We will use the Windows Instrumentation command-line interface: wmic
$searcher = New-Object DirectoryServices.DirectorySearcher([adsi]"")
#!/bin/bash
There is a good collection for the starting:
Linux-based rescue/repair set for the Windows machines:
Some useful links for the Microsoft Enhanced Mitigation Experience Toolkit:
Kaspersky Ransomware Decryptor: