antonioCoco 
							
						 
					 
					
						
						
							
						
						87bb8cfd3e 
					 
					
						
						
							
							Update Rpcping.yml  
						
						 
						
						
						
						
					 
					
						2021-09-29 23:31:06 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								antonioCoco 
							
						 
					 
					
						
						
							
						
						27b1f9bfb1 
					 
					
						
						
							
							Update Rpcping.yml  
						
						 
						
						
						
						
					 
					
						2021-09-29 23:27:16 +02:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						741d0f7b36 
					 
					
						
						
							
							Update CL_LoadAssembly.yml  
						
						 
						
						
						
						
					 
					
						2021-09-26 23:35:01 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								root 
							
						 
					 
					
						
						
							
						
						b5357cdec0 
					 
					
						
						
							
							Adding app-ctrl bypass bins and a few lolscripts  
						
						 
						
						
						
						
					 
					
						2021-09-26 23:31:30 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						c48a5ea1ea 
					 
					
						
						
							
							Merge pull request  #159  from timwhitez/master  
						
						 
						
						... 
						
						
						
						Create VSIISExeLauncher.yml 
						
						
					 
					
						2021-09-25 22:51:39 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						3475ce1213 
					 
					
						
						
							
							Merge pull request  #158  from JohnLaTwC/patch-1  
						
						 
						
						... 
						
						
						
						Add lolbin for fltMC.exe 
						
						
					 
					
						2021-09-25 22:47:30 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						cab273394a 
					 
					
						
						
							
							Merge pull request  #126  from ahmadalsabagh/fix  
						
						 
						
						... 
						
						
						
						Fixed the resources link 
						
						
					 
					
						2021-09-25 22:30:23 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						6c20e750e8 
					 
					
						
						
							
							Merge pull request  #144  from defensivedepth/patch-1  
						
						 
						
						... 
						
						
						
						Fix ART link 
						
						
					 
					
						2021-09-25 22:22:42 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						198b421d15 
					 
					
						
						
							
							Merge pull request  #130  from whickey-r7/patch-3  
						
						 
						
						... 
						
						
						
						Create IMEWDBLD.yml 
						
						
					 
					
						2021-09-25 22:07:23 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						c51df24076 
					 
					
						
						
							
							Merge pull request  #129  from SpookySec/cdb-update  
						
						 
						
						... 
						
						
						
						edited cdb.yml 
						
						
					 
					
						2021-09-25 21:40:09 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								TimWhite 
							
						 
					 
					
						
						
							
						
						9336b4d599 
					 
					
						
						
							
							Update VSIISExeLauncher.yml  
						
						 
						
						
						
						
					 
					
						2021-09-24 15:28:39 +08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								TimWhite 
							
						 
					 
					
						
						
							
						
						559d9bc3ff 
					 
					
						
						
							
							Create VSIISExeLauncher.yml  
						
						 
						
						
						
						
					 
					
						2021-09-24 15:28:01 +08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								John Lambert 
							
						 
					 
					
						
						
							
						
						ecbc2f817f 
					 
					
						
						
							
							Add lolbin for fltMC.exe  
						
						 
						
						... 
						
						
						
						Used by redteams for defense evasion to disable drivers used by agents like sysmon
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon 
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py  
						
						
					 
					
						2021-09-18 17:43:59 -07:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bohops 
							
						 
					 
					
						
						
							
						
						f51a70c03e 
					 
					
						
						
							
							Merge pull request  #143  from Efraim-Kaplan/patch-1  
						
						 
						
						... 
						
						
						
						Fixed Typo 
						
						
					 
					
						2021-08-26 09:08:40 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Josh Brower 
							
						 
					 
					
						
						
							
						
						87c3319ad4 
					 
					
						
						
							
							Fix ART link  
						
						 
						
						
						
						
					 
					
						2021-07-06 13:56:24 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Efraim-Kaplan 
							
						 
					 
					
						
						
							
						
						ebf494ae4d 
					 
					
						
						
							
							FIxed typo  
						
						 
						
						... 
						
						
						
						Replaced "handeling" with "handling". 
						
						
					 
					
						2021-07-02 17:33:53 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Parker McGee 
							
						 
					 
					
						
						
							
						
						bbf14cf4b9 
					 
					
						
						
							
							Fix a typo in Findstr.yml  
						
						 
						
						... 
						
						
						
						`finstr.exe` should be `findstr.exe` 
						
						
					 
					
						2021-03-20 16:40:37 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								whickey-r7 
							
						 
					 
					
						
						
							
						
						782bc68c7c 
					 
					
						
						
							
							Create IMEWDBLD.yml  
						
						 
						
						
						
						
					 
					
						2021-03-05 11:35:06 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								SpookySec 
							
						 
					 
					
						
						
							
						
						d539a7dacd 
					 
					
						
						
							
							edited cdb.yml  
						
						 
						
						
						
						
					 
					
						2021-02-12 22:26:16 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								SpookySec 
							
						 
					 
					
						
						
							
						
						84de927a83 
					 
					
						
						
							
							edited cdb.yml  
						
						 
						
						
						
						
					 
					
						2021-02-08 16:28:25 +03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								ahmad 
							
						 
					 
					
						
						
							
						
						3ca7bdc542 
					 
					
						
						
							
							Fixed the url  
						
						 
						
						
						
						
					 
					
						2021-01-22 06:33:58 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						7c1a4a7959 
					 
					
						
						
							
							Merge pull request  #125  from wokis/master  
						
						 
						
						... 
						
						
						
						Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen 
						
						
					 
					
						2021-01-21 22:58:24 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						9ce6984dd7 
					 
					
						
						
							
							Merge pull request  #121  from ahmadalsabagh/adplus.exe  
						
						 
						
						... 
						
						
						
						Create Adplus.yml 
						
						
					 
					
						2021-01-21 22:56:34 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						b79a48f082 
					 
					
						
						
							
							Fixed Category on pnputil  
						
						 
						
						
						
						
					 
					
						2021-01-21 22:54:58 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						515235a202 
					 
					
						
						
							
							Merge pull request  #120  from ahmadalsabagh/remote.exe  
						
						 
						
						... 
						
						
						
						Create remote.yml 
						
						
					 
					
						2021-01-21 22:52:24 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						2406d99f33 
					 
					
						
						
							
							Rename pnputil.yml to Pnputil.yml  
						
						 
						
						... 
						
						
						
						Casing 
						
						
					 
					
						2021-01-21 22:49:19 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						64914b641c 
					 
					
						
						
							
							Adjusted error on pnputil yml file  
						
						 
						
						
						
						
					 
					
						2021-01-21 22:48:05 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						5b9c4f63dc 
					 
					
						
						
							
							Merge pull request  #118  from LuxNoBulIshit/master  
						
						 
						
						... 
						
						
						
						Pnputil.exe 
						
						
					 
					
						2021-01-21 22:42:40 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						394d3c66f9 
					 
					
						
						
							
							Merge pull request  #112  from zeroSteiner/patch-1  
						
						 
						
						... 
						
						
						
						Update the affected operating systems for SyncAppvPublishingServer 
						
						
					 
					
						2021-01-21 22:35:50 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						e9e458d6b7 
					 
					
						
						
							
							Merge pull request  #111  from michalani/patch-1  
						
						 
						
						... 
						
						
						
						Addded missing path for winword.exe 
						
						
					 
					
						2021-01-21 22:32:24 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						97176a0a07 
					 
					
						
						
							
							Merge pull request  #110  from whickey-r7/patch-2  
						
						 
						
						... 
						
						
						
						Create AppInstaller.yml 
						
						
					 
					
						2021-01-21 22:29:35 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						6774d228a5 
					 
					
						
						
							
							Merge pull request  #109  from unexpectedBy/patch-2  
						
						 
						
						... 
						
						
						
						Create DataSvcUtil.yml 
						
						
					 
					
						2021-01-21 22:24:02 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Oddvar Moe 
							
						 
					 
					
						
						
							
						
						1bf91d246a 
					 
					
						
						
							
							Merge pull request  #107  from nasbench/adding-dllhost-lolbin  
						
						 
						
						... 
						
						
						
						Create Dllhost.yml 
						
						
					 
					
						2021-01-21 22:20:03 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								wokis 
							
						 
					 
					
						
						
							
						
						00935f154e 
					 
					
						
						
							
							Update Wsreset.yml  
						
						 
						
						... 
						
						
						
						Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen 
						
						
					 
					
						2021-01-20 14:47:23 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ahmad AS 
							
						 
					 
					
						
						
							
						
						be69f54245 
					 
					
						
						
							
							Update Adplus.yml  
						
						 
						
						
						
						
					 
					
						2021-01-09 03:00:05 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								ahmad 
							
						 
					 
					
						
						
							
						
						080fe4ca5b 
					 
					
						
						
							
							Create Adplus.yml  
						
						 
						
						
						
						
					 
					
						2021-01-09 02:56:32 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ahmad AS 
							
						 
					 
					
						
						
							
						
						4254927f78 
					 
					
						
						
							
							Update Remote.yml  
						
						 
						
						
						
						
					 
					
						2021-01-06 23:31:01 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								ahmad 
							
						 
					 
					
						
						
							
						
						7dab1b916e 
					 
					
						
						
							
							Create remote.yml  
						
						 
						
						
						
						
					 
					
						2021-01-06 20:48:25 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								LuxNoBu!!shit 
							
						 
					 
					
						
						
							
						
						0d819439c5 
					 
					
						
						
							
							Create pnputil.exe  
						
						 
						
						
						
						
					 
					
						2020-12-25 12:14:15 -08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Spencer McIntyre 
							
						 
					 
					
						
						
							
						
						deb249042b 
					 
					
						
						
							
							Update the affected operating systems for SyncAppvPublishingServer  
						
						 
						
						
						
						
					 
					
						2020-12-08 15:32:35 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								michalani 
							
						 
					 
					
						
						
							
						
						36b28ddd98 
					 
					
						
						
							
							Update Winword.yml  
						
						 
						
						
						
						
					 
					
						2020-12-03 01:03:08 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								whickey-r7 
							
						 
					 
					
						
						
							
						
						b381d04faf 
					 
					
						
						
							
							Create AppInstaller.yml  
						
						 
						
						... 
						
						
						
						New lolbin for downloading files in Windows 10. 
						
						
					 
					
						2020-12-02 11:35:49 -05:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								unload 
							
						 
					 
					
						
						
							
						
						bfe248b07e 
					 
					
						
						
							
							Create DataSvcUtil.yml  
						
						 
						
						... 
						
						
						
						Another data exfil way with lolbins 
						
						
					 
					
						2020-12-01 22:57:09 -03:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nasreddine Bencherchali 
							
						 
					 
					
						
						
							
						
						15d5ff302d 
					 
					
						
						
							
							Create Dllhost.yml  
						
						 
						
						
						
						
					 
					
						2020-11-07 14:22:24 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								jesgal 
							
						 
					 
					
						
						
							
						
						483482e3a3 
					 
					
						
						
							
							Create Upload.yml  
						
						 
						
						... 
						
						
						
						File describing the execution of LolBin Update.exe deployed with the installation of Whatsapp on Windows operating systems. 
						
						
					 
					
						2020-11-01 20:09:41 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								jesgal 
							
						 
					 
					
						
						
							
						
						4c67be51c1 
					 
					
						
						
							
							Delete Update.yml  
						
						 
						
						
						
						
					 
					
						2020-11-01 20:05:25 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								jesgal 
							
						 
					 
					
						
						
							
						
						748cfb4223 
					 
					
						
						
							
							Merge pull request  #2  from jesgal/jesgal-persistence-update  
						
						 
						
						... 
						
						
						
						Update Update.yml 
						
						
					 
					
						2020-11-01 19:53:13 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								jesgal 
							
						 
					 
					
						
						
							
						
						31c7d34a00 
					 
					
						
						
							
							Create Update.yml  
						
						 
						
						... 
						
						
						
						This file describes LoLbin Update.exe deployed in the Whatsapp installation for Windows Operating Systems. 
						
						
					 
					
						2020-11-01 19:50:59 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								jesgal 
							
						 
					 
					
						
						
							
						
						9642f81be7 
					 
					
						
						
							
							Update Update.yml  
						
						 
						
						... 
						
						
						
						I update this LolBin to create persistence of payload.exe in the directory "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" by running payload.exe with the argument "--createShortcut" and "--removeShortcut". 
						
						
					 
					
						2020-10-29 09:12:28 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Conor Richard 
							
						 
					 
					
						
						
							
						
						d15172284a 
					 
					
						
						
							
							Merge pull request  #101  from leo1-1/master  
						
						 
						
						... 
						
						
						
						added command to certutil 
						
						
					 
					
						2020-10-26 19:44:53 -04:00