bohops
							
						 
					 | 
					
						
						
							
						
						198b421d15
					 | 
					
						
						
							
							Merge pull request #130 from whickey-r7/patch-3
						
						
						
						
						
						
						
						Create IMEWDBLD.yml 
						
						
					 | 
					
						2021-09-25 22:07:23 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						c51df24076
					 | 
					
						
						
							
							Merge pull request #129 from SpookySec/cdb-update
						
						
						
						
						
						
						
						edited cdb.yml 
						
						
					 | 
					
						2021-09-25 21:40:09 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								TimWhite
							
						 
					 | 
					
						
						
							
						
						9336b4d599
					 | 
					
						
						
							
							Update VSIISExeLauncher.yml
						
						
						
						
						
						
					 | 
					
						2021-09-24 15:28:39 +08:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								TimWhite
							
						 
					 | 
					
						
						
							
						
						559d9bc3ff
					 | 
					
						
						
							
							Create VSIISExeLauncher.yml
						
						
						
						
						
						
					 | 
					
						2021-09-24 15:28:01 +08:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Lambert
							
						 
					 | 
					
						
						
							
						
						ecbc2f817f
					 | 
					
						
						
							
							Add lolbin for fltMC.exe
						
						
						
						
						
						
						
						Used by redteams for defense evasion to disable drivers used by agents like sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py 
						
						
					 | 
					
						2021-09-18 17:43:59 -07:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Ruben
							
						 
					 | 
					
						
						
							
						
						bb73c013fb
					 | 
					
						
						
							
							Update Finger.yml
						
						
						
						
						
						
						
						Fixed header and footer 
						
						
					 | 
					
						2021-08-30 13:30:52 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Rubén
							
						 
					 | 
					
						
						
							
						
						670a5f1870
					 | 
					
						
						
							
							Create Finger.exe
						
						
						
						
						
						
					 | 
					
						2021-08-30 13:16:08 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						6e047908a4
					 | 
					
						
						
							
							Create OneDriveStandaloneUpdater.yml
						
						
						
						
						
						
					 | 
					
						2021-08-28 05:16:35 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						02207882f6
					 | 
					
						
						
							
							Create cmdl32.yml
						
						
						
						
						
						
					 | 
					
						2021-08-28 00:55:50 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						3b1fd0ea8e
					 | 
					
						
						
							
							Create SettingSyncHost.yml
						
						
						
						
						
						
					 | 
					
						2021-08-26 13:35:15 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						692a3bf4c2
					 | 
					
						
						
							
							Remove .exe from command and increase specificity
						
						
						
						
						
						
					 | 
					
						2021-08-26 12:49:43 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						34af96f564
					 | 
					
						
						
							
							Remove .exe from command
						
						
						
						
						
						
					 | 
					
						2021-08-26 12:21:34 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						084fb83984
					 | 
					
						
						
							
							Remove .exe from command and increase specificity
						
						
						
						
						
						
					 | 
					
						2021-08-26 12:07:04 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						f51a70c03e
					 | 
					
						
						
							
							Merge pull request #143 from Efraim-Kaplan/patch-1
						
						
						
						
						
						
						
						Fixed Typo 
						
						
					 | 
					
						2021-08-26 09:08:40 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						d521284bb9
					 | 
					
						
						
							
							Create DeviceCredentialDeployment.yml
						
						
						
						
						
						
					 | 
					
						2021-08-16 20:21:48 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						26a15f55cf
					 | 
					
						
						
							
							Create OfflineScannerShell.yml
						
						
						
						
						
						
					 | 
					
						2021-08-16 19:46:47 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						95baee85fd
					 | 
					
						
						
							
							Create WorkFolders.yml
						
						
						
						
						
						
					 | 
					
						2021-08-16 19:42:32 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						5ba729ee1d
					 | 
					
						
						
							
							Create fsutil.yml
						
						
						
						
						
						
					 | 
					
						2021-08-16 19:37:37 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						63af8cca3b
					 | 
					
						
						
							
							Add resources section and improve formatting
						
						
						
						
						
						
					 | 
					
						2021-07-10 11:54:35 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Josh Brower
							
						 
					 | 
					
						
						
							
						
						87c3319ad4
					 | 
					
						
						
							
							Fix ART link
						
						
						
						
						
						
					 | 
					
						2021-07-06 13:56:24 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Efraim-Kaplan
							
						 
					 | 
					
						
						
							
						
						ebf494ae4d
					 | 
					
						
						
							
							FIxed typo
						
						
						
						
						
						
						
						Replaced "handeling" with "handling". 
						
						
					 | 
					
						2021-07-02 17:33:53 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Elliot Killick
							
						 
					 | 
					
						
						
							
						
						8f705bb7a4
					 | 
					
						
						
							
							Create PrintBrm.yml
						
						
						
						
						
						
						
						New lolbin for zipping & unzipping to and from UNC paths and ADS. The zip file could also serve as a useful form of obfuscation for evading detection. 
						
						
					 | 
					
						2021-06-22 02:11:27 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Parker McGee
							
						 
					 | 
					
						
						
							
						
						bbf14cf4b9
					 | 
					
						
						
							
							Fix a typo in Findstr.yml
						
						
						
						
						
						
						
						`finstr.exe` should be `findstr.exe` 
						
						
					 | 
					
						2021-03-20 16:40:37 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						29acd82968
					 | 
					
						
						
							
							putting quotes around strings with special chars
						
						
						
						
						
						
					 | 
					
						2021-03-09 15:04:09 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						ff9f5cff3d
					 | 
					
						
						
