Commit Graph

445 Commits

Author SHA1 Message Date
721574n
4b564464fd Added external reference for Rundll32 2022-08-24 12:11:31 +02:00
Oddvar Moe
c53a8ea06e Adjusted comment in command 2022-08-23 15:47:17 +02:00
Oddvar Moe
fdc1b2c827 Update pester.bat with an additional example 2022-08-23 15:44:57 +02:00
fslds
3162825fdc
Split procdump name pattern into two actual names. 2022-08-08 20:27:04 +00:00
Oddvar Moe
8283d8d915
Delete Dllhost.yml
https://twitter.com/0gtweet/status/1533804788038647808
2022-06-09 10:51:40 +02:00
frack113
91350057ce
Add sigma references to CL_LoadAssembly, CLMutexVerifiers entries (#221) 2022-06-04 11:50:35 +01:00
Kostas
314f585da9
Update Hh.yml
Added SysWoW64 Path
2022-05-24 15:29:03 -07:00
Kostas
aae794c59c
Update Hh.yml
Fixing the full path of the hh.exe binary to C:\Windows\hh.exe
2022-05-24 14:23:18 -07:00
frack113
f85eeb748a
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219) 2022-05-23 12:35:58 +01:00
Chris "Lopi" Spehn
36945392ca
Merge pull request #201 from wietze/new/Conhost
Adding Conhost.exe LOLBAS
2022-05-19 10:27:10 -06:00
Chris "Lopi" Spehn
e872ce028b
Merge pull request #214 from jstnk9/master
Added new sigma rule and references to desk.cpl
2022-05-19 10:21:21 -06:00
ManuelBerrueta
68b772a567 Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign shared my Microsoft Security Intelligence. Would be useful reference for Red Teamers/Offensive Security Engineers as well as Blue Teamers/Defenders who reference this open source project/library. 2022-05-19 07:12:37 -07:00
John Dwyer
90b6082f1d Update Rdrleakdiag.yml 2022-05-19 13:30:11 +00:00
John Dwyer
e2493d8ccf Detection Resources and Other Updates (LOLBAS-Project#84)
https://github.com/LOLBAS-Project/LOLBAS/issues/84
2022-05-18 19:00:26 +00:00
John Dwyer
d935f096fd Added rdrleakdiag dump
Added yaml for rdrleakdiag process dumping capability
2022-05-18 18:58:04 +00:00
frack113
d1738b946b
Adding various Sigma references (#213)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-05-17 09:18:45 +01:00
bohops
3571a7ad88
Create AccCheckConsole.yml (#187) 2022-05-15 21:55:16 +01:00
mrd0x
7c2f3231d3
Adding Dump64.exe (#182)
Co-authored-by: mrd0x <mrd0x@example.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-05-15 21:21:45 +01:00
Wietze
b333db4f91
Fixing typo (ieaframe -> ieframe) 2022-05-15 21:06:33 +01:00
akshat pradhan
79f4cbdb7f
Changed tid to T1105 for downloads (#195) 2022-05-15 20:38:24 +01:00
jstnk9
00bc9177bd Added new sigma rule and references
Added new sigma rule and references
2022-05-15 16:42:44 +02:00
bohops
d93539bf9b
Quick fix for syntax and removed IOC 2022-04-29 23:06:41 -04:00
cr1sp4
666e6e8645
Update Desk.yml (#210)
Added Sigma rules.
2022-04-29 22:52:57 -04:00
Wietze
619aafbfa2
Adding extra contributor to Desk.cpl entry 2022-04-28 13:01:35 +01:00
Wietze
4a8bdf4844
Fix casing on Desk.cpl entry 2022-04-27 11:20:13 +01:00
LuxNoBu!!shit
6ed0fb9326
Create Desk.cpl (#207)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-04-27 11:15:15 +01:00
Wietze
e4261b1f02
Fixing typo 2022-04-26 16:59:14 +01:00
Wietze
5c46dd63f5
Giving Hexacorn the proper credit 2022-04-07 15:50:39 +01:00
Wietze
4df2e43c82
Adding Conhost.exe LOLBAS 2022-04-05 18:46:58 +01:00
Wietze
55a7ea9a81
Fixing wlrmdr entry 2022-02-16 21:02:24 +00:00
Moshe Kaplan
12c85eb8f0
Create wlrmdr.yml (#194)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-02-16 20:41:14 +00:00
akshat pradhan
a7f7ec2cc2
Changing ATT&CK TID of wuauclt.exe entry (#193) 2022-01-23 22:24:59 +00:00
whickey-r7
18bceb7639
Create Unregmp2.yml
Added a new lolbin, unregmp2.exe, used for proxying execution.
2021-12-06 12:13:24 -05:00
frack113
17899acbb0
Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184) 2021-12-06 11:19:01 +00:00
frack113
2d28767c04
Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183) 2021-11-25 09:42:26 +00:00
Wietze
f7b30775a4
Odbcconf realign to T1218.008, hh.exe to T1218.001 2021-11-16 14:09:37 +00:00
bohops
23dd0236ae
Detection Resources and Other Updates (#179)
* Add detection links for scripts

* Add detection links for OtherMSBins. Fixed and updated as needed.

