mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-10-25 14:55:19 +02:00 
			
		
		
		
	Merge branch 'master' into windows_11_sprint
This commit is contained in:
		| @@ -14,6 +14,7 @@ Commands: | ||||
| Full_Path: | ||||
|   - Path: C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\AppInstaller.exe | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/bdb00f403fd8ede0daa04449ad913200af9466ff/rules/windows/dns_query/win_dq_lobas_appinstaller.yml | ||||
| Resources: | ||||
|   - Link: https://twitter.com/notwhickey/status/1333900137232523264 | ||||
| Acknowledgement: | ||||
|   | ||||
| @@ -18,10 +18,11 @@ Code_Sample: | ||||
|   - Code: https://github.com/ThunderGunExpress/BringYourOwnBuilder | ||||
| Detection: | ||||
|   - BlockRule: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/960a03eaf480926ed8db464477335a713e9e6630/rules/windows/process_creation/win_pc_lobas_aspnet_compiler.yml | ||||
| Resources: | ||||
|   - Link: https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/ | ||||
|   - Link: https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8 | ||||
| Acknowledgement: | ||||
|   - Person: cpl | ||||
|     Handle: '@cpl3h' | ||||
| --- | ||||
| --- | ||||
| @@ -39,6 +39,7 @@ Code_Sample: | ||||
|   - Code: | ||||
| Detection: | ||||
|   - BlockRule: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/960a03eaf480926ed8db464477335a713e9e6630/rules/windows/process_creation/win_pc_lobas_bash.yml | ||||
|   - IOC: Child process from bash.exe | ||||
| Resources: | ||||
|   - Link: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules | ||||
|   | ||||
| @@ -24,6 +24,7 @@ Full_Path: | ||||
| Code_Sample: | ||||
|   - Code: | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/eb8c9c046b86e7d412bdcc3235693fa1c00f70d6/rules/windows/process_creation/win_susp_certreq_download.yml | ||||
|   - IOC: certreq creates new files | ||||
|   - IOC: certreq makes POST requests | ||||
| Resources: | ||||
|   | ||||
| @@ -16,6 +16,7 @@ Full_Path: | ||||
| Code_Sample: | ||||
|   - Code: | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/5e57e476c29980800dcc88a7a001ddb75d21a58b/rules/windows/process_creation/win_pc_lolbas_configsecuritypolicy.yml | ||||
|   - IOC: ConfigSecurityPolicy storing data into alternate data streams. | ||||
|   - IOC: Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS. | ||||
|   - IOC: Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe. | ||||
|   | ||||
| @@ -24,6 +24,8 @@ Full_Path: | ||||
| Code_Sample: | ||||
|   - Code: | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/0593446f96c57a8b64e2b5b9fd15a20f1c56acab/rules/windows/process_creation/win_pc_lolbas_diantz_ads.yml | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/0f33cbc85bf4b23b8d8308bfcc8b21a9e5431ee7/rules/windows/process_creation/win_pc_lolbas_diantz_remote_cab.yml | ||||
|   - IOC: diantz storing data into alternate data streams. | ||||
|   - IOC: diantz getting a file from a remote machine or the internet. | ||||
| Resources: | ||||
|   | ||||
| @@ -17,6 +17,7 @@ Full_Path: | ||||
| Code_Sample: | ||||
|  - Code: | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/0f33cbc85bf4b23b8d8308bfcc8b21a9e5431ee7/rules/windows/process_creation/win_pc_lolbas_extexport.yml | ||||
|   - IOC: Extexport.exe loads dll and is execute from other folder the original path | ||||
| Resources: | ||||
|   - Link: http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/ | ||||
|   | ||||
| @@ -39,6 +39,8 @@ Code_Sample: | ||||
|   - Code: | ||||
| Detection: | ||||
|  - Elastic: https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml | ||||
|  - Sigma: https://github.com/SigmaHQ/sigma/blob/0f33cbc85bf4b23b8d8308bfcc8b21a9e5431ee7/rules/windows/process_creation/win_pc_lolbas_extrac32.yml | ||||
|  - Sigma: https://github.com/SigmaHQ/sigma/blob/0f33cbc85bf4b23b8d8308bfcc8b21a9e5431ee7/rules/windows/process_creation/win_pc_lolbas_extrac32_ads.yml | ||||
| Resources: | ||||
|   - Link: https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/ | ||||
|   - Link: https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f | ||||
|   | ||||
		Reference in New Issue
	
	Block a user