mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-11-04 10:39:56 +01:00 
			
		
		
		
	Update Sc.yml Tags
Added Tags: Execute EXE
This commit is contained in:
		@@ -11,6 +11,8 @@ Commands:
 | 
				
			|||||||
    Privileges: User
 | 
					    Privileges: User
 | 
				
			||||||
    MitreID: T1564.004
 | 
					    MitreID: T1564.004
 | 
				
			||||||
    OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
					    OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
				
			||||||
 | 
					    Tags:
 | 
				
			||||||
 | 
					    - Execute: EXE
 | 
				
			||||||
  - Command: sc config <existing> binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" & sc start <existing>
 | 
					  - Command: sc config <existing> binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" & sc start <existing>
 | 
				
			||||||
    Description: Modifies an existing service and executes the file stored in the ADS.
 | 
					    Description: Modifies an existing service and executes the file stored in the ADS.
 | 
				
			||||||
    Usecase: Execute binary file hidden inside an alternate data stream
 | 
					    Usecase: Execute binary file hidden inside an alternate data stream
 | 
				
			||||||
@@ -18,6 +20,8 @@ Commands:
 | 
				
			|||||||
    Privileges: User
 | 
					    Privileges: User
 | 
				
			||||||
    MitreID: T1564.004
 | 
					    MitreID: T1564.004
 | 
				
			||||||
    OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
					    OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
 | 
				
			||||||
 | 
					    Tags:
 | 
				
			||||||
 | 
					    - Execute: EXE
 | 
				
			||||||
Full_Path:
 | 
					Full_Path:
 | 
				
			||||||
  - Path: C:\Windows\System32\sc.exe
 | 
					  - Path: C:\Windows\System32\sc.exe
 | 
				
			||||||
  - Path: C:\Windows\SysWOW64\sc.exe
 | 
					  - Path: C:\Windows\SysWOW64\sc.exe
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user