* Add detection links for MSBins. Fixed and updated as needed.

* Add detection links for oslibraries

* Updating template for Detections

* Removing empty Detection:Sigma entries

* Remove redundant blank line

* Replacing commit URL with file URL

Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2021-11-15 08:19:03 -05:00
Wietze
4860585fb7
Adding CustomShellHost.exe LOLBAS 2021-11-14 23:26:39 +00:00
akshat pradhan
2031916b1a
ATT&CK realignment, typo fixes (#178)
* Corrected Mitre TID for pnputil
* Fixed Command misspells
2021-11-14 17:27:17 +00:00
akshat pradhan
53a4070205 Fixed formating 2021-11-09 08:16:34 +05:30
akshat pradhan
33a8da933c Added AWL Bypass to Ssh.yml 2021-11-09 08:14:43 +05:30
akshat pradhan
dfc7d40b1f Create Ssh 2021-11-08 22:21:37 +05:30
Wietze
2380c506d4
LSASS realign to T1003.001 2021-11-05 20:35:58 +00:00
Wietze
df8c88f4ca
Remaping NTDS entries to T1003.003 2021-11-05 20:32:44 +00:00
Wietze
8257d60aad
Realigning .ps1 scripts to T1216 2021-11-05 20:29:07 +00:00
Wietze
bc51cb4e03
More changes (mainly changing some T1218 instances to T1202) 2021-11-05 20:19:39 +00:00
Wietze
2577066af9
More changes (mainly changing generic T1218 to dev-specific T1127) 2021-11-05 20:06:57 +00:00
Wietze
8286677dac
Applying more specific subtechniques to Verclsid 2021-11-05 19:38:21 +00:00
Wietze
80e3f67e44
Applying more specific subtechniques to At/Schtasks, closes LOLBAS-Project/LOLBAS#113 2021-11-05 19:33:59 +00:00
Wietze
4f7ec8d2af
MITRE ATT&CK realignment sprint 2021-11-05 18:58:26 +00:00
Ensar Şamil
97f5042a58
Update Certoc.yml (#168)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2021-10-27 10:02:52 +01:00
Oddvar Moe
5db35bb397 Updated msbuild with logger technique 2021-10-26 00:27:35 +02:00
Oddvar Moe
7aeed60864 Updated msbuild with logger technique 2021-10-26 00:19:57 +02:00
Oddvar Moe
b91c7ddab5 Updated msbuild with logger technique 2021-10-26 00:17:08 +02:00
Wietze
ca11578655
Archiving off legacy LOLUtilz 2021-10-25 21:32:59 +01:00
Wietze
fa3ff39cac
Update Nvudisp.yml 2021-10-25 12:33:19 +01:00
Wietze
d411d9572b
Create Finger.exe (#154)
Closes #24, #123
2021-10-25 12:30:32 +01:00
Wietze
eafc1982f0
Website update 2021-10-25 12:28:09 +01:00
Wietze
234eb99a7d
Formatting 2021-10-25 12:27:00 +01:00
Wietze
afe93672a4
Minor updates 2021-10-25 12:25:13 +01:00
Oddvar Moe
7a34f57a31
Update Procdump.yml 2021-10-22 16:49:59 +02:00
Oddvar Moe
e70295bc7c
Merge pull request #163 from ajpc500/master
added procdump dll load
2021-10-22 16:48:46 +02:00
Oddvar Moe
1b15eccf07
Merge branch 'master' into master 2021-10-22 16:46:18 +02:00
Oddvar Moe
58b5eb7513
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:43:28 +02:00
Oddvar Moe
a509625acc
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:41:56 +02:00
Oddvar Moe
70a061d301
Merge pull request #153 from elliotkillick/OneDriveStandaloneUpdater
Create OneDriveStandaloneUpdater.yml
2021-10-22 16:39:14 +02:00
Oddvar Moe
486b5fc1ef
Merge pull request #152 from elliotkillick/SettingSyncHost
Create SettingSyncHost.yml
2021-10-22 16:36:13 +02:00
Oddvar Moe
44f88df089
Update Cmdl32.yml 2021-10-22 16:34:41 +02:00
Oddvar Moe
ccb20e560c
Rename cmdl32.yml to Cmdl32.yml 2021-10-22 16:33:24 +02:00
Oddvar Moe
5a62424a79
Merge pull request #151 from elliotkillick/cmdl32
Create cmdl32.yml
2021-10-22 16:32:42 +02:00
Oddvar Moe
fb9b6d65d5
Update cmdl32.yml 2021-10-22 16:31:54 +02:00
Oddvar Moe
adcb7e0c57
Merge pull request #150 from elliotkillick/OfflineScannerShell
Create OfflineScannerShell.yml
2021-10-22 16:28:33 +02:00
Oddvar Moe
c04d90c533
Merge pull request #149 from elliotkillick/WorkFolders
Create WorkFolders.yml
2021-10-22 16:26:50 +02:00
Oddvar Moe
8c1b97629b
Merge pull request #146 from elliotkillick/PrintBrm
Create PrintBrm.yml
2021-10-22 16:21:21 +02:00
Oddvar Moe
d9e31e2291
Rename fltMC.yml to FltMC.yml 2021-10-22 16:04:27 +02:00
Oddvar Moe
6bda2344eb
Rename certoc.yml to Certoc.yml 2021-10-22 16:04:12 +02:00
Oddvar Moe
e32f944030
Merge pull request #162 from esebese/master
Create certoc.yml
2021-10-22 16:02:20 +02:00
Oddvar Moe
985bda094e
Merge pull request #164 from eral4m/master
Create Stordiag.yml
2021-10-22 15:58:35 +02:00
Oddvar Moe
30a9f90f5f
Update Stordiag.yml 2021-10-22 15:56:52 +02:00
Oddvar Moe
9f9af1cfee
Merge branch 'master' into feat/yamllinting 2021-10-22 15:20:35 +02:00
Oddvar Moe
a55e2249c1
Merge branch 'master' into fixing-yaml-issues 2021-10-22 14:53:09 +02:00
Elliot Killick
a1d7fd00c9
Acknowledge John Carroll and their resource 2021-10-21 05:36:18 -04:00
eral4m
8b49ca2054 Update Stordiag.yml 2021-10-21 10:30:54 +01:00
eral4m
b723258dbf Update Stordiag.yml 2021-10-21 10:30:31 +01:00
eral4m
6da5480936 Update Stordiag.yml 2021-10-21 10:14:04 +01:00
eral4m
fd2a31b43b Create Stordiag.yml 2021-10-21 10:00:47 +01:00
Elliot Killick
6fb1882a16
Add resources section 2021-10-18 23:38:45 -04:00
ajpc500
079e3cd72a added procdump dll load 2021-10-14 17:32:17 +01:00
Ensar Şamil
6b6fd3fd62
Create certoc.yml 2021-10-07 13:31:45 +03:00
antonioCoco
87bb8cfd3e
Update Rpcping.yml 2021-09-29 23:31:06 +02:00
antonioCoco
27b1f9bfb1
Update Rpcping.yml 2021-09-29 23:27:16 +02:00
bohops
741d0f7b36
Update CL_LoadAssembly.yml 2021-09-26 23:35:01 -04:00
root
b5357cdec0 Adding app-ctrl bypass bins and a few lolscripts 2021-09-26 23:31:30 -04:00
bohops
c48a5ea1ea
Merge pull request #159 from timwhitez/master
Create VSIISExeLauncher.yml
2021-09-25 22:51:39 -04:00
bohops
3475ce1213
Merge pull request #158 from JohnLaTwC/patch-1
Add lolbin for fltMC.exe
2021-09-25 22:47:30 -04:00
bohops
cab273394a
Merge pull request #126 from ahmadalsabagh/fix
Fixed the resources link
2021-09-25 22:30:23 -04:00
bohops
6c20e750e8
Merge pull request #144 from defensivedepth/patch-1
Fix ART link
2021-09-25 22:22:42 -04:00
bohops
198b421d15
Merge pull request #130 from whickey-r7/patch-3
Create IMEWDBLD.yml
2021-09-25 22:07:23 -04:00
bohops
c51df24076
Merge pull request #129 from SpookySec/cdb-update
edited cdb.yml
2021-09-25 21:40:09 -04:00
TimWhite
9336b4d599
Update VSIISExeLauncher.yml 2021-09-24 15:28:39 +08:00