Windows Terminal Profile
Location:
%LOCALAPPDATA%\Packages\Microsoft.WindowsTerminal_8wekyb3d8bbwe\LocalState\settings.json
Classification:
| Criteria | Value |
|---|---|
| Permissions | User |
| Security context | User |
| Persistence type | File |
| Code type | EXE |
| Launch type | User initiated1 |
| Impact | Non-destructive |
| OS Version | All OS versions |
| Dependencies | Additional software required2 |
| Toolset | Scriptable |
Description:
- Modify the
settings.jsonlocated in%localappdata%and add a custom profile that contains your payload- Change the
defaultProfilevalue and put your GUID- Add the value
"startOnUserLogin": true
References:
- https://twitter.com/nas_bench/status/1550836225652686848
- https://nasbench.medium.com/persistence-using-windows-terminal-profiles-5035d3fc86fe