From a61d2586cf6d5b61c118fb8c8f1e96010baba3c6 Mon Sep 17 00:00:00 2001 From: Oddvar Moe Date: Thu, 25 Oct 2018 21:24:55 +0200 Subject: [PATCH] Errors in YAML files corrected --- .../Microsoft.Workflow.Compiler.yml | 40 ++++++++----------- yml/OSBinaries/Schtasks.yml | 23 ++++++----- yml/OSScripts/Winrm.yml | 2 +- 3 files changed, 31 insertions(+), 34 deletions(-) diff --git a/yml/OSBinaries/Microsoft.Workflow.Compiler.yml b/yml/OSBinaries/Microsoft.Workflow.Compiler.yml index 1a7d35b..eec5b16 100644 --- a/yml/OSBinaries/Microsoft.Workflow.Compiler.yml +++ b/yml/OSBinaries/Microsoft.Workflow.Compiler.yml @@ -11,19 +11,11 @@ Commands: Privileges: User MitreID: T1127 MitreLink: https://attack.mitre.org/wiki/Technique/T1127 - OperatingSystem: Windows 10S + OperatingSystem: Windows 10S - Command: Microsoft.Worflow.Compiler.exe tests.txt results.txt Description: Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file. Usecase: Compile and run code - Category: Execution - Privileges: User - MitreID: T1127 - MitreLink: https://attack.mitre.org/wiki/Technique/T1127 - OperatingSystem: Windows 10S - - Command: Microsoft.Worflow.Compiler.exe tests.xml results.xml - Description: Compile and execute C# or VB.net code in a XOML file referenced in the test.xml file. - Usecase: Compile and run code - Category: AWL Bypass + Category: Execute Privileges: User MitreID: T1127 MitreLink: https://attack.mitre.org/wiki/Technique/T1127 @@ -37,22 +29,22 @@ Commands: MitreLink: https://attack.mitre.org/wiki/Technique/T1127 OperatingSystem: Windows 10S Full Path: -- Path: C:\Windows\Microsoft.Net\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe + - Path: C:\Windows\Microsoft.Net\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe Code Sample: - Code: -Detection: -- IOC: Microsoft.Workflow.Compiler.exe would not normally be run on workstations. -- IOC: The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe -- IOC: Presence of "