Commit Graph

382 Commits

Author SHA1 Message Date
Oddvar Moe
e70295bc7c
Merge pull request #163 from ajpc500/master
added procdump dll load
2021-10-22 16:48:46 +02:00
Oddvar Moe
1b15eccf07
Merge branch 'master' into master 2021-10-22 16:46:18 +02:00
Oddvar Moe
58b5eb7513
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:43:28 +02:00
Oddvar Moe
a509625acc
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:41:56 +02:00
Oddvar Moe
70a061d301
Merge pull request #153 from elliotkillick/OneDriveStandaloneUpdater
Create OneDriveStandaloneUpdater.yml
2021-10-22 16:39:14 +02:00
Oddvar Moe
486b5fc1ef
Merge pull request #152 from elliotkillick/SettingSyncHost
Create SettingSyncHost.yml
2021-10-22 16:36:13 +02:00
Oddvar Moe
44f88df089
Update Cmdl32.yml 2021-10-22 16:34:41 +02:00
Oddvar Moe
ccb20e560c
Rename cmdl32.yml to Cmdl32.yml 2021-10-22 16:33:24 +02:00
Oddvar Moe
5a62424a79
Merge pull request #151 from elliotkillick/cmdl32
Create cmdl32.yml
2021-10-22 16:32:42 +02:00
Oddvar Moe
fb9b6d65d5
Update cmdl32.yml 2021-10-22 16:31:54 +02:00
Oddvar Moe
adcb7e0c57
Merge pull request #150 from elliotkillick/OfflineScannerShell
Create OfflineScannerShell.yml
2021-10-22 16:28:33 +02:00
Oddvar Moe
c04d90c533
Merge pull request #149 from elliotkillick/WorkFolders
Create WorkFolders.yml
2021-10-22 16:26:50 +02:00
Oddvar Moe
8c1b97629b
Merge pull request #146 from elliotkillick/PrintBrm
Create PrintBrm.yml
2021-10-22 16:21:21 +02:00
Oddvar Moe
d9e31e2291
Rename fltMC.yml to FltMC.yml 2021-10-22 16:04:27 +02:00
Oddvar Moe
6bda2344eb
Rename certoc.yml to Certoc.yml 2021-10-22 16:04:12 +02:00
Oddvar Moe
e32f944030
Merge pull request #162 from esebese/master
Create certoc.yml
2021-10-22 16:02:20 +02:00
Oddvar Moe
985bda094e
Merge pull request #164 from eral4m/master
Create Stordiag.yml
2021-10-22 15:58:35 +02:00
Oddvar Moe
30a9f90f5f
Update Stordiag.yml 2021-10-22 15:56:52 +02:00
Oddvar Moe
9f9af1cfee
Merge branch 'master' into feat/yamllinting 2021-10-22 15:20:35 +02:00
Oddvar Moe
a55e2249c1
Merge branch 'master' into fixing-yaml-issues 2021-10-22 14:53:09 +02:00
Elliot Killick
a1d7fd00c9
Acknowledge John Carroll and their resource 2021-10-21 05:36:18 -04:00
eral4m
8b49ca2054 Update Stordiag.yml 2021-10-21 10:30:54 +01:00
eral4m
b723258dbf Update Stordiag.yml 2021-10-21 10:30:31 +01:00
eral4m
6da5480936 Update Stordiag.yml 2021-10-21 10:14:04 +01:00
eral4m
fd2a31b43b Create Stordiag.yml 2021-10-21 10:00:47 +01:00
Elliot Killick
6fb1882a16
Add resources section 2021-10-18 23:38:45 -04:00
ajpc500
079e3cd72a added procdump dll load 2021-10-14 17:32:17 +01:00
Ensar Şamil
6b6fd3fd62
Create certoc.yml 2021-10-07 13:31:45 +03:00
antonioCoco
87bb8cfd3e
Update Rpcping.yml 2021-09-29 23:31:06 +02:00
