Update Setupapi.yml Tags

Changed Input: INF to Execute:INF for consistency
This commit is contained in:
hegusung 2024-10-13 18:25:38 +02:00 committed by GitHub
parent 25047c34d9
commit b1d0a85d2e
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -12,7 +12,7 @@ Commands:
MitreID: T1218.011 MitreID: T1218.011
OperatingSystem: Windows 10, Windows 11 OperatingSystem: Windows 10, Windows 11
Tags: Tags:
- Input: INF - Execute: INF
- Command: rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\Tools\calc_exe.inf - Command: rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\Tools\calc_exe.inf
Description: Launch an executable file via the InstallHinfSection function and .inf file section directive. Description: Launch an executable file via the InstallHinfSection function and .inf file section directive.
Usecase: Load an executable payload. Usecase: Load an executable payload.
@ -21,7 +21,7 @@ Commands:
MitreID: T1218.011 MitreID: T1218.011
OperatingSystem: Windows OperatingSystem: Windows
Tags: Tags:
- Input: INF - Execute: INF
Full_Path: Full_Path:
- Path: c:\windows\system32\setupapi.dll - Path: c:\windows\system32\setupapi.dll
- Path: c:\windows\syswow64\setupapi.dll - Path: c:\windows\syswow64\setupapi.dll