bohops
741d0f7b36
Update CL_LoadAssembly.yml
2021-09-26 23:35:01 -04:00
root
b5357cdec0
Adding app-ctrl bypass bins and a few lolscripts
2021-09-26 23:31:30 -04:00
bohops
c48a5ea1ea
Merge pull request #159 from timwhitez/master
...
Create VSIISExeLauncher.yml
2021-09-25 22:51:39 -04:00
bohops
3475ce1213
Merge pull request #158 from JohnLaTwC/patch-1
...
Add lolbin for fltMC.exe
2021-09-25 22:47:30 -04:00
bohops
cab273394a
Merge pull request #126 from ahmadalsabagh/fix
...
Fixed the resources link
2021-09-25 22:30:23 -04:00
bohops
6c20e750e8
Merge pull request #144 from defensivedepth/patch-1
...
Fix ART link
2021-09-25 22:22:42 -04:00
bohops
198b421d15
Merge pull request #130 from whickey-r7/patch-3
...
Create IMEWDBLD.yml
2021-09-25 22:07:23 -04:00
bohops
c51df24076
Merge pull request #129 from SpookySec/cdb-update
...
edited cdb.yml
2021-09-25 21:40:09 -04:00
TimWhite
9336b4d599
Update VSIISExeLauncher.yml
2021-09-24 15:28:39 +08:00
TimWhite
559d9bc3ff
Create VSIISExeLauncher.yml
2021-09-24 15:28:01 +08:00
John Lambert
ecbc2f817f
Add lolbin for fltMC.exe
...
Used by redteams for defense evasion to disable drivers used by agents like sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py
2021-09-18 17:43:59 -07:00
bohops
f51a70c03e
Merge pull request #143 from Efraim-Kaplan/patch-1
...
Fixed Typo
2021-08-26 09:08:40 -04:00
Josh Brower
87c3319ad4
Fix ART link
2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d
FIxed typo
...
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Parker McGee
bbf14cf4b9
Fix a typo in Findstr.yml
...
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
whickey-r7
782bc68c7c
Create IMEWDBLD.yml
2021-03-05 11:35:06 -05:00
SpookySec
d539a7dacd
edited cdb.yml
2021-02-12 22:26:16 +03:00
SpookySec
84de927a83
edited cdb.yml
2021-02-08 16:28:25 +03:00
ahmad
3ca7bdc542
Fixed the url
2021-01-22 06:33:58 -05:00
Oddvar Moe
7c1a4a7959
Merge pull request #125 from wokis/master
...
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
9ce6984dd7
Merge pull request #121 from ahmadalsabagh/adplus.exe
...
Create Adplus.yml
2021-01-21 22:56:34 +01:00
Oddvar Moe
b79a48f082
Fixed Category on pnputil
2021-01-21 22:54:58 +01:00
Oddvar Moe
515235a202
Merge pull request #120 from ahmadalsabagh/remote.exe
...
Create remote.yml
2021-01-21 22:52:24 +01:00
Oddvar Moe
2406d99f33
Rename pnputil.yml to Pnputil.yml
...
Casing
2021-01-21 22:49:19 +01:00
Oddvar Moe
64914b641c
Adjusted error on pnputil yml file
2021-01-21 22:48:05 +01:00
Oddvar Moe
5b9c4f63dc
Merge pull request #118 from LuxNoBulIshit/master
...
Pnputil.exe
2021-01-21 22:42:40 +01:00
Oddvar Moe
394d3c66f9
Merge pull request #112 from zeroSteiner/patch-1
...
Update the affected operating systems for SyncAppvPublishingServer
2021-01-21 22:35:50 +01:00
Oddvar Moe
e9e458d6b7
Merge pull request #111 from michalani/patch-1
...
Addded missing path for winword.exe
2021-01-21 22:32:24 +01:00
Oddvar Moe
97176a0a07
Merge pull request #110 from whickey-r7/patch-2
...
Create AppInstaller.yml
2021-01-21 22:29:35 +01:00
Oddvar Moe
6774d228a5
Merge pull request #109 from unexpectedBy/patch-2
...
Create DataSvcUtil.yml
2021-01-21 22:24:02 +01:00
Oddvar Moe
1bf91d246a
Merge pull request #107 from nasbench/adding-dllhost-lolbin
...
Create Dllhost.yml
2021-01-21 22:20:03 +01:00
wokis
00935f154e
Update Wsreset.yml
...
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-20 14:47:23 +01:00
Ahmad AS
be69f54245
Update Adplus.yml
2021-01-09 03:00:05 -05:00
ahmad
080fe4ca5b
Create Adplus.yml
2021-01-09 02:56:32 -05:00
Ahmad AS
4254927f78
Update Remote.yml
2021-01-06 23:31:01 -05:00
ahmad
7dab1b916e
Create remote.yml
2021-01-06 20:48:25 -05:00
LuxNoBu!!shit
0d819439c5
Create pnputil.exe
2020-12-25 12:14:15 -08:00
Spencer McIntyre
deb249042b
Update the affected operating systems for SyncAppvPublishingServer
2020-12-08 15:32:35 -05:00
michalani
36b28ddd98
Update Winword.yml
2020-12-03 01:03:08 +00:00
whickey-r7
b381d04faf
Create AppInstaller.yml
...
New lolbin for downloading files in Windows 10.
2020-12-02 11:35:49 -05:00
unload
bfe248b07e
Create DataSvcUtil.yml
...
Another data exfil way with lolbins
2020-12-01 22:57:09 -03:00
Nasreddine Bencherchali
15d5ff302d
Create Dllhost.yml
2020-11-07 14:22:24 +01:00
jesgal
483482e3a3
Create Upload.yml
...
File describing the execution of LolBin Update.exe deployed with the installation of Whatsapp on Windows operating systems.
2020-11-01 20:09:41 +01:00
jesgal
4c67be51c1
Delete Update.yml
2020-11-01 20:05:25 +01:00
jesgal
748cfb4223
Merge pull request #2 from jesgal/jesgal-persistence-update
...
Update Update.yml
2020-11-01 19:53:13 +01:00
jesgal
31c7d34a00
Create Update.yml
...
This file describes LoLbin Update.exe deployed in the Whatsapp installation for Windows Operating Systems.
2020-11-01 19:50:59 +01:00
jesgal
9642f81be7
Update Update.yml
...
I update this LolBin to create persistence of payload.exe in the directory "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" by running payload.exe with the argument "--createShortcut" and "--removeShortcut".
2020-10-29 09:12:28 +01:00
Conor Richard
d15172284a
Merge pull request #101 from leo1-1/master
...
added command to certutil
2020-10-26 19:44:53 -04:00
Conor Richard
5806d33e70
Update Certutil.yml
2020-10-26 19:43:55 -04:00
leo1-1
64d5dffc4b
Delete certutil.yml
2020-10-26 08:59:00 +02:00