Psr.exe

Windows Problem Steps Recorder, used to record screen and clicks.

Paths

  • c:\windows\system32\psr.exe
  • c:\windows\syswow64\psr.exe

Commands

Reconnaissance

Record a user screen without creating a GUI. You should use "psr.exe /stop" to stop recording and create output file.

Use case: Can be used to take screenshots of the user environment

Privileges: User

psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0

Detection

Resources