wokis 
							
						 
					 
					
						
						
							
						
						00935f154e 
					 
					
						
						
							
							Update Wsreset.yml  
						
						 
						
						... 
						
						
						
						Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen 
						
						
					 
					
						2021-01-20 14:47:23 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						d15172284a 
					 
					
						
						
							
							Merge pull request  #101  from leo1-1/master  
						
						 
						
						... 
						
						
						
						added command to certutil 
						
						
					 
					
						2020-10-26 19:44:53 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						5806d33e70 
					 
					
						
						
							
							Update Certutil.yml  
						
						 
						
						
						
						
					 
					
						2020-10-26 19:43:55 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								leo1-1 
							
						 
					 
					
						
						
							
						
						64d5dffc4b 
					 
					
						
						
							
							Delete certutil.yml  
						
						 
						
						
						
						
					 
					
						2020-10-26 08:59:00 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								leo1-1 
							
						 
					 
					
						
						
							
						
						76d79ea479 
					 
					
						
						
							
							Update Certutil  
						
						 
						
						
						
						
					 
					
						2020-10-26 08:57:42 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								leo1-1 
							
						 
					 
					
						
						
							
						
						2166960d4e 
					 
					
						
						
							
							changed path  
						
						 
						
						
						
						
					 
					
						2020-10-26 08:22:58 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						9a83179ddd 
					 
					
						
						
							
							Merge pull request  #99  from dtmsecurity/master  
						
						 
						
						... 
						
						
						
						Create Wuauclt.yml 
						
						
					 
					
						2020-10-24 22:29:34 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						04c0e7ee38 
					 
					
						
						
							
							Update Explorer.yml  
						
						 
						
						... 
						
						
						
						Fixing alignment in Acknowledgement section 
						
						
					 
					
						2020-10-22 22:00:05 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						4f19dbba19 
					 
					
						
						
							
							Merge pull request  #93  from C3dr1cMFE/add_MpCmdRun_Bypass  
						
						 
						
						... 
						
						
						
						Update MpCmdRun.yml 
						
						
					 
					
						2020-10-22 21:05:37 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						d281faccd3 
					 
					
						
						
							
							Merge pull request  #92  from whickey-r7/patch-1  
						
						 
						
						... 
						
						
						
						Update Xwizard.yml 
						
						
					 
					
						2020-10-22 20:57:55 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						9a6309d8de 
					 
					
						
						
							
							Update ConfigSecurityPolicy.yml  
						
						 
						
						... 
						
						
						
						Added link to Tweet from author containing an example usage. 
						
						
					 
					
						2020-10-22 20:38:50 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								@dtmsecurity 
							
						 
					 
					
						
						
							
						
						651e156583 
					 
					
						
						
							
							Create Wuauclt.yml  
						
						 
						
						
						
						
					 
					
						2020-10-12 19:24:45 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Cochin, Cedric 
							
						 
					 
					
						
						
							
						
						13026a481b 
					 
					
						
						
							
							Update MpCmdRun.yml  
						
						 
						
						... 
						
						
						
						DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker 
						
						
					 
					
						2020-09-24 14:09:58 -07:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								whickey-r7 
							
						 
					 
					
						
						
							
						
						11aa1e503b 
					 
					
						
						
							
							Update Xwizard.yml  
						
						 
						
						... 
						
						
						
						This lolbin has functionality which allows downloading of files from the internet as well as previously outlined execution functionality. 
						
						
					 
					
						2020-09-16 16:34:47 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								unload 
							
						 
					 
					
						
						
							
						
						6a5af9a71c 
					 
					
						
						
							
							Create ConfigSecurityPolicy.yml  
						
						 
						
						
						
						
					 
					
						2020-09-04 07:54:44 -03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Rich Rumble 
							
						 
					 
					
						
						
							
						
						1b00b374b3 
					 
					
						
						
							
							Updated per suggestion  
						
						 
						
						... 
						
						
						
						Thanks! 
						
						
					 
					
						2020-09-03 11:46:25 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Rich Rumble 
							
						 
					 
					
						
						
							
						
						3078cc3755 
					 
					
						
						
							
							Update MpCmdRun.yml  
						
						 
						
						... 
						
						
						
						Added note that slashes (/) can also be used as command separators, and that the UA is MpCommunication
Thanks! 
						
						
					 
					
						2020-09-03 10:39:24 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						63c9bc97c3 
					 
					
						
						
							
							Added detection details on mpcmdrun  
						
						 
						
						
						
						
					 
					
						2020-09-03 15:29:32 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						5c5a218faf 
					 
					
						
						
							
							Updated links on mpcmdrun  
						
						 
						
						
						
						
					 
					
						2020-09-03 11:00:56 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						bfccb51085 
					 
					
						
						
							
							Added MpCmdRun.exe  
						
						 
						
						
						
						
					 
					
						2020-09-03 10:55:37 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						9a5e2b114f 
					 
					
						
						
							
							Fixed the OS versions on Diantz  
						
						 
						
						
						
						
					 
					
						2020-09-03 10:28:49 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						38a3d406b0 
					 
					
						
						
							
							Update and rename pktmon.yml to Pktmon.yml  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:51:48 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						2bb6404160 
					 
					
						
						
							
							Merge pull request  #82  from binar-x79/patch-1  
						
						 
						
						... 
						
