PowerShell AutoRuns Module
Sources:
Overview
About:
AutoRuns module was designed to help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
Installation
Note:
The module is located on theĀ PowerShellGallery
Version Name Repository Description
------- ---- ---------- -----------
14.0.2 AutoRuns PSGallery AutoRuns is a module ...
Stop and please review the content of the module, I mean the code to make sure itās trustworthy.
You can also verify that the SHA256 hashes of downloaded files match those stored in the catalog file.
Usage
Commands
Check available commands:
CommandType Name Version Source
----------- ---- ------- ------
Function Compare-AutoRunsBaseLine 14.0.2 AutoRuns
Function Get-PSAutorun 14.0.2 AutoRuns
Function New-AutoRunsBaseLine 14.0.2 AutoRuns
Syntax
Get-PSAutorun
New-AutoRunsBaseLine
Compare-AutoRunsBaseLine
Examples
Get-PSAutorun
New-AutoRunsBaseLine
Compare-AutoRunsBaseLine
Issues
-
What are registrations in the WMI\Default namespace introduced in Autoruns v13.7? seeĀ c7eab48c77f578e0dcff61d2b46a479b28225a56
-
If you run PowerShell 5.1 and Applocker in allow mode, you need to add a local appplocker rule that allows the module to be loaded. The module files arenāt signed anymore with a DigiCert certificate.
If your corporate admin has turned off local group policy objects processing on a domain joined device, youāll need to add the trusted publisher rule in a Domain group policy.
Other links
- https://live.sysinternals.com
- https://docs.microsoft.com/en-us/sysinternals
- https://docs.microsoft.com/en-us/archive/blogs/sysinternals
OriginalĀ AutorunsĀ from Mark Russinovich
This update to Autoruns, a utility for monitoring startup items, fixes a bug with detecting non-shortcut files in startup folders, fixes a bug with handling non-UNC, non-absolute paths, and improves theming support.
This Autoruns update fixes a bug preventing the enabling/disabling of startup folder items.
This Autoruns update fixes a series of application crashes, now correctly parses paths with spaces passed as command line arguments and improves .arn import functionality.
This Autoruns update can open .arn files from the command line, fixes RunDll32 parameter handling in some cases, supports toggling Active Setup entries, fixes a crash when no ProcExp can be found in the path and improves 32/64 bit redirection.
This Autoruns release fixes a crash happening for scheduled tasks containing spaces.
This update for Autoruns addresses a bug preventing opening and comparing .arn files.
This update for Autoruns adds a series of display/theme fixes, restores autorunsc, fixes a regression for rundll32 entries, limits per-user scans to the user locations, fixes Microsoft entry hiding and adds a high DPI application icon.
This update for Autoruns restores entries previously shown in v13.100, improves Wow64 redirection handling and entry name resolution.
Autoruns, a utility for monitoring startup items, receives a series of UI improvements related to the dark theme and general Windows 10 tweaks, VirusTotal and signed files regressions fixes.
This update for Autoruns fixes a regression with VirusTotal submissions introduced in v14.0.
Autoruns, a utility for monitoring startup items, is the latest Sysinternals tool to receive a UI overhaul including a dark theme.
This update to Autoruns fixes a crash reported in v13.99.
This update to Autoruns fixes a bug that resulted in some empty locations being hidden when the Include Empty Locations option is selected.
This release of Autoruns resolves an issue where Microsoft Defender binaries were being flagged as unsigned.
This Autoruns update adds support for user Shell folders redirections.
This Autoruns update fixes a bug that prevented the correct display of the target of image hosts such as svchost.exe, rundll32.exe, and cmd.exe.
This Autoruns update fixes a bug that prevented UserInitMprLogonScript from being scanned and by-default enables HCKU scanning for the console version.
Autoruns, a comprehensive Windows autostart entry point (ASEP) manager, now includes Runonce*\Depend keys and GPO logon and logoff locations, as well as fixes a bug in WMI path parsing.
This Autoruns release shows Onenote addins and fixes several bugs.
This update to Autoruns fixes a Wow64 bug in Autorunsc that could cause 32-bit paths to result in āfile not foundā errors, and expands the set of images not considered part of Windows for the Windows filter in order to reveal malicious files masquerading as Windows images
This release of Autoruns, a utility for viewing and managing autostart execution points (ASEPs), adds additional autostart entry points, has asynchronous file saving, fixes a bug parsing 32-bit paths on 64-bit Windows, shows the display name for drivers and services, and fixes a bug in offline Virus Total scanning.
This update to Autoruns, a comprehensive autostart execution point manager, adds Microsoft HTML Application Host (mshta.exe) as hosting image so it displays the hosted image details, and now doesnāt apply filters to hosting images.
Autoruns, an autostart entry point management utility, now reports print providers, registrations in the WMI\Default namespace, fixes a KnownDLLs enumeration bug, and has improved toolbar usability on high-DPI displays.
This release of Autoruns, a comprehensive autostart entry manager, fixes a WMI command-line parsing bug, emits a UNICODE BOM in the file generated when saving results to a text file, and adds back the ability to selectively verify the signing status of individual entries.
This update to Autoruns, the most comprehensive autostart viewer and manager available for Windows, now shows 32-bit Office addins and font drivers, and enables resubmission of known images to Virus Total for a new scan.
Autoruns, the most comprehensive utility available for showing what executables, DLLs, and drivers are configured to automatically start and load, now reports Office addins, adds several additional autostart locations, and no longer hides hosting executables like cmd.exe, powershell.exe and others when Windows and Microsoft filters are in effect.
Autoruns, a utility that shows what processes, DLLs, and drivers are configured to automatically load, adds reporting of GP extension DLLs and now shows the target of hosting processes like cmd.exe and rundll32.exe.
In addition to bug fixes to CSV and XML output, Autorunsc introduces import-hash reporting, and Autoruns now excludes command-line and other host processes from the Microsoft and Windows filters.
This release fixes a bug in v13 that caused autostart entry lines not to show when you enter a filter string into the toolbarās filter control
This major update to Autoruns, an autostart execution point (ASEP) manager, now has integration with Virustotal.com to show the status of entries with respect to scans by over four dozen antimalware engines. It also includes a revamped scanning architecture that supports dynamic filters, including a free-form text filter, a greatly improved compare feature that highlights not just new items but deleted ones as well, and file saving and loading that preserves all the information of a scan
This update to Autoruns adds the registered HTML file extension, fixes a bug that could cause disabling of specific entry types to fail with a āpath not foundā error, and addresses another that could prevent the Jump-to-image function from opening the selected image on 64-bit Windows.
This fixes a bug that could cause Autoruns to crash on startup, updates the image path parsing for Installed Components to remove false positive file-not-found entries, and correctly reports image entry timestamps in local time instead of UTC.
This update to Autoruns, a utility that comes in Windows application and command-line forms, has numerous bug fixes, adds a profile attribute/column to CSV and XML output, and interprets the CodeBase value for COM object registrations.
This release of Autoruns, a Windows application and command-line utility for viewing autostart entries, now reports the presence of batch file and executable image entries in the WMI database, a vector used by some types of malware.
This release of Autoruns, a powerful utility for scanning and disabling autostart code, adds a new option to have it show only per-user locations, something that is useful when analyzing the autostarts of different accounts than the one that Autoruns is running under.
This release fixes a bug in version 11.61ās jump-to-image functionality.
Appendix
Note created on 2024-05-17 and last modified on 2024-05-17.
See Also
Backlinks
(c) No Clocks, LLC | 2024