							
							Removing blank lines
						
						
						
						
						
						
					 | 
					
						2021-03-09 15:00:55 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						b0a321e4c4
					 | 
					
						
						
							
							Too many whitespaces
						
						
						
						
						
						
					 | 
					
						2021-03-09 14:58:44 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						a232cfa007
					 | 
					
						
						
							
							Too many empty lines
						
						
						
						
						
						
					 | 
					
						2021-03-09 14:57:47 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						13901ea496
					 | 
					
						
						
							
							Too many whitespaces
						
						
						
						
						
						
					 | 
					
						2021-03-09 14:57:01 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Filipe Spencer Lopes
							
						 
					 | 
					
						
						
							
						
						56035a7d10
					 | 
					
						
						
							
							Too many whitespaces
						
						
						
						
						
						
					 | 
					
						2021-03-09 14:56:47 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								whickey-r7
							
						 
					 | 
					
						
						
							
						
						782bc68c7c
					 | 
					
						
						
							
							Create IMEWDBLD.yml
						
						
						
						
						
						
					 | 
					
						2021-03-05 11:35:06 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SpookySec
							
						 
					 | 
					
						
						
							
						
						d539a7dacd
					 | 
					
						
						
							
							edited cdb.yml
						
						
						
						
						
						
					 | 
					
						2021-02-12 22:26:16 +03:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SpookySec
							
						 
					 | 
					
						
						
							
						
						84de927a83
					 | 
					
						
						
							
							edited cdb.yml
						
						
						
						
						
						
					 | 
					
						2021-02-08 16:28:25 +03:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								ahmad
							
						 
					 | 
					
						
						
							
						
						3ca7bdc542
					 | 
					
						
						
							
							Fixed the url
						
						
						
						
						
						
					 | 
					
						2021-01-22 06:33:58 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						7c1a4a7959
					 | 
					
						
						
							
							Merge pull request #125 from wokis/master
						
						
						
						
						
						
						
						Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen 
						
						
					 | 
					
						2021-01-21 22:58:24 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						9ce6984dd7
					 | 
					
						
						
							
							Merge pull request #121 from ahmadalsabagh/adplus.exe
						
						
						
						
						
						
						
						Create Adplus.yml 
						
						
					 | 
					
						2021-01-21 22:56:34 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						b79a48f082
					 | 
					
						
						
							
							Fixed Category on pnputil
						
						
						
						
						
						
					 | 
					
						2021-01-21 22:54:58 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						515235a202
					 | 
					
						
						
							
							Merge pull request #120 from ahmadalsabagh/remote.exe
						
						
						
						
						
						
						
						Create remote.yml 
						
						
					 | 
					
						2021-01-21 22:52:24 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						2406d99f33
					 | 
					
						
						
							
							Rename pnputil.yml to Pnputil.yml
						
						
						
						
						
						
						
						Casing 
						
						
					 | 
					
						2021-01-21 22:49:19 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						64914b641c
					 | 
					
						
						
							
							Adjusted error on pnputil yml file
						
						
						
						
						
						
					 | 
					
						2021-01-21 22:48:05 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						5b9c4f63dc
					 | 
					
						
						
							
							Merge pull request #118 from LuxNoBulIshit/master
						
						
						
						
						
						
						
						Pnputil.exe 
						
						
					 | 
					
						2021-01-21 22:42:40 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						394d3c66f9
					 | 
					
						
						
							
							Merge pull request #112 from zeroSteiner/patch-1
						
						
						
						
						
						
						
						Update the affected operating systems for SyncAppvPublishingServer 
						
						
					 | 
					
						2021-01-21 22:35:50 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						e9e458d6b7
					 | 
					
						
						
							
							Merge pull request #111 from michalani/patch-1
						
						
						
						
						
						
						
						Addded missing path for winword.exe 
						
						
					 | 
					
						2021-01-21 22:32:24 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						97176a0a07
					 | 
					
						
						
							
							Merge pull request #110 from whickey-r7/patch-2
						
						
						
						
						
						
						
						Create AppInstaller.yml 
						
						
					 | 
					
						2021-01-21 22:29:35 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						6774d228a5
					 | 
					
						
						
							
							Merge pull request #109 from unexpectedBy/patch-2
						
						
						
						
						
						
						
						Create DataSvcUtil.yml 
						
						
					 | 
					
						2021-01-21 22:24:02 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						1bf91d246a
					 | 
					
						
						
							
							Merge pull request #107 from nasbench/adding-dllhost-lolbin
						
						
						
						
						
						
						
						Create Dllhost.yml 
						
						
					 | 
					
						2021-01-21 22:20:03 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								wokis
							
						 
					 | 
					
						
						
							
						
						00935f154e
					 | 
					
						
						
							
							Update Wsreset.yml
						
						
						
						
						
						
						
						Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen 
						
						
					 | 
					
						2021-01-20 14:47:23 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						2e08819eef
					 | 
					
						
						
							
							Fix Usecase field
						
						
						
						
						
						
					 | 
					
						2021-01-10 15:54:00 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						5012f95152
					 | 
					
						
						
							
							Fix Code_Sample field
						
						
						
						
						
						
					 | 
					
						2021-01-10 15:49:30 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						fc223eb3d8
					 | 
					
						
						
							
							Remove/fix unnecessary Categories field
						
						
						
						
						
						
					 | 
					
						2021-01-10 15:48:20 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						5ec4de562b
					 | 
					
						
						
							
							Fixed acknowledgements
						
						
						
						
						
						
					 | 
					
						2021-01-10 15:45:25 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 |