mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-10-25 06:45:41 +02:00 
			
		
		
		
	Major changes to Web portal - Small fixes to source files to adjust
This commit is contained in:
		| @@ -12,11 +12,11 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\diagnostics\system\WindowsUpdate\CL_Mutexverifiers.ps1 | ||||
|   - Path: C:\Windows\diagnostics\system\Audio\CL_Mutexverifiers.ps1 | ||||
|   - Path: C:\Windows\diagnostics\system\WindowsUpdate\CL_Mutexverifiers.ps1 | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: | ||||
| Detection: | ||||
|   - IOC: | ||||
|   | ||||
| @@ -12,11 +12,11 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\diagnostics\system\AERO\CL_Invocation.ps1 | ||||
|   - Path: C:\Windows\diagnostics\system\Audio\CL_Invocation.ps1 | ||||
|   - Path: C:\Windows\diagnostics\system\WindowsUpdate\CL_Invocation.ps1 | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: | ||||
| Detection: | ||||
|   - IOC: | ||||
|   | ||||
| @@ -20,9 +20,9 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\System32\manage-bde.wsf | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: | ||||
| Detection: | ||||
|   - IOC: Manage-bde.wsf should normally not be invoked by a user | ||||
|   | ||||
| @@ -12,10 +12,10 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\System32\Printing_Admin_Scripts\en-US\pubprn.vbs | ||||
|   - Path: C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\pubprn.vbs | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: https://raw.githubusercontent.com/LOLBAS-Project/LOLBAS/master/OSScripts/Payload/Pubprn_calc.sct | ||||
| Detection: | ||||
|   - IOC: | ||||
|   | ||||
| @@ -12,10 +12,10 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\System32\slmgr.vbs | ||||
|   - Path: C:\Windows\SysWOW64\slmgr.vbs | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: https://raw.githubusercontent.com/LOLBAS-Project/LOLBAS/master/OSScripts/Payload/Slmgr_calc.sct | ||||
|   - Code: https://raw.githubusercontent.com/LOLBAS-Project/LOLBAS/master/OSScripts/Payload/Slmgr.reg | ||||
| Detection: | ||||
|   | ||||
| @@ -12,9 +12,9 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\System32\SyncAppvPublishingServer.vbs | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: | ||||
| Detection: | ||||
|   - IOC: | ||||
|   | ||||
| @@ -36,10 +36,10 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: C:\Windows\System32\winrm.vbs | ||||
|   - Path: C:\Windows\SysWOW64\winrm.vbs | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: https://raw.githubusercontent.com/LOLBAS-Project/LOLBAS/master/OSScripts/Payload/Slmgr.reg | ||||
|   - Code: https://raw.githubusercontent.com/LOLBAS-Project/LOLBAS/master/OSScripts/Payload/Slmgr_calc.sct | ||||
| Detection: | ||||
|   | ||||
| @@ -12,10 +12,10 @@ Commands: | ||||
|     MitreID: T1216 | ||||
|     MitreLink: https://attack.mitre.org/wiki/Technique/T1216 | ||||
|     OperatingSystem: Windows 10 | ||||
| Full Path: | ||||
| Full_Path: | ||||
|   - Path: c:\Program Files\WindowsPowerShell\Modules\Pester\3.4.0\bin\Pester.bat | ||||
|   - Path: c:\Program Files\WindowsPowerShell\Modules\Pester\*\bin\Pester.bat | ||||
| Code Sample:  | ||||
| Code_Sample:  | ||||
|   - Code: | ||||
| Detection: | ||||
|   - IOC: | ||||
|   | ||||
		Reference in New Issue
	
	Block a user