Update Shell32.yml Tags

Added Tags:
Execute EXE
Execute CMD
This commit is contained in:
hegusung 2024-10-13 18:27:37 +02:00 committed by GitHub
parent a28f2a756a
commit eb9dfdee17
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -20,6 +20,8 @@ Commands:
Privileges: User Privileges: User
MitreID: T1218.011 MitreID: T1218.011
OperatingSystem: Windows 10, Windows 11 OperatingSystem: Windows 10, Windows 11
Tags:
- Execute: EXE
- Command: rundll32 SHELL32.DLL,ShellExec_RunDLL "cmd.exe" "/c echo hi" - Command: rundll32 SHELL32.DLL,ShellExec_RunDLL "cmd.exe" "/c echo hi"
Description: Launch command line by calling the ShellExec_RunDLL function. Description: Launch command line by calling the ShellExec_RunDLL function.
Usecase: Run an executable payload. Usecase: Run an executable payload.
@ -27,6 +29,8 @@ Commands:
Privileges: User Privileges: User
MitreID: T1218.011 MitreID: T1218.011
OperatingSystem: Windows 10, Windows 11 OperatingSystem: Windows 10, Windows 11
Tags:
- Execute: CMD
Full_Path: Full_Path:
- Path: c:\windows\system32\shell32.dll - Path: c:\windows\system32\shell32.dll
- Path: c:\windows\syswow64\shell32.dll - Path: c:\windows\syswow64\shell32.dll