AutoRDPwn - The Shadow Attack Framework

AutoRDPwn is a script created in Powershell and designed to automate the Shadow attack on Microsoft Windows computers. This vulnerability allows a remote attacker to view his victim's desktop without his consent, and even control it on request. For its correct operation, it is necessary to comply with the requirements described in the user guide.

Powershell 5.0 or higher


Version 4.0
• Fixed a bug in the scheduled task to remove the user AutoRDPwn
• The Scheluded Task attack has been replaced by Invoke-Command
• It is now possible to choose the language of the application and launch the attack on English versions of Windows
*The rest of the changes can be consulted in the CHANGELOG file

Execution in a line:
powershell -ExecutionPolicy Bypass "cd $ env: TEMP; iwr -Outfile AutoRDPwn.ps1;. \ AutoRDPwn.ps1"
The detailed guide of use can be found at the following link:

Credits and Acknowledgments
Mark Russinovich for his tool PsExec ->
Stas'M Corp. for its RDP tool Wrapper ->
Kevin Robertson for his tool Invoke-TheHash ->
Benjamin Delpy for his tool Mimikatz ->

This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.
For more information, you can contact through [email protected]

AutoRDPwn - The Shadow Attack Framework AutoRDPwn - The Shadow Attack Framework Reviewed by Zion3R on 5:46 PM Rating: 5