Commit Graph

349 Commits

Author SHA1 Message Date
Wietze
e1df4e9f83
Merge remote-tracking branch 'upstream/master' into windows_11_sprint 2022-09-02 17:23:45 +01:00
Grzegorz Tworek
9b70f38986
Create Ldifde.yml 2022-08-31 17:58:30 +02:00
721574n
4b564464fd Added external reference for Rundll32 2022-08-24 12:11:31 +02:00
Oddvar Moe
8283d8d915
Delete Dllhost.yml
https://twitter.com/0gtweet/status/1533804788038647808
2022-06-09 10:51:40 +02:00
Wietze
539c1da0fa
Merge branch 'master' into windows_11_sprint 2022-05-25 09:25:42 +01:00
Kostas
314f585da9
Update Hh.yml
Added SysWoW64 Path
2022-05-24 15:29:03 -07:00
Kostas
aae794c59c
Update Hh.yml
Fixing the full path of the hh.exe binary to C:\Windows\hh.exe
2022-05-24 14:23:18 -07:00
Wietze
7797a1967c
Merge branch 'master' into windows_11_sprint 2022-05-24 08:38:50 +01:00
frack113
f85eeb748a
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219) 2022-05-23 12:35:58 +01:00
Chris "Lopi" Spehn
36945392ca
Merge pull request #201 from wietze/new/Conhost
Adding Conhost.exe LOLBAS
2022-05-19 10:27:10 -06:00
John Dwyer
90b6082f1d Update Rdrleakdiag.yml 2022-05-19 13:30:11 +00:00
John Dwyer
e2493d8ccf Detection Resources and Other Updates (LOLBAS-Project#84)
https://github.com/LOLBAS-Project/LOLBAS/issues/84
2022-05-18 19:00:26 +00:00
John Dwyer
d935f096fd Added rdrleakdiag dump
Added yaml for rdrleakdiag process dumping capability
2022-05-18 18:58:04 +00:00
frack113
d1738b946b
Adding various Sigma references (#213)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-05-17 09:18:45 +01:00
akshat pradhan
79f4cbdb7f
Changed tid to T1105 for downloads (#195) 2022-05-15 20:38:24 +01:00
Wietze
b92ee99627
Addressing @bohops's feedback 2022-05-05 11:12:22 +01:00
Wietze
5c46dd63f5
Giving Hexacorn the proper credit 2022-04-07 15:50:39 +01:00
Wietze
4df2e43c82
Adding Conhost.exe LOLBAS 2022-04-05 18:46:58 +01:00
Wietze
55a7ea9a81
Fixing wlrmdr entry 2022-02-16 21:02:24 +00:00
Moshe Kaplan
12c85eb8f0
Create wlrmdr.yml (#194)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-02-16 20:41:14 +00:00
akshat pradhan
a7f7ec2cc2
Changing ATT&CK TID of wuauclt.exe entry (#193) 2022-01-23 22:24:59 +00:00
Wietze
085aaa37b1
Adding more missed-out entries 2021-12-15 11:50:18 +00:00
Wietze
52302853c9
Merge branch 'master' into windows_11_sprint 2021-12-14 17:39:36 +00:00
Wietze
e51caad3dd
Adding Windows 11 reference to missed-out executables 2021-12-14 16:57:56 +00:00
Wietze
6793a7d238
Fixing various issues identified 2021-12-14 16:50:22 +00:00
Wietze
adf171d089
Applying minor format changes (incorrectly formatted dates, typos, etc.) 2021-12-14 15:53:03 +00:00
Wietze
754a451e76
Updating entries that have been confirmed to be working on Windows 11 (21H2) 2021-12-14 15:51:43 +00:00
Wietze
39d4e815af
Minor formatting changes (redudant backslashes, incorrect dates, typos, etc.) 2021-12-14 14:57:32 +00:00
whickey-r7
18bceb7639
Create Unregmp2.yml
Added a new lolbin, unregmp2.exe, used for proxying execution.
2021-12-06 12:13:24 -05:00
frack113
17899acbb0
Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184) 2021-12-06 11:19:01 +00:00
frack113
2d28767c04
Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183) 2021-11-25 09:42:26 +00:00
Wietze
f7b30775a4
Odbcconf realign to T1218.008, hh.exe to T1218.001 2021-11-16 14:09:37 +00:00
bohops
23dd0236ae
Detection Resources and Other Updates (#179)
* Add detection links for scripts

* Add detection links for OtherMSBins. Fixed and updated as needed.

