CL_Mutexverifiers.ps1

type: OSScripts
Proxy execution with CL_Mutexverifiers.ps1

Full path

C:\Windows\diagnostics\system\WindowsUpdate\CL_Mutexverifiers.ps1
C:\Windows\diagnostics\system\Audio\CL_Mutexverifiers.ps1
C:\Windows\diagnostics\system\WindowsUpdate\CL_Mutexverifiers.ps1
C:\Windows\diagnostics\system\Video\CL_Mutexverifiers.ps1
C:\Windows\diagnostics\system\Speech\CL_Mutexverifiers.ps1

Commands

  1. ExecuteUser T1216

    Proxy execution

    . C:\Windows\diagnostics\system\AERO\CL_Mutexverifiers.ps1   \nrunAfterCancelProcess {PATH:.ps1}

    Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.

    os: Windows 10

    Execute: PowerShell

Detection

Resources

acknowledgement: Pierre-Alexandre Braeken @pabraeken