Removing REM from T1112 - causing incorrect execution #2681
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Details:
During an execution run I noticed that atomics were failing due to PowerShell scripts not being enabled on the host system. I traced the issue back to
T1112:95b25212-91a7-42ff-9613-124aca6845a8
and specifically theREM
command that is used in place of a comment. I don't know the specifics as to why this command stops execution but it results in the subsequent deletion command not being executed.This screenshot shows execution of the atomic with the REM command in place, note the EnableScripts registry value remains
This screenshot shows execution of the same atomic with the REM command removed, note the removal of the registry value.
Testing:
Tested on W10
Associated Issues:
None