Elliot Killick
02207882f6
Create cmdl32.yml
2021-08-28 00:55:50 -04:00
Elliot Killick
3b1fd0ea8e
Create SettingSyncHost.yml
2021-08-26 13:35:15 -04:00
Elliot Killick
692a3bf4c2
Remove .exe from command and increase specificity
2021-08-26 12:49:43 -04:00
Elliot Killick
34af96f564
Remove .exe from command
2021-08-26 12:21:34 -04:00
Elliot Killick
084fb83984
Remove .exe from command and increase specificity
2021-08-26 12:07:04 -04:00
bohops
f51a70c03e
Merge pull request #143 from Efraim-Kaplan/patch-1
...
Fixed Typo
2021-08-26 09:08:40 -04:00
Elliot Killick
26a15f55cf
Create OfflineScannerShell.yml
2021-08-16 19:46:47 -04:00
Elliot Killick
95baee85fd
Create WorkFolders.yml
2021-08-16 19:42:32 -04:00
Elliot Killick
63af8cca3b
Add resources section and improve formatting
2021-07-10 11:54:35 -04:00
Josh Brower
87c3319ad4
Fix ART link
2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d
FIxed typo
...
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Elliot Killick
8f705bb7a4
Create PrintBrm.yml
...
New lolbin for zipping & unzipping to and from UNC paths and ADS. The zip file could also serve as a useful form of obfuscation for evading detection.
2021-06-22 02:11:27 +00:00
Parker McGee
bbf14cf4b9
Fix a typo in Findstr.yml
...
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
Filipe Spencer Lopes
29acd82968
putting quotes around strings with special chars
2021-03-09 15:04:09 +01:00
Filipe Spencer Lopes
ff9f5cff3d
Removing blank lines
2021-03-09 15:00:55 +01:00
Filipe Spencer Lopes
b0a321e4c4
Too many whitespaces
2021-03-09 14:58:44 +01:00
Filipe Spencer Lopes
a232cfa007
Too many empty lines
2021-03-09 14:57:47 +01:00
Filipe Spencer Lopes
13901ea496
Too many whitespaces
2021-03-09 14:57:01 +01:00
Filipe Spencer Lopes
56035a7d10
Too many whitespaces
2021-03-09 14:56:47 +01:00
whickey-r7
782bc68c7c
Create IMEWDBLD.yml
2021-03-05 11:35:06 -05:00
SpookySec
d539a7dacd
edited cdb.yml
2021-02-12 22:26:16 +03:00
SpookySec
84de927a83
edited cdb.yml
2021-02-08 16:28:25 +03:00
ahmad
3ca7bdc542
Fixed the url
2021-01-22 06:33:58 -05:00
Oddvar Moe
7c1a4a7959
Merge pull request #125 from wokis/master
...
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
9ce6984dd7
Merge pull request #121 from ahmadalsabagh/adplus.exe
...
Create Adplus.yml
2021-01-21 22:56:34 +01:00
Oddvar Moe
b79a48f082
Fixed Category on pnputil
2021-01-21 22:54:58 +01:00
Oddvar Moe
515235a202
Merge pull request #120 from ahmadalsabagh/remote.exe
...
Create remote.yml
2021-01-21 22:52:24 +01:00
Oddvar Moe
2406d99f33
Rename pnputil.yml to Pnputil.yml
...
Casing
2021-01-21 22:49:19 +01:00
Oddvar Moe
64914b641c
Adjusted error on pnputil yml file
2021-01-21 22:48:05 +01:00
Oddvar Moe
5b9c4f63dc
Merge pull request #118 from LuxNoBulIshit/master
...
Pnputil.exe
2021-01-21 22:42:40 +01:00
Oddvar Moe
394d3c66f9
Merge pull request #112 from zeroSteiner/patch-1
...
Update the affected operating systems for SyncAppvPublishingServer
2021-01-21 22:35:50 +01:00
Oddvar Moe
e9e458d6b7
Merge pull request #111 from michalani/patch-1
...
Addded missing path for winword.exe
2021-01-21 22:32:24 +01:00
Oddvar Moe
97176a0a07
Merge pull request #110 from whickey-r7/patch-2
...
Create AppInstaller.yml
2021-01-21 22:29:35 +01:00
Oddvar Moe
6774d228a5
Merge pull request #109 from unexpectedBy/patch-2
...
Create DataSvcUtil.yml
2021-01-21 22:24:02 +01:00
Oddvar Moe
1bf91d246a
Merge pull request #107 from nasbench/adding-dllhost-lolbin
...
Create Dllhost.yml
2021-01-21 22:20:03 +01:00
wokis
00935f154e
Update Wsreset.yml
...
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-20 14:47:23 +01:00
Wietze
2e08819eef
Fix Usecase field
2021-01-10 15:54:00 +00:00
Wietze
5012f95152
Fix Code_Sample field
2021-01-10 15:49:30 +00:00
Wietze
fc223eb3d8
Remove/fix unnecessary Categories field
2021-01-10 15:48:20 +00:00
Wietze
5ec4de562b
Fixed acknowledgements
2021-01-10 15:45:25 +00:00
Wietze
38f9a0a032
Fixed incorrect MItreLink
2021-01-10 15:26:27 +00:00
Wietze
14dca38278
Standardise date formats (see https://yaml.org/type/timestamp.html )
2021-01-10 15:04:52 +00:00
Wietze
de50a47957
Fix invalid YAML
2021-01-10 14:46:36 +00:00
Ahmad AS
be69f54245
Update Adplus.yml
2021-01-09 03:00:05 -05:00
ahmad
080fe4ca5b
Create Adplus.yml
2021-01-09 02:56:32 -05:00
Ahmad AS
4254927f78
Update Remote.yml
2021-01-06 23:31:01 -05:00
ahmad
7dab1b916e
Create remote.yml
2021-01-06 20:48:25 -05:00
LuxNoBu!!shit
0d819439c5
Create pnputil.exe
2020-12-25 12:14:15 -08:00
Spencer McIntyre
deb249042b
Update the affected operating systems for SyncAppvPublishingServer
2020-12-08 15:32:35 -05:00
michalani
36b28ddd98
Update Winword.yml
2020-12-03 01:03:08 +00:00
whickey-r7
b381d04faf
Create AppInstaller.yml
...
New lolbin for downloading files in Windows 10.
2020-12-02 11:35:49 -05:00
unload
bfe248b07e
Create DataSvcUtil.yml
...
Another data exfil way with lolbins
2020-12-01 22:57:09 -03:00
Nasreddine Bencherchali
15d5ff302d
Create Dllhost.yml
2020-11-07 14:22:24 +01:00
jesgal
483482e3a3
Create Upload.yml
...
File describing the execution of LolBin Update.exe deployed with the installation of Whatsapp on Windows operating systems.
2020-11-01 20:09:41 +01:00
jesgal
4c67be51c1
Delete Update.yml
2020-11-01 20:05:25 +01:00
jesgal
748cfb4223
Merge pull request #2 from jesgal/jesgal-persistence-update
...
Update Update.yml
2020-11-01 19:53:13 +01:00
jesgal
31c7d34a00
Create Update.yml
...
This file describes LoLbin Update.exe deployed in the Whatsapp installation for Windows Operating Systems.
2020-11-01 19:50:59 +01:00
jesgal
9642f81be7
Update Update.yml
...
I update this LolBin to create persistence of payload.exe in the directory "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" by running payload.exe with the argument "--createShortcut" and "--removeShortcut".
2020-10-29 09:12:28 +01:00
Conor Richard
d15172284a
Merge pull request #101 from leo1-1/master
...
added command to certutil
2020-10-26 19:44:53 -04:00
Conor Richard
5806d33e70
Update Certutil.yml
2020-10-26 19:43:55 -04:00
leo1-1
64d5dffc4b
Delete certutil.yml
2020-10-26 08:59:00 +02:00
leo1-1
76d79ea479
Update Certutil
2020-10-26 08:57:42 +02:00
leo1-1
2166960d4e
changed path
2020-10-26 08:22:58 +02:00
Conor Richard
9a83179ddd
Merge pull request #99 from dtmsecurity/master
...
Create Wuauclt.yml
2020-10-24 22:29:34 -04:00
Conor Richard
edbd01860c
Merge pull request #97 from MartinSohn/master
...
Create Coregen.yml - Thank you for the contribution!
2020-10-24 21:49:09 -04:00
Conor Richard
04c0e7ee38
Update Explorer.yml
...
Fixing alignment in Acknowledgement section
2020-10-22 22:00:05 -04:00
xenoscr
de169664d6
Finxing missing quotes
2020-10-22 21:51:57 -04:00
Conor Richard
b61cd18072
Merge pull request #94 from checkymander/master
...
Create DefaultPack.yml
2020-10-22 21:19:50 -04:00
Conor Richard
4f19dbba19
Merge pull request #93 from C3dr1cMFE/add_MpCmdRun_Bypass
...
Update MpCmdRun.yml
2020-10-22 21:05:37 -04:00
Conor Richard
d281faccd3
Merge pull request #92 from whickey-r7/patch-1
...
Update Xwizard.yml
2020-10-22 20:57:55 -04:00
Conor Richard
9a6309d8de
Update ConfigSecurityPolicy.yml
...
Added link to Tweet from author containing an example usage.
2020-10-22 20:38:50 -04:00
@dtmsecurity
651e156583
Create Wuauclt.yml
2020-10-12 19:24:45 +01:00
Martin
47c03c97b8
Typo
2020-10-10 19:54:50 +00:00
Martin
22d9bbe92a
Initial commit of Coregen.yml
2020-10-09 17:10:49 +02:00
checkymander
a45d4ca25c
Create DefaultPack.yml
...
Added DefaultPack.EXE LOLBin
2020-10-01 22:37:00 -04:00
Cochin, Cedric
13026a481b
Update MpCmdRun.yml
...
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker
2020-09-24 14:09:58 -07:00
whickey-r7
11aa1e503b
Update Xwizard.yml
...
This lolbin has functionality which allows downloading of files from the internet as well as previously outlined execution functionality.
2020-09-16 16:34:47 +00:00
unload
6a5af9a71c
Create ConfigSecurityPolicy.yml
2020-09-04 07:54:44 -03:00
Rich Rumble
1b00b374b3
Updated per suggestion
...
Thanks!
2020-09-03 11:46:25 -04:00
Rich Rumble
3078cc3755
Update MpCmdRun.yml
...
Added note that slashes (/) can also be used as command separators, and that the UA is MpCommunication
Thanks!
2020-09-03 10:39:24 -04:00
Oddvar Moe
63c9bc97c3
Added detection details on mpcmdrun
2020-09-03 15:29:32 +02:00
Oddvar Moe
5c5a218faf
Updated links on mpcmdrun
2020-09-03 11:00:56 +02:00
Oddvar Moe
bfccb51085
Added MpCmdRun.exe
2020-09-03 10:55:37 +02:00
Oddvar Moe
9a5e2b114f
Fixed the OS versions on Diantz
2020-09-03 10:28:49 +02:00
Oddvar Moe
38a3d406b0
Update and rename pktmon.yml to Pktmon.yml
2020-08-24 09:51:48 +02:00
Oddvar Moe
2bb6404160
Merge pull request #82 from binar-x79/patch-1
...
Create pktmon.yml
2020-08-24 09:49:44 +02:00
Oddvar Moe
525fc0c1eb
Added missing ticks in Diantz
2020-08-24 09:48:07 +02:00
Oddvar Moe
9b290ba808
Update and rename diantz.yml to Diantz.yml
2020-08-24 09:46:09 +02:00
Oddvar Moe
48219b177f
Merge pull request #80 from Tamirye/master
...
Create diantz.yml
2020-08-24 09:45:12 +02:00
Oddvar Moe
c5c6820c56
Rename agentexecutor.yml to Agentexecutor.yml
2020-08-24 09:42:07 +02:00
Oddvar Moe
a7da0deddd
Merge pull request #77 from leftp/master
...
Added method for AgentExecutor
2020-08-24 09:41:22 +02:00
Oddvar Moe
57346d17f4
Changed capitalization inside file
2020-08-24 09:34:56 +02:00
Oddvar Moe
4792d22ddd
Rename vbc.yml to Vbc.yml
2020-08-24 09:33:37 +02:00
Oddvar Moe
380b8cfecd
Rename ilasm.yml to Ilasm.yml
2020-08-24 09:33:22 +02:00
Oddvar Moe
fa3710ede5
Rename certreq.yml to Certreq.yml
2020-08-24 09:32:54 +02:00
Oddvar Moe
a104fbd075
Merge pull request #75 from dtmsecurity/master
...
Create certreq.yml
2020-08-24 09:30:16 +02:00
Oddvar Moe
2cf7d8cdeb
Adjusted missing ticks in Acknowledgement
2020-08-24 09:28:38 +02:00
Oddvar Moe
84a6cd8e85
Merge pull request #66 from GoSecure/gosecure/ttdinject
...
Added proxy execution for ttdinject.exe
2020-08-24 09:25:29 +02:00
Oddvar Moe
8cf6ef53fb
Rename squirrel.yml to Squirrel.yml
2020-08-15 00:27:11 +02:00
Oddvar Moe
39f55359ef
Rename update.yml to Update.yml
2020-08-15 00:26:53 +02:00