mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-07-26 04:04:09 +02:00
Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392)
This commit is contained in:
@@ -14,6 +14,8 @@ Commands:
|
||||
Full_Path:
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddinUtil.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\AddInUtil.exe
|
||||
Code_Sample:
|
||||
- Code: https://gist.github.com/SILJAEUROPA/a850d476179d73df230a876944e9f3b1#file-addins-store
|
||||
Detection:
|
||||
|
@@ -21,6 +21,10 @@ Commands:
|
||||
Full_Path:
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\Csc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Csc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\csc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\csc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
|
||||
Code_Sample:
|
||||
- Code:
|
||||
Detection:
|
||||
|
@@ -14,10 +14,10 @@ Commands:
|
||||
Tags:
|
||||
- Download: INetCache
|
||||
Full_Path:
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.xxx\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.xxx\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.xxx\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.xxx\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe
|
||||
Acknowledgement:
|
||||
- Person: Avihay Eldad
|
||||
Handle: '@AvihayEldad'
|
||||
|
@@ -25,8 +25,10 @@ Commands:
|
||||
- Execute: DLL
|
||||
- Input: Custom Format
|
||||
Full_Path:
|
||||
- Path: c:\Windows\Microsoft.NET\Framework\v*\regsvcs.exe
|
||||
- Path: c:\Windows\Microsoft.NET\Framework64\v*\regsvcs.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
|
||||
Detection:
|
||||
- Sigma: https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml
|
||||
- Elastic: https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml
|
||||
|
@@ -23,8 +23,12 @@ Commands:
|
||||
Tags:
|
||||
- Execute: WSH
|
||||
Full_Path:
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\vbc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\vbc.exe
|
||||
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\vbc.exe
|
||||
Code_Sample:
|
||||
- Code:
|
||||
Detection:
|
||||
|
Reference in New Issue
Block a user