{"repo":"bitsadmin/nopowershell","free":true,"listed":false,"github":"https://github.com/bitsadmin/nopowershell","clone":"git clone https://github.com/bitsadmin/nopowershell.git","description":"PowerShell rebuilt in C# for Red Teaming purposes","language":"C#","stars":1060,"topics":["powershell","redteaming","cobaltstrike"],"license":"BSD-3-Clause","category":"workflow-automation","readme_excerpt":"NoPowerShell NoPowerShell is a tool implemented in C# which supports executing PowerShell-like commands while remaining invisible to any PowerShell logging mechanisms. This .NET Framework 2 compatible binary can be loaded in Cobalt Strike to execute commands in-memory. No System.Management.Automation.dll is used; only native .NET libraries. An alternative usecase for NoPowerShell is to launch it as a DLL via rundll32.exe in a restricted environment: rundll32 NoPowerShell.dll,main . This project makes it easy for everyone to extend its functionality using only a few lines of C# code. For more info, see CONTRIBUTING.md. Latest binaries available from the Releases page. The MASTER branch is not updated very regularly; the latest code and cmdlets are available in the DEV branch. To kickstart your NoPowerShell skills, make sure to also check out the cmdlet Cheatsheet. Screenshots Running in Cobalt Strike Sample execution of commands Rundll32 version Why NoPowerShell NoPowerShell is developed to be used with the execute-assembly command of Cobalt Strike or in a restricted environment using rundll32.exe . Reasons to use NoPowerShell: - Executes pretty stealthy - Powerful functionality - Provides the cmdlets you are already familiar with in PowerShell, so no need to learn yet another tool - If you are not yet very familiar with PowerShell, the cmd.exe aliases are available as well (e.g. ping instead of Test-NetConnection ) - In case via powerpick or powershell cmdlets are not availab","default_branch":null,"files":null,"tree":[],"storefront":"/r/bitsadmin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bitsadmin/nopowershell/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}