						
						
						Create pktmon.yml 
						
						
					 
					
						2020-08-24 09:49:44 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						525fc0c1eb 
					 
					
						
						
							
							Added missing ticks in Diantz  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:48:07 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						9b290ba808 
					 
					
						
						
							
							Update and rename diantz.yml to Diantz.yml  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:46:09 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						48219b177f 
					 
					
						
						
							
							Merge pull request  #80  from Tamirye/master  
						
						 
						
						... 
						
						
						
						Create diantz.yml 
						
						
					 
					
						2020-08-24 09:45:12 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						57346d17f4 
					 
					
						
						
							
							Changed capitalization inside file  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:34:56 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						4792d22ddd 
					 
					
						
						
							
							Rename vbc.yml to Vbc.yml  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:33:37 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						380b8cfecd 
					 
					
						
						
							
							Rename ilasm.yml to Ilasm.yml  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:33:22 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						fa3710ede5 
					 
					
						
						
							
							Rename certreq.yml to Certreq.yml  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:32:54 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						a104fbd075 
					 
					
						
						
							
							Merge pull request  #75  from dtmsecurity/master  
						
						 
						
						... 
						
						
						
						Create certreq.yml 
						
						
					 
					
						2020-08-24 09:30:16 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						2cf7d8cdeb 
					 
					
						
						
							
							Adjusted missing ticks in Acknowledgement  
						
						 
						
						
						
						
					 
					
						2020-08-24 09:28:38 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						84a6cd8e85 
					 
					
						
						
							
							Merge pull request  #66  from GoSecure/gosecure/ttdinject  
						
						 
						
						... 
						
						
						
						Added proxy execution for ttdinject.exe 
						
						
					 
					
						2020-08-24 09:25:29 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						2dabdb0840 
					 
					
						
						
							
							adjusted extrac32 yml error  
						
						 
						
						
						
						
					 
					
						2020-08-15 00:13:16 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						a24bc5b946 
					 
					
						
						
							
							Merge pull request  #79  from LuxNoBulIshit/master  
						
						 
						
						... 
						
						
						
						add new usecase for Extrace32.exe 
						
						
					 
					
						2020-08-15 00:05:37 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						631996950a 
					 
					
						
						
							
							Update Extrac32.yml  
						
						 
						
						
						
						
					 
					
						2020-08-15 00:05:16 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								binar-x79 
							
						 
					 
					
						
						
							
						
						eb0279838b 
					 
					
						
						
							
							Create pktmon.yml  
						
						 
						
						
						
						
					 
					
						2020-08-12 22:04:03 -07:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Tamirye 
							
						 
					 
					
						
						
							
						
						4db780e0f0 
					 
					
						
						
							
							Create diantz.yml  
						
						 
						
						... 
						
						
						
						use daintz.exe to download and compress a binary file from a remote server\internet or use it to store file in Alternate data stream. 
						
						
					 
					
						2020-08-08 15:09:53 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								LuxNoBu!!shit 
							
						 
					 
					
						
						
							
						
						be19ca53ed 
					 
					
						
						
							
							Update Extrac32.yml  
						
						 
						
						
						
						
					 
					
						2020-08-08 15:02:05 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								LuxNoBu!!shit 
							
						 
					 
					
						
						
							
						
						2450b9fc0a 
					 
					
						
						
							
							Update Extrac32.yml  
						
						 
						
						
						
						
					 
					
						2020-08-08 15:01:46 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								LuxNoBu!!shit 
							
						 
					 
					
						
						
							
						
						3a3d28e496 
					 
					
						
						
							
							Update Extrac32.yml  
						
						 
						
						... 
						
						
						
						another use case for extrace32. 
						
						
					 
					
						2020-08-08 14:59:15 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Chris "Lopi" Spehn 
							
						 
					 
					
						
						
							
						
						689c3b1fea 
					 
					
						
						
							
							Update Regsvcs.yml  
						
						 
						
						... 
						
						
						
						Fixed inaccurate permissions 
						
						
					 
					
						2020-08-04 07:40:48 -06:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								@dtmsecurity 
							
						 
					 
					
						
						
							
						
						aa88bf8144 
					 
					
						
						
							
							Create certreq.yml  
						
						 
						
						
						
						
					 
					
						2020-07-07 21:09:06 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Maxime Nadeau 
							
						 
					 
					
						
						
							
						
						640e7f2d65 
					 
					
						
						
							
							Added a Windows 10 2004 version  
						
						 
						
						
						
						
					 
					
						2020-07-03 16:59:53 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						343a0e2478 
					 
					
						
						
							
							Added plain explorer execution  
						
						 
						
						
						
						
					 
					
						2020-07-03 15:03:07 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						a976eaefe1 
					 
					
						
						
							
							Updated Mitre Reference - T1096  
						
						 
						
						
						
						
					 
					
						2020-07-03 10:35:01 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						f1a7ad92dd 
					 
					
						
						
							
							Changed privilege level for registration  
						
						 
						
						
						
						
					 
					
						2020-07-03 10:24:34 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						cb3a45008e 
					 
					
						
						
							
							Added regini.exe writing to registry using ADS  
						
						 
						
						
						
						
					 
					
						2020-07-03 15:40:58 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						420860e5f7 
					 
					
						
						
							
							Adjusted some missing quotes and stuff on Dekstopimgdownldr  
						
						 
						
						
						
						
					 
					
						2020-07-03 15:05:33 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						7dfbc7af67 
					 
					
						
						
							
							Update and rename desktopimgdownldr.yml to Desktopimgdownldr.yml  
						
						 
						
						... 
						
						
						
						Changed capitalization 
						
						
					 
					
						2020-07-03 15:04:09 +02:00