Skip to content

Comments

adding powershell#133

Open
Mzack9999 wants to merge 4 commits intomainfrom
feat-powershell
Open

adding powershell#133
Mzack9999 wants to merge 4 commits intomainfrom
feat-powershell

Conversation

@Mzack9999
Copy link
Member

@Mzack9999 Mzack9999 commented Dec 19, 2025

$ cat tpl.yaml
id: pw-echo

info:
  name: PowerShell Echo Test
  author: pdteam
  severity: info
  description: Tests PowerShell execution with an echo-like operation.
  tags: test,powershell,echo

self-contained: true

code:
  - engine:
      - pwsh
      - powershell
      - powershell.exe
    args:
      - -ExecutionPolicy
      - Bypass
    pattern: "*.ps1"
    source: |
      Write-Output "test-output-success"

    matchers:
      - type: word
        words:
          - "test-output-success"
% go run . -t pwsh.yaml -code -debug

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.6.1

                projectdiscovery.io

[INF] Current nuclei version: v3.6.1 (latest)
[INF] Current nuclei-templates version: v10.3.5 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 57
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from test
[DBG] [automatic-windows-updates-disabled] Dumped Executed Source Code for input/stdin: ''
---------------
Source Code:
---------------
Write-Output "test-output-success"


---------------
Command Executed:
---------------
/usr/local/bin/pwsh -ExecutionPolicy Bypass /var/folders/hv/g0ls8b7930x_mn973s_44zpm0000gn/T/nuclei-tmp-3666699316/2483372463.ps1

---------------
Command Output:
---------------
test-output-success

[WRN] Command Output here is stdout+sterr, in response variables they are separate (use -v -svd flags for more details)
[DBG] [automatic-windows-updates-disabled] Dumped Code Execution for 

test-output-success

[pw-echo:word-1] [code] [info] 
[INF] Scan completed in 440.878416ms. 1 matches found.
mzack@MacBookPro nuclei % 

@Mzack9999 Mzack9999 self-assigned this Dec 19, 2025
@Mzack9999 Mzack9999 marked this pull request as ready for review December 19, 2025 23:45
@Mzack9999 Mzack9999 added the Type: Enhancement Most issues will probably ask for additions or changes. label Dec 20, 2025
@Mzack9999 Mzack9999 requested a review from ehsandeep December 21, 2025 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Enhancement Most issues will probably ask for additions or changes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant