mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-10-25 14:55:19 +02:00 
			
		
		
		
	Addressing @bohops's feedback
This commit is contained in:
		| @@ -15,7 +15,7 @@ Commands: | ||||
|     Description: Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied). | ||||
|     Usecase: Run local or remote script(let) code through INF file specification. | ||||
|     Category: AWL Bypass | ||||
|     Privileges: Admin | ||||
|     Privileges: User | ||||
|     MitreID: T1218.011 | ||||
|     OperatingSystem: Windows 10, Windows 11 | ||||
|   - Command: rundll32.exe advpack.dll,RegisterOCX test.dll | ||||
|   | ||||
| @@ -15,7 +15,7 @@ Commands: | ||||
|     Description: Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied). | ||||
|     Usecase: Run local or remote script(let) code through INF file specification. | ||||
|     Category: AWL Bypass | ||||
|     Privileges: Admin | ||||
|     Privileges: User | ||||
|     MitreID: T1218.011 | ||||
|     OperatingSystem: Windows 10, Windows 11 | ||||
|   - Command: rundll32.exe ieadvpack.dll,RegisterOCX test.dll | ||||
|   | ||||
| @@ -5,7 +5,7 @@ Author: | ||||
| Created: 2018-05-25 | ||||
| Commands: | ||||
|   - Command: rundll32.exe Mshtml.dll,PrintHTML "C:\temp\calc.hta" | ||||
|     Description: Invoke an HTML Application via mshta.exe (Note - Pops a security warning and a print dialogue box). | ||||
|     Description: "Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box)." | ||||
|     Usecase: Launch an HTA application. | ||||
|     Category: Execute | ||||
|     Privileges: User | ||||
|   | ||||
| @@ -4,7 +4,7 @@ Description: COM+ Services | ||||
| Author: | ||||
| Created: 2019-08-30 | ||||
| Commands: | ||||
|   - Command: rundll32 C:\windows\system32\comsvcs.dll MiniDump "[LSASS_PID] dump.bin full" | ||||
|   - Command: powershell /c rundll32 C:\windows\system32\comsvcs.dll MiniDump [LSASS_PID] dump.bin full | ||||
|     Description: Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump. | ||||
|     Usecase: Dump Lsass.exe process memory to retrieve credentials. | ||||
|     Category: Dump | ||||
|   | ||||
		Reference in New Issue
	
	Block a user