TryHackMe-Walkthroughs-by-Aby

Room : Windows Local Persistence - Backdooring Files

We will be using the built-in Windows task scheduler Using command: schtasks

Note: keep the name “THM-TaskBackdoor” intact, do not change it, else the flag won’t be retrieved

The script is scheduled to run with SYSTEM privileges

WLP25

WLP26

schtasks /query /tn thm-taskbackdoor

WLP27

WLP29