From be69f54245d0f0027b614eb01557c269d6ef79f1 Mon Sep 17 00:00:00 2001 From: Ahmad AS Date: Sat, 9 Jan 2021 03:00:05 -0500 Subject: [PATCH] Update Adplus.yml --- yml/OtherMSBinaries/Adplus.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/yml/OtherMSBinaries/Adplus.yml b/yml/OtherMSBinaries/Adplus.yml index 9e35b3c..d3095d9 100644 --- a/yml/OtherMSBinaries/Adplus.yml +++ b/yml/OtherMSBinaries/Adplus.yml @@ -7,7 +7,7 @@ Commands: - Command: adplus.exe -hang -pn lsass.exe -o c:\users\mr.d0x\output\folder -quiet Description: Creates a memory dump of the lsass process Usecase: Create memory dump and parse it offline - Category: Credentials + Category: Dump Privileges: SYSTEM MitreID: T1003 MitreLink: https://attack.mitre.org/techniques/T1003/ @@ -24,4 +24,4 @@ Resources: Acknowledgement: - Person: mr.d0x Handle: '@mrd0x' ---- \ No newline at end of file +---