM32>\wevtutil.exe' epl "Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose" config\WindowsFirewallLogVerbose.evtx
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Rules currently enforced : >> config\WindowsFirewallEffectiveRules.txt
- '<SYSTEM32>\cmd.exe' /c set processor >> config\osinfo.txt
- '<SYSTEM32>\netsh.exe' advfirewall monitor show consec rule name=all
- '<SYSTEM32>\cmd.exe' /c echo Connection Security Configuration: >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show firewall >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c echo Firewall Configuration: >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh mbn show readyinfo interface=* >> config\envinfo.txt
- '<SYSTEM32>\netsh.exe' mbn show readyinfo interface=*
- '<SYSTEM32>\cmd.exe' /c netsh mbn show capability interface=* >> config\envinfo.txt
- '<SYSTEM32>\netsh.exe' mbn show capability interface=*
- '<SYSTEM32>\cmd.exe' /c ipconfig /all >> config\envinfo.txt
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\cmd.exe' /c echo. >> config\envinfo.txt
- '<SYSTEM32>\cmd.exe' /c echo ROUTE PRINT: >> config\envinfo.txt
- '<SYSTEM32>\cmd.exe' /c route print >> config\envinfo.txt
- '<SYSTEM32>\route.exe' print
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent My >> config\envinfo.txt
- '<SYSTEM32>\cmd.exe' /c netsh mbn show profile name=* interface=* >> config\envinfo.txt
- '<SYSTEM32>\certutil.exe' -v -store -silent My
- '<SYSTEM32>\certutil.exe' -v -store -silent -user My
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent root >> config\envinfo.txt
- '<SYSTEM32>\certutil.exe' -v -store -silent root
- '<SYSTEM32>\cmd.exe' /c certutil -v -enterprise -store -silent NTAuth >> config\envinfo.txt
- '<SYSTEM32>\certutil.exe' -v -enterprise -store -silent NTAuth
- '<SYSTEM32>\cmd.exe' /c certutil -v -user -store -silent root >> config\envinfo.txt
- '<SYSTEM32>\certutil.exe' -v -user -store -silent root
- '<SYSTEM32>\cmd.exe' /c netsh winsock show catalog > config\WinsockCatalog.txt
- '<SYSTEM32>\netsh.exe' winsock show catalog
- '<SYSTEM32>\cmd.exe' /c echo Current Profiles: > config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c echo ------------------------------------------------------------------------ >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall monitor show currentprofile >> config\WindowsFirewallConfig.txt
- '<SYSTEM32>\cmd.exe' /c certutil -v -store -silent -user My >> config\envinfo.txt
- '<SYSTEM32>\netsh.exe' advfirewall monitor show currentprofile
- '<SYSTEM32>\netsh.exe' mbn show interfaces
- '<SYSTEM32>\ping.exe' bing.com -6