Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save trietptm/bc04c3a8b48548731d47aae81197a826 to your computer and use it in GitHub Desktop.
Save trietptm/bc04c3a8b48548731d47aae81197a826 to your computer and use it in GitHub Desktop.
Native Windows UserAgents for Threat Hunting
Invoke-WebRequest:
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.14393.1066
System.Net.WebClient.DownloadFile():
None
Start-BitsTransfer:
Microsoft BITS/7.8
certutil.exe:
"Microsoft-CryptoAPI/10.0" & "CertUtil URL Agent"
regsvr32.exe:
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment