Start-Transcriptwithout specifying the path will do just fine.
616which had spawned the powershell process (mentioned in point 1) that ran the mimikatz script;
powershell > nc > cmd > powershellinstead of
cmd > nc > cmd > powershell- to no avail.
(cmd > nc > cmd > powershell)process ancestry, same like the first time, where the transcript.txt came back empty. This time, however, the results are different - the output is logged this time:
-version 2switch of the powershell.exe binary like so:
System.Management.Automation.dll- you can find its location by using powershell:
PS C:\Users\mantvydas> [psobject].assembly.location
bypass.exealthough the file got successfully created!