Slackbot
01/12/2024, 1:32 PMJames Rankin
01/12/2024, 1:33 PMJames Rankin
01/12/2024, 1:34 PMc4rm0
01/12/2024, 1:35 PMJames Rankin
01/12/2024, 1:35 PMc4rm0
01/12/2024, 1:36 PMJames Rankin
01/12/2024, 1:39 PMJames Rankin
01/12/2024, 1:39 PMtaskkill /F /T /IM foo.exe /FI "USERNAME eq target_user"James Rankin
01/12/2024, 1:39 PMJames Rankin
01/12/2024, 1:40 PMRyan Gallier
01/12/2024, 2:54 PMc4rm0
01/12/2024, 2:55 PMRyan Gallier
01/12/2024, 3:08 PMc4rm0
01/16/2024, 1:51 PMc4rm0
01/16/2024, 4:53 PM# Force close the process under the user-context:
$ProcessToClose = "Notepad.exe"
$CurrentUser = $env:UserName
# Load assembly
Add-Type -AssemblyName System.Windows.Forms
Try
{
# Try to kill the process for the specific user:
$ProcessesToClose = Get-WmiObject Win32_Process -Filter "name='$ProcessToClose'" | Where-Object {$_.GetOwner().User -eq "$CurrentUser"} | Select -Expand ProcessID
$ProcessCount = $ProcessesToClose.Count
Stop-Process -Force ($ProcessesToClose)
# Display a message:
$msg = [System.Windows.Forms.Messagebox]::Show("Successfully killed $ProcessCount instance(s) of $ProcessToClose.")
}
Catch
{
# This is what you see if there is an error, or no instances of the process.
$msg = [System.Windows.Forms.Messagebox]::Show("No instances of $ProcessToClose running.")
}