* Add detection links for MSBins. Fixed and updated as needed.

* Add detection links for oslibraries

* Updating template for Detections

* Removing empty Detection:Sigma entries

* Remove redundant blank line

* Replacing commit URL with file URL

Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2021-11-15 08:19:03 -05:00
Wietze
4860585fb7
Adding CustomShellHost.exe LOLBAS 2021-11-14 23:26:39 +00:00
akshat pradhan
2031916b1a
ATT&CK realignment, typo fixes (#178)
* Corrected Mitre TID for pnputil
* Fixed Command misspells
2021-11-14 17:27:17 +00:00
akshat pradhan
53a4070205 Fixed formating 2021-11-09 08:16:34 +05:30
akshat pradhan
33a8da933c Added AWL Bypass to Ssh.yml 2021-11-09 08:14:43 +05:30
akshat pradhan
dfc7d40b1f Create Ssh 2021-11-08 22:21:37 +05:30
Wietze
2380c506d4
LSASS realign to T1003.001 2021-11-05 20:35:58 +00:00
Wietze
df8c88f4ca
Remaping NTDS entries to T1003.003 2021-11-05 20:32:44 +00:00
Wietze
bc51cb4e03
More changes (mainly changing some T1218 instances to T1202) 2021-11-05 20:19:39 +00:00
Wietze
2577066af9
More changes (mainly changing generic T1218 to dev-specific T1127) 2021-11-05 20:06:57 +00:00
Wietze
8286677dac
Applying more specific subtechniques to Verclsid 2021-11-05 19:38:21 +00:00
Wietze
80e3f67e44
Applying more specific subtechniques to At/Schtasks, closes LOLBAS-Project/LOLBAS#113 2021-11-05 19:33:59 +00:00
Wietze
4f7ec8d2af
MITRE ATT&CK realignment sprint 2021-11-05 18:58:26 +00:00
Ensar Şamil
97f5042a58
Update Certoc.yml (#168)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2021-10-27 10:02:52 +01:00
Oddvar Moe
5db35bb397 Updated msbuild with logger technique 2021-10-26 00:27:35 +02:00
Oddvar Moe
7aeed60864 Updated msbuild with logger technique 2021-10-26 00:19:57 +02:00
Oddvar Moe
b91c7ddab5 Updated msbuild with logger technique 2021-10-26 00:17:08 +02:00
Wietze
d411d9572b
Create Finger.exe (#154)
Closes #24, #123
2021-10-25 12:30:32 +01:00
Wietze
eafc1982f0
Website update 2021-10-25 12:28:09 +01:00
Wietze
234eb99a7d
Formatting 2021-10-25 12:27:00 +01:00
Wietze
afe93672a4
Minor updates 2021-10-25 12:25:13 +01:00
Oddvar Moe
1b15eccf07
Merge branch 'master' into master 2021-10-22 16:46:18 +02:00
Oddvar Moe
58b5eb7513
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:43:28 +02:00
Oddvar Moe
a509625acc
Update OneDriveStandaloneUpdater.yml 2021-10-22 16:41:56 +02:00
Oddvar Moe
70a061d301
Merge pull request #153 from elliotkillick/OneDriveStandaloneUpdater
Create OneDriveStandaloneUpdater.yml
2021-10-22 16:39:14 +02:00
Oddvar Moe
486b5fc1ef
Merge pull request #152 from elliotkillick/SettingSyncHost
Create SettingSyncHost.yml
2021-10-22 16:36:13 +02:00
Oddvar Moe
44f88df089
Update Cmdl32.yml 2021-10-22 16:34:41 +02:00
Oddvar Moe
ccb20e560c
Rename cmdl32.yml to Cmdl32.yml 2021-10-22 16:33:24 +02:00
Oddvar Moe
5a62424a79
Merge pull request #151 from elliotkillick/cmdl32
Create cmdl32.yml
2021-10-22 16:32:42 +02:00
Oddvar Moe
fb9b6d65d5
Update cmdl32.yml 2021-10-22 16:31:54 +02:00
Oddvar Moe
adcb7e0c57
Merge pull request #150 from elliotkillick/OfflineScannerShell
Create OfflineScannerShell.yml
2021-10-22 16:28:33 +02:00
Oddvar Moe
c04d90c533
Merge pull request #149 from elliotkillick/WorkFolders
Create WorkFolders.yml
2021-10-22 16:26:50 +02:00
Oddvar Moe
8c1b97629b
Merge pull request #146 from elliotkillick/PrintBrm
Create PrintBrm.yml
2021-10-22 16:21:21 +02:00
Oddvar Moe
d9e31e2291
Rename fltMC.yml to FltMC.yml 2021-10-22 16:04:27 +02:00
Oddvar Moe
6bda2344eb
Rename certoc.yml to Certoc.yml 2021-10-22 16:04:12 +02:00
Oddvar Moe
e32f944030
Merge pull request #162 from esebese/master
Create certoc.yml
2021-10-22 16:02:20 +02:00
Oddvar Moe
985bda094e
Merge pull request #164 from eral4m/master
Create Stordiag.yml
2021-10-22 15:58:35 +02:00
Oddvar Moe
30a9f90f5f
Update Stordiag.yml 2021-10-22 15:56:52 +02:00
Oddvar Moe
a55e2249c1
Merge branch 'master' into fixing-yaml-issues 2021-10-22 14:53:09 +02:00
Elliot Killick
a1d7fd00c9
Acknowledge John Carroll and their resource 2021-10-21 05:36:18 -04:00
eral4m
8b49ca2054 Update Stordiag.yml 2021-10-21 10:30:54 +01:00
eral4m
b723258dbf Update Stordiag.yml 2021-10-21 10:30:31 +01:00
eral4m
6da5480936 Update Stordiag.yml 2021-10-21 10:14:04 +01:00
eral4m
fd2a31b43b Create Stordiag.yml 2021-10-21 10:00:47 +01:00
Elliot Killick
6fb1882a16
Add resources section 2021-10-18 23:38:45 -04:00
Ensar Şamil
6b6fd3fd62
Create certoc.yml 2021-10-07 13:31:45 +03:00
antonioCoco
87bb8cfd3e
Update Rpcping.yml 2021-09-29 23:31:06 +02:00
antonioCoco
27b1f9bfb1
Update Rpcping.yml 2021-09-29 23:27:16 +02:00
root
b5357cdec0 Adding app-ctrl bypass bins and a few lolscripts 2021-09-26 23:31:30 -04:00
bohops
3475ce1213
Merge pull request #158 from JohnLaTwC/patch-1
Add lolbin for fltMC.exe
2021-09-25 22:47:30 -04:00
bohops
6c20e750e8
Merge pull request #144 from defensivedepth/patch-1
Fix ART link
2021-09-25 22:22:42 -04:00
bohops
198b421d15
Merge pull request #130 from whickey-r7/patch-3
Create IMEWDBLD.yml
2021-09-25 22:07:23 -04:00
John Lambert
ecbc2f817f
Add lolbin for fltMC.exe
Used by redteams for defense evasion to disable drivers used by agents like sysmon

https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py
2021-09-18 17:43:59 -07:00
Ruben
bb73c013fb
Update Finger.yml
Fixed header and footer
2021-08-30 13:30:52 +02:00
Rubén
670a5f1870 Create Finger.exe 2021-08-30 13:16:08 +02:00
Elliot Killick
6e047908a4
Create OneDriveStandaloneUpdater.yml 2021-08-28 05:16:35 -04:00
Elliot Killick
02207882f6
Create cmdl32.yml 2021-08-28 00:55:50 -04:00
Elliot Killick
3b1fd0ea8e
Create SettingSyncHost.yml 2021-08-26 13:35:15 -04:00
Elliot Killick
692a3bf4c2
Remove .exe from command and increase specificity 2021-08-26 12:49:43 -04:00
Elliot Killick
34af96f564
Remove .exe from command 2021-08-26 12:21:34 -04:00
Elliot Killick
084fb83984
Remove .exe from command and increase specificity 2021-08-26 12:07:04 -04:00
bohops
f51a70c03e
Merge pull request #143 from Efraim-Kaplan/patch-1
Fixed Typo
2021-08-26 09:08:40 -04:00
Elliot Killick
d521284bb9
Create DeviceCredentialDeployment.yml 2021-08-16 20:21:48 -04:00
Elliot Killick
26a15f55cf
Create OfflineScannerShell.yml 2021-08-16 19:46:47 -04:00
Elliot Killick
95baee85fd
Create WorkFolders.yml 2021-08-16 19:42:32 -04:00
Elliot Killick
5ba729ee1d
Create fsutil.yml 2021-08-16 19:37:37 -04:00
Elliot Killick
63af8cca3b
Add resources section and improve formatting 2021-07-10 11:54:35 -04:00
Josh Brower
87c3319ad4
Fix ART link 2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d
FIxed typo
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Elliot Killick
8f705bb7a4
Create PrintBrm.yml
New lolbin for zipping & unzipping to and from UNC paths and ADS. The zip file could also serve as a useful form of obfuscation for evading detection.
2021-06-22 02:11:27 +00:00
Parker McGee
bbf14cf4b9
Fix a typo in Findstr.yml
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
whickey-r7
782bc68c7c
Create IMEWDBLD.yml 2021-03-05 11:35:06 -05:00
Oddvar Moe
7c1a4a7959
Merge pull request #125 from wokis/master
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
b79a48f082 Fixed Category on pnputil 2021-01-21 22:54:58 +01:00
Oddvar Moe
2406d99f33
Rename pnputil.yml to Pnputil.yml
Casing
2021-01-21 22:49:19 +01:00
Oddvar Moe
64914b641c Adjusted error on pnputil yml file 2021-01-21 22:48:05 +01:00
Oddvar Moe
5b9c4f63dc
Merge pull request #118 from LuxNoBulIshit/master
Pnputil.exe
2021-01-21 22:42:40 +01:00
Oddvar Moe
394d3c66f9
Merge pull request #112 from zeroSteiner/patch-1
Update the affected operating systems for SyncAppvPublishingServer
2021-01-21 22:35:50 +01:00
Oddvar Moe
97176a0a07
Merge pull request #110 from whickey-r7/patch-2
Create AppInstaller.yml
2021-01-21 22:29:35 +01:00
Oddvar Moe
6774d228a5
Merge pull request #109 from unexpectedBy/patch-2
Create DataSvcUtil.yml
2021-01-21 22:24:02 +01:00
wokis
00935f154e
Update Wsreset.yml
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-20 14:47:23 +01:00
Wietze
5012f95152
Fix Code_Sample field 2021-01-10 15:49:30 +00:00
Wietze
14dca38278
Standardise date formats (see https://yaml.org/type/timestamp.html) 2021-01-10 15:04:52 +00:00
LuxNoBu!!shit
0d819439c5
Create pnputil.exe 2020-12-25 12:14:15 -08:00
Spencer McIntyre
deb249042b
Update the affected operating systems for SyncAppvPublishingServer 2020-12-08 15:32:35 -05:00
whickey-r7
b381d04faf
Create AppInstaller.yml
New lolbin for downloading files in Windows 10.
2020-12-02 11:35:49 -05:00
unload
bfe248b07e
Create DataSvcUtil.yml
Another data exfil way with lolbins
2020-12-01 22:57:09 -03:00
Nasreddine Bencherchali
15d5ff302d
Create Dllhost.yml 2020-11-07 14:22:24 +01:00
Conor Richard
d15172284a
Merge pull request #101 from leo1-1/master
added command to certutil
2020-10-26 19:44:53 -04:00
Conor Richard
5806d33e70
Update Certutil.yml 2020-10-26 19:43:55 -04:00
leo1-1
64d5dffc4b
Delete certutil.yml 2020-10-26 08:59:00 +02:00
leo1-1
76d79ea479
Update Certutil 2020-10-26 08:57:42 +02:00
leo1-1
2166960d4e
changed path 2020-10-26 08:22:58 +02:00
Conor Richard
9a83179ddd
Merge pull request #99 from dtmsecurity/master
Create Wuauclt.yml
2020-10-24 22:29:34 -04:00
Conor Richard
04c0e7ee38
Update Explorer.yml
Fixing alignment in Acknowledgement section
2020-10-22 22:00:05 -04:00
Conor Richard
4f19dbba19
Merge pull request #93 from C3dr1cMFE/add_MpCmdRun_Bypass
Update MpCmdRun.yml
2020-10-22 21:05:37 -04:00
Conor Richard
d281faccd3
Merge pull request #92 from whickey-r7/patch-1
Update Xwizard.yml
2020-10-22 20:57:55 -04:00
Conor Richard
9a6309d8de
Update ConfigSecurityPolicy.yml
Added link to Tweet from author containing an example usage.
2020-10-22 20:38:50 -04:00
@dtmsecurity
651e156583
Create Wuauclt.yml 2020-10-12 19:24:45 +01:00
Cochin, Cedric
13026a481b Update MpCmdRun.yml
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker
2020-09-24 14:09:58 -07:00
whickey-r7
11aa1e503b
Update Xwizard.yml
This lolbin has functionality which allows downloading of files from the internet as well as previously outlined execution functionality.
2020-09-16 16:34:47 +00:00
unload
6a5af9a71c
Create ConfigSecurityPolicy.yml 2020-09-04 07:54:44 -03:00
Rich Rumble
1b00b374b3
Updated per suggestion
Thanks!
2020-09-03 11:46:25 -04:00
Rich Rumble
3078cc3755
Update MpCmdRun.yml
Added note that slashes (/) can also be used as command separators, and that the UA is MpCommunication
Thanks!
2020-09-03 10:39:24 -04:00
Oddvar Moe
63c9bc97c3 Added detection details on mpcmdrun 2020-09-03 15:29:32 +02:00
Oddvar Moe
5c5a218faf Updated links on mpcmdrun 2020-09-03 11:00:56 +02:00
Oddvar Moe
bfccb51085 Added MpCmdRun.exe 2020-09-03 10:55:37 +02:00
Oddvar Moe
9a5e2b114f Fixed the OS versions on Diantz 2020-09-03 10:28:49 +02:00
Oddvar Moe
38a3d406b0
Update and rename pktmon.yml to Pktmon.yml 2020-08-24 09:51:48 +02:00
Oddvar Moe
2bb6404160
Merge pull request #82 from binar-x79/patch-1
Create pktmon.yml
2020-08-24 09:49:44 +02:00
Oddvar Moe
525fc0c1eb Added missing ticks in Diantz 2020-08-24 09:48:07 +02:00
Oddvar Moe
9b290ba808
Update and rename diantz.yml to Diantz.yml 2020-08-24 09:46:09 +02:00
Oddvar Moe
48219b177f
Merge pull request #80 from Tamirye/master
Create diantz.yml
2020-08-24 09:45:12 +02:00
Oddvar Moe
57346d17f4 Changed capitalization inside file 2020-08-24 09:34:56 +02:00
Oddvar Moe
4792d22ddd
Rename vbc.yml to Vbc.yml 2020-08-24 09:33:37 +02:00
Oddvar Moe
380b8cfecd
Rename ilasm.yml to Ilasm.yml 2020-08-24 09:33:22 +02:00
Oddvar Moe
fa3710ede5
Rename certreq.yml to Certreq.yml 2020-08-24 09:32:54 +02:00
Oddvar Moe
a104fbd075
Merge pull request #75 from dtmsecurity/master
Create certreq.yml
2020-08-24 09:30:16 +02:00