frack113
|
01d7580886
|
Add Sigma rule references to various LOLBAS (#260)
|
2022-10-26 09:10:39 +01:00 |
|
Wietze
|
a0556744d1
|
Merge branch 'master' into windows_11_sprint
|
2022-10-04 15:45:57 +01:00 |
|
Wietze
|
6f2135e173
|
Updating category of fltMC to tamper
|
2022-10-04 15:37:56 +01:00 |
|
Daniel Santos
|
4217d0f8ca
|
Adding .NET Core binary createdump.exe (#240)
Co-authored-by: Daniel Santos <vovohelo@gmail.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-10-04 13:23:10 +01:00 |
|
securepeacock
|
461fbaf787
|
Update Powerpnt.yml with Sigma (#222)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-10-04 12:36:49 +01:00 |
|
Wietze
|
76acca6f2b
|
Merge branch 'master' into windows_11_sprint
|
2022-10-04 12:31:31 +01:00 |
|
C-h4ck-0
|
f29471dde9
|
Adding download functionality entries to existing binaries (#239)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-10-04 12:27:31 +01:00 |
|
C-h4ck-0
|
ea68ad824d
|
Adding 3 Microsoft Office-based downloaders (#238)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-10-04 12:13:56 +01:00 |
|
saulpanders
|
83ca9aa197
|
Adding Windows Package Manager tool winget.exe (#188)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-10-04 11:27:47 +01:00 |
|
Wietze
|
67e1040172
|
Merge remote-tracking branch 'upstream/master' into windows_11_sprint
|
2022-10-03 16:18:57 +01:00 |
|
Conor Richard
|
da38f3d8ed
|
Merge pull request #185 from whickey-r7/patch-1
Create Unregmp2.yml
|
2022-09-17 21:38:59 -04:00 |
|
Conor Richard
|
a9e5707f74
|
Removing extra YAML record start "---"
|
2022-09-17 21:37:30 -04:00 |
|
Conor Richard
|
59808608e7
|
Merge pull request #180 from wietze/new/CustomShellHost
Adding CustomShellHost.exe LOLBAS
|
2022-09-17 21:34:04 -04:00 |
|
Conor Richard
|
05faad73b2
|
Removing extra YAML record start "---"
|
2022-09-17 21:32:13 -04:00 |
|
Conor Richard
|
c22d17a116
|
Merge pull request #176 from akat12/Ssh
Create Ssh
|
2022-09-17 21:25:49 -04:00 |
|
Conor Richard
|
14896a1436
|
Removed trailing space on line 3
|
2022-09-17 21:24:04 -04:00 |
|
Conor Richard
|
730359aa0d
|
Changed AWL MitreID and removed extra YAML record start "---"
|
2022-09-17 21:21:13 -04:00 |
|
Conor Richard
|
aa698337ff
|
Merge pull request #148 from elliotkillick/fsutil
Create fsutil.yml
|
2022-09-17 08:10:53 -04:00 |
|
Conor Richard
|
181672267b
|
Adding quotes since the ":" falls at the end to fix linting error
|
2022-09-17 08:09:27 -04:00 |
|
Conor Richard
|
4615fbc582
|
fixing indentation in line 14
|
2022-09-17 08:04:58 -04:00 |
|
Conor Richard
|
2759dd0565
|
Adding USN deletion that @bohops mentioned in #148 notes
|
2022-09-17 08:01:53 -04:00 |
|
Conor Richard
|
e878c66e6f
|
Cleaning YAML, updated new category Tamper
|
2022-09-17 07:55:16 -04:00 |
|
Conor Richard
|
f5c797a888
|
Merge pull request #147 from elliotkillick/DeviceCredentialDeployment
Create DeviceCredentialDeployment.yml
|
2022-09-17 07:52:29 -04:00 |
|
Conor Richard
|
7dd6ca24aa
|
Removing invalid MiterLink key.
|
2022-09-17 07:50:44 -04:00 |
|
Conor Richard
|
1e6d6d23cc
|
Removing extra document start "---" and updating category to Conceal.
|
2022-09-17 07:47:06 -04:00 |
|
Conor Richard
|
61043ccf0b
|
Merge pull request #245 from gtworek/patch-1
Create Ldifde.yml
|
2022-09-17 00:09:22 -04:00 |
|
Conor Richard
|
2689786b59
|
Update Ldifde.yml
Removed trailing spaces.
|
2022-09-17 00:06:25 -04:00 |
|
Conor Richard
|
9875eb2ed2
|
Update Ldifde.yml
Removed final "---". It does not match the current template and schema checks.
|
2022-09-17 00:03:20 -04:00 |
|
Conor Richard
|
2c9a7a97ce
|
Merge pull request #244 from 721574n/tristan_add
Added external reference about Rundll32
|
2022-09-16 23:46:43 -04:00 |
|
Filipe Spencer
|
d780de4ece
|
Prep for new yamllint
|
2022-09-16 11:29:26 +00:00 |
|
Conor Richard
|
3347e43b3f
|
Merge branch 'master' into alias_introduction
|
2022-09-15 13:54:50 -04:00 |
|
xenoscr
|
dfb30f194f
|
Tweaked the Link regex to allow anchor tags and the handle regex to permit blank entries.
|
2022-09-13 23:37:10 -04:00 |
|
xenoscr
|
ee68df7f26
|
Put schema back to previous state and fixed non-compliant Link in At.yml
|
2022-09-13 23:06:42 -04:00 |
|
xenoscr
|
92424a40de
|
Implimenting requested changes from PR #251 review from @wietze.
|
2022-09-13 22:51:52 -04:00 |
|
xenoscr
|
2c3653f0c4
|
Fixing more file formatting issues.
|
2022-09-11 01:36:14 -04:00 |
|
xenoscr
|
654cdd2d61
|
Fixing file formating.
|
2022-09-11 01:33:36 -04:00 |
|
xenoscr
|
3d6a4be2a5
|
Fixing more formatting errors.
|
2022-09-11 01:23:21 -04:00 |
|
xenoscr
|
98813fe01b
|
Fixing errors found in yaml lint action.
|
2022-09-11 01:07:18 -04:00 |
|
xenoscr
|
6e253a7a38
|
Adding missing OperatingSystem values.
|
2022-09-11 00:22:36 -04:00 |
|
xenoscr
|
68e5795aec
|
Fixing Acknowledgement values.
|
2022-09-11 00:20:05 -04:00 |
|
xenoscr
|
aa1e1ea2be
|
Adding no defualt paths to pass schema validations
|
2022-09-11 00:16:59 -04:00 |
|
xenoscr
|
c933426c1a
|
Adding missing Path value.
|
2022-09-11 00:03:30 -04:00 |
|
xenoscr
|
1bd305e3a3
|
Adding missing Usecase values.
|
2022-09-10 23:53:21 -04:00 |
|
xenoscr
|
c24cad7868
|
Adding missing OperatingSystem values.
|
2022-09-10 23:48:38 -04:00 |
|
xenoscr
|
371d1cf2cc
|
Correcting case in Usecase key names.
|
2022-09-10 23:45:28 -04:00 |
|
xenoscr
|
a040ca3e40
|
Adding missing OperatingSystem values to Ieadvpack.yml
|
2022-09-10 23:41:38 -04:00 |
|
xenoscr
|
f5baac1c45
|
Adding missing authors
|
2022-09-10 23:37:10 -04:00 |
|
xenoscr
|
700d181c7e
|
Adding missing OperatingSystem key in Ilasm.yml
|
2022-09-10 23:30:36 -04:00 |
|
xenoscr
|
d585695b08
|
Adding missing Descriptions.
|
2022-09-10 23:26:10 -04:00 |
|
xenoscr
|
abb1034b00
|
Added missing description to Extexport.yml
|
2022-09-10 23:08:46 -04:00 |
|
xenoscr
|
dd58662ee9
|
Correcting 'UAC bypass' to 'UAC Bypass'
|
2022-09-10 22:58:06 -04:00 |
|
xenoscr
|
0ed1694bf1
|
Correcting 'AWL bypass' to 'AWL Bypass'
|
2022-09-10 22:55:32 -04:00 |
|
xenoscr
|
09e81d0bd1
|
Correcting Cmstp.yml Category value, case.
|
2022-09-10 22:48:08 -04:00 |
|
xenoscr
|
5e0ae9c976
|
Correcting Cmstp.yml Category value.
|
2022-09-10 22:46:13 -04:00 |
|
xenoscr
|
ce36f924fc
|
Removing extra --- from each yaml file
|
2022-09-10 22:16:47 -04:00 |
|
Ryan Stamp
|
8810e30f0a
|
Fix incorrect decodehex command syntax (#230)
|
2022-09-02 18:44:23 +01:00 |
|
securepeacock
|
68c14b894c
|
Update UtilityFunctions.yml (#228)
|
2022-09-02 18:42:59 +01:00 |
|
Wietze
|
e1df4e9f83
|
Merge remote-tracking branch 'upstream/master' into windows_11_sprint
|
2022-09-02 17:23:45 +01:00 |
|
Oddvar Moe
|
c5c227a7ba
|
added sigma detection for pester
|
2022-09-02 17:18:24 +01:00 |
|
Oddvar Moe
|
5a38aa722f
|
Adjusted comment in command
|
2022-09-02 17:18:24 +01:00 |
|
Oddvar Moe
|
4b99cadd85
|
Update pester.bat with an additional example
|
2022-09-02 17:18:23 +01:00 |
|
Wietze
|
400158f2df
|
Add sigma references to CL_LoadAssembly, CLMutexVerifiers entries (#221)
|
2022-09-02 17:16:58 +01:00 |
|
Grzegorz Tworek
|
9b70f38986
|
Create Ldifde.yml
|
2022-08-31 17:58:30 +02:00 |
|
Oddvar Moe
|
68a6f0a35f
|
added sigma detection for pester
|
2022-08-24 12:32:48 +02:00 |
|
721574n
|
4b564464fd
|
Added external reference for Rundll32
|
2022-08-24 12:11:31 +02:00 |
|
Oddvar Moe
|
c53a8ea06e
|
Adjusted comment in command
|
2022-08-23 15:47:17 +02:00 |
|
Oddvar Moe
|
fdc1b2c827
|
Update pester.bat with an additional example
|
2022-08-23 15:44:57 +02:00 |
|
fslds
|
3162825fdc
|
Split procdump name pattern into two actual names.
|
2022-08-08 20:27:04 +00:00 |
|
Oddvar Moe
|
8283d8d915
|
Delete Dllhost.yml
https://twitter.com/0gtweet/status/1533804788038647808
|
2022-06-09 10:51:40 +02:00 |
|
frack113
|
91350057ce
|
Add sigma references to CL_LoadAssembly, CLMutexVerifiers entries (#221)
|
2022-06-04 11:50:35 +01:00 |
|
Wietze
|
539c1da0fa
|
Merge branch 'master' into windows_11_sprint
|
2022-05-25 09:25:42 +01:00 |
|
Kostas
|
314f585da9
|
Update Hh.yml
Added SysWoW64 Path
|
2022-05-24 15:29:03 -07:00 |
|
Kostas
|
aae794c59c
|
Update Hh.yml
Fixing the full path of the hh.exe binary to C:\Windows\hh.exe
|
2022-05-24 14:23:18 -07:00 |
|
Wietze
|
7797a1967c
|
Merge branch 'master' into windows_11_sprint
|
2022-05-24 08:38:50 +01:00 |
|
frack113
|
f85eeb748a
|
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219)
|
2022-05-23 12:35:58 +01:00 |
|
Chris "Lopi" Spehn
|
36945392ca
|
Merge pull request #201 from wietze/new/Conhost
Adding Conhost.exe LOLBAS
|
2022-05-19 10:27:10 -06:00 |
|
Chris "Lopi" Spehn
|
e872ce028b
|
Merge pull request #214 from jstnk9/master
Added new sigma rule and references to desk.cpl
|
2022-05-19 10:21:21 -06:00 |
|
ManuelBerrueta
|
68b772a567
|
Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign shared my Microsoft Security Intelligence. Would be useful reference for Red Teamers/Offensive Security Engineers as well as Blue Teamers/Defenders who reference this open source project/library.
|
2022-05-19 07:12:37 -07:00 |
|
John Dwyer
|
90b6082f1d
|
Update Rdrleakdiag.yml
|
2022-05-19 13:30:11 +00:00 |
|
John Dwyer
|
e2493d8ccf
|
Detection Resources and Other Updates (LOLBAS-Project#84)
https://github.com/LOLBAS-Project/LOLBAS/issues/84
|
2022-05-18 19:00:26 +00:00 |
|
John Dwyer
|
d935f096fd
|
Added rdrleakdiag dump
Added yaml for rdrleakdiag process dumping capability
|
2022-05-18 18:58:04 +00:00 |
|
frack113
|
d1738b946b
|
Adding various Sigma references (#213)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-05-17 09:18:45 +01:00 |
|
bohops
|
3571a7ad88
|
Create AccCheckConsole.yml (#187)
|
2022-05-15 21:55:16 +01:00 |
|
mrd0x
|
7c2f3231d3
|
Adding Dump64.exe (#182)
Co-authored-by: mrd0x <mrd0x@example.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-05-15 21:21:45 +01:00 |
|
Wietze
|
b333db4f91
|
Fixing typo (ieaframe -> ieframe)
|
2022-05-15 21:06:33 +01:00 |
|
akshat pradhan
|
79f4cbdb7f
|
Changed tid to T1105 for downloads (#195)
|
2022-05-15 20:38:24 +01:00 |
|
jstnk9
|
00bc9177bd
|
Added new sigma rule and references
Added new sigma rule and references
|
2022-05-15 16:42:44 +02:00 |
|
Wietze
|
2b20998371
|
Remove redundant powershell command from comsvcs entry
|
2022-05-05 11:18:39 +01:00 |
|
Wietze
|
b92ee99627
|
Addressing @bohops's feedback
|
2022-05-05 11:12:22 +01:00 |
|
bohops
|
d93539bf9b
|
Quick fix for syntax and removed IOC