antonioCoco
27b1f9bfb1
Update Rpcping.yml 2021-09-29 23:27:16 +02:00
bohops
741d0f7b36
Update CL_LoadAssembly.yml 2021-09-26 23:35:01 -04:00
root
b5357cdec0 Adding app-ctrl bypass bins and a few lolscripts 2021-09-26 23:31:30 -04:00
bohops
c48a5ea1ea
Merge pull request #159 from timwhitez/master
Create VSIISExeLauncher.yml
2021-09-25 22:51:39 -04:00
bohops
3475ce1213
Merge pull request #158 from JohnLaTwC/patch-1
Add lolbin for fltMC.exe
2021-09-25 22:47:30 -04:00
bohops
cab273394a
Merge pull request #126 from ahmadalsabagh/fix
Fixed the resources link
2021-09-25 22:30:23 -04:00
bohops
6c20e750e8
Merge pull request #144 from defensivedepth/patch-1
Fix ART link
2021-09-25 22:22:42 -04:00
bohops
198b421d15
Merge pull request #130 from whickey-r7/patch-3
Create IMEWDBLD.yml
2021-09-25 22:07:23 -04:00
bohops
c51df24076
Merge pull request #129 from SpookySec/cdb-update
edited cdb.yml
2021-09-25 21:40:09 -04:00
TimWhite
9336b4d599
Update VSIISExeLauncher.yml 2021-09-24 15:28:39 +08:00
TimWhite
559d9bc3ff
Create VSIISExeLauncher.yml 2021-09-24 15:28:01 +08:00
John Lambert
ecbc2f817f
Add lolbin for fltMC.exe
Used by redteams for defense evasion to disable drivers used by agents like sysmon

https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py
2021-09-18 17:43:59 -07:00
Ruben
bb73c013fb
Update Finger.yml
Fixed header and footer
2021-08-30 13:30:52 +02:00
Rubén
670a5f1870 Create Finger.exe 2021-08-30 13:16:08 +02:00
Elliot Killick
6e047908a4
Create OneDriveStandaloneUpdater.yml 2021-08-28 05:16:35 -04:00
Elliot Killick
02207882f6
Create cmdl32.yml 2021-08-28 00:55:50 -04:00
Elliot Killick
3b1fd0ea8e
Create SettingSyncHost.yml 2021-08-26 13:35:15 -04:00
Elliot Killick
692a3bf4c2
Remove .exe from command and increase specificity 2021-08-26 12:49:43 -04:00
Elliot Killick
34af96f564
Remove .exe from command 2021-08-26 12:21:34 -04:00
Elliot Killick
084fb83984
Remove .exe from command and increase specificity 2021-08-26 12:07:04 -04:00
bohops
f51a70c03e
Merge pull request #143 from Efraim-Kaplan/patch-1
Fixed Typo
2021-08-26 09:08:40 -04:00
Elliot Killick
26a15f55cf
Create OfflineScannerShell.yml 2021-08-16 19:46:47 -04:00
Elliot Killick
95baee85fd
Create WorkFolders.yml 2021-08-16 19:42:32 -04:00
Elliot Killick
63af8cca3b
Add resources section and improve formatting 2021-07-10 11:54:35 -04:00
Josh Brower
87c3319ad4
Fix ART link 2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d
FIxed typo
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Elliot Killick
8f705bb7a4
Create PrintBrm.yml
New lolbin for zipping & unzipping to and from UNC paths and ADS. The zip file could also serve as a useful form of obfuscation for evading detection.
2021-06-22 02:11:27 +00:00
Parker McGee
bbf14cf4b9
Fix a typo in Findstr.yml
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
Filipe Spencer Lopes
29acd82968 putting quotes around strings with special chars 2021-03-09 15:04:09 +01:00
Filipe Spencer Lopes
ff9f5cff3d Removing blank lines 2021-03-09 15:00:55 +01:00
Filipe Spencer Lopes
b0a321e4c4 Too many whitespaces 2021-03-09 14:58:44 +01:00
Filipe Spencer Lopes
a232cfa007 Too many empty lines 2021-03-09 14:57:47 +01:00
Filipe Spencer Lopes
13901ea496 Too many whitespaces 2021-03-09 14:57:01 +01:00
Filipe Spencer Lopes
56035a7d10 Too many whitespaces 2021-03-09 14:56:47 +01:00
whickey-r7
782bc68c7c
Create IMEWDBLD.yml 2021-03-05 11:35:06 -05:00
SpookySec
d539a7dacd edited cdb.yml 2021-02-12 22:26:16 +03:00
SpookySec
84de927a83 edited cdb.yml 2021-02-08 16:28:25 +03:00
ahmad
3ca7bdc542 Fixed the url 2021-01-22 06:33:58 -05:00
Oddvar Moe
7c1a4a7959
Merge pull request #125 from wokis/master
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
9ce6984dd7
Merge pull request #121 from ahmadalsabagh/adplus.exe
Create Adplus.yml
2021-01-21 22:56:34 +01:00
Oddvar Moe
b79a48f082 Fixed Category on pnputil 2021-01-21 22:54:58 +01:00
Oddvar Moe
515235a202
Merge pull request #120 from ahmadalsabagh/remote.exe
Create remote.yml
2021-01-21 22:52:24 +01:00
Oddvar Moe
2406d99f33
Rename pnputil.yml to Pnputil.yml
Casing
2021-01-21 22:49:19 +01:00
Oddvar Moe
64914b641c Adjusted error on pnputil yml file 2021-01-21 22:48:05 +01:00
Oddvar Moe
5b9c4f63dc
Merge pull request #118 from LuxNoBulIshit/master
Pnputil.exe
2021-01-21 22:42:40 +01:00
Oddvar Moe
394d3c66f9
Merge pull request #112 from zeroSteiner/patch-1
Update the affected operating systems for SyncAppvPublishingServer
2021-01-21 22:35:50 +01:00
Oddvar Moe
e9e458d6b7
Merge pull request #111 from michalani/patch-1
Addded missing path for winword.exe
2021-01-21 22:32:24 +01:00
Oddvar Moe
97176a0a07
Merge pull request #110 from whickey-r7/patch-2
Create AppInstaller.yml
2021-01-21 22:29:35 +01:00
Oddvar Moe
6774d228a5
Merge pull request #109 from unexpectedBy/patch-2
Create DataSvcUtil.yml
2021-01-21 22:24:02 +01:00
Oddvar Moe
1bf91d246a
Merge pull request #107 from nasbench/adding-dllhost-lolbin
Create Dllhost.yml
2021-01-21 22:20:03 +01:00
wokis
00935f154e
Update Wsreset.yml
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-20 14:47:23 +01:00
Wietze
2e08819eef
Fix Usecase field 2021-01-10 15:54:00 +00:00
Wietze
5012f95152
Fix Code_Sample field 2021-01-10 15:49:30 +00:00
Wietze
fc223eb3d8
Remove/fix unnecessary Categories field 2021-01-10 15:48:20 +00:00
Wietze
5ec4de562b
Fixed acknowledgements 2021-01-10 15:45:25 +00:00
Wietze
38f9a0a032
Fixed incorrect MItreLink 2021-01-10 15:26:27 +00:00
Wietze
14dca38278
Standardise date formats (see https://yaml.org/type/timestamp.html) 2021-01-10 15:04:52 +00:00
Wietze
de50a47957
Fix invalid YAML 2021-01-10 14:46:36 +00:00
Ahmad AS
be69f54245
Update Adplus.yml 2021-01-09 03:00:05 -05:00
ahmad
080fe4ca5b Create Adplus.yml 2021-01-09 02:56:32 -05:00
Ahmad AS
4254927f78
Update Remote.yml 2021-01-06 23:31:01 -05:00
ahmad
7dab1b916e Create remote.yml 2021-01-06 20:48:25 -05:00
LuxNoBu!!shit
0d819439c5
Create pnputil.exe 2020-12-25 12:14:15 -08:00
Spencer McIntyre
deb249042b
Update the affected operating systems for SyncAppvPublishingServer 2020-12-08 15:32:35 -05:00
michalani
36b28ddd98
Update Winword.yml 2020-12-03 01:03:08 +00:00
whickey-r7
b381d04faf
Create AppInstaller.yml
New lolbin for downloading files in Windows 10.
2020-12-02 11:35:49 -05:00
unload
bfe248b07e
Create DataSvcUtil.yml
Another data exfil way with lolbins
2020-12-01 22:57:09 -03:00
Nasreddine Bencherchali
15d5ff302d
Create Dllhost.yml 2020-11-07 14:22:24 +01:00
jesgal
483482e3a3
Create Upload.yml
File describing the execution of LolBin Update.exe deployed with the installation of Whatsapp on Windows operating systems.
2020-11-01 20:09:41 +01:00
jesgal
4c67be51c1
Delete Update.yml 2020-11-01 20:05:25 +01:00
jesgal
748cfb4223
Merge pull request #2 from jesgal/jesgal-persistence-update
Update Update.yml
2020-11-01 19:53:13 +01:00