Skip to content

Instantly share code, notes, and snippets.

@MatthewDemaske
Created June 16, 2017 22:03
Show Gist options
  • Star 11 You must be signed in to star a gist
  • Fork 1 You must be signed in to fork a gist
  • Save MatthewDemaske/d23280ef84b0a67e0848577600940ba9 to your computer and use it in GitHub Desktop.
Save MatthewDemaske/d23280ef84b0a67e0848577600940ba9 to your computer and use it in GitHub Desktop.
Powershell NaughtyWord List
*ExecuteShellCommand*
*GetDelegateForFunctionPointer*
*GetModuleHandle*
*GetProcAddress*
*Groups.User.Properties.cpassword*
*IMAGE_NT_OPTIONAL_HDR64_MAGIC*
*InteropServices.HandleRef*
*kernel32.dll*
*LSA_UNICODE_STRING*
*Management.Automation.RuntimeException*
*Metasploit*
*Microsoft.Win32.UnsafeNativeMethods*
*MiniDumpWriteDump*
*msvcrt.dll*
*OpenProcess*
*PAGE_EXECUTE_READ*
*psremoting*
*pssession*
*ReadProcessMemory.Invoke*
*Reflection.Emit.CustomAttributeBuilder*
*Reflection.Emit.OpCodes*
*ScheduledTasks.Task.Properties.cpassword*
*SE_PRIVILEGE_ENABLED*
*Security.Cryptography.CryptoStream*
*SECURITY_DELEGATION*
*System.BitConverter*
*System.DirectoryServices.ActiveDirectory*
*System.DirectoryServices.DirectorySearcher*
*system.dll*
*System.IdentityModel.Tokens.KerberosRequestorSecurityToken*
*Add-Type*
*DllImport*
*DefineDynamicAssembly*
*DefineDynamicModule*
*DefineType*
*DefineConstructor*
*CreateType*
*DefineLiteral*
*DefineEnum*
*DefineField*
*ILGenerator*
*Emit*
*UnverifiableCodeAttribute*
*DefinePInvokeMethod*
*GetTypes*
*GetAssemblies*
*Methods*
*Properties*
*GetConstructor*
*GetConstructors*
*GetDefaultMembers*
*GetEvent*
*GetEvents*
*GetField*
*GetFields*
*GetInterface*
*GetInterfaceMap*
*GetInterfaces*
*GetMember*
*GetMembers*
*GetMethod*
*GetMethods*
*GetNestedType*
*GetNestedTypes*
*GetProperties*
*GetProperty*
*InvokeMember*
*MakeArrayType*
*MakeByRefType*
*MakeGenericType*
*MakePointerType*
*DeclaringMethod*
*DeclaringType*
*ReflectedType*
*TypeHandle*
*TypeInitializer*
*UnderlyingSystemType*
*InteropServices*
*Marshal*
*AllocHGlobal*
*PtrToStructure*
*StructureToPtr*
*FreeHGlobal*
*IntPtr*
*MemoryStream*
*DeflateStream*
*FromBase64String*
*EncodedCommand*
*Bypass*
*ToBase64String*
*ExpandString*
*GetPowerShell*
*OpenProcess*
*VirtualAlloc*
*VirtualFree*
*WriteProcessMemory*
*CreateUserThread*
*CloseHandle*
*GetDelegateForFunctionPointer*
*kernel32*
*CreateThread*
*memcpy*
*LoadLibrary*
*GetModuleHandle*
*GetProcAddress*
*VirtualProtect*
*FreeLibrary*
*ReadProcessMemory*
*CreateRemoteThread*
*AdjustTokenPrivileges*
*WriteByte*
*WriteInt32*
*OpenThreadToken*
*PtrToString*
*ZeroFreeGlobalAllocUnicode*
*OpenProcessToken*
*GetTokenInformation*
*SetThreadToken*
*ImpersonateLoggedOnUser*
*RevertToSelf*
*GetLogonSessionData*
*CreateProcessWithToken*
*DuplicateTokenEx*
*OpenWindowStation*
*OpenDesktop*
*MiniDumpWriteDump*
*AddSecurityPackage*
*EnumerateSecurityPackages*
*GetProcessHandle*
*DangerousGetHandle*
*CryptoServiceProvider*
*Cryptography*
*RijndaelManaged*
*SHA1Managed*
*CryptoStream*
*CreateEncryptor*
*CreateDecryptor*
*TransformFinalBlock*
*DeviceIoControl*
*SetInformationProcess*
*PasswordDeriveBytes*
*GetAsyncKeyState*
*GetKeyboardState*
*GetForegroundWindow*
*BindingFlags*
*NonPublic*
*ScriptBlockLogging*
*LogPipelineExecutionDetails*
*ProtectedEventLogging*
*adsisearcher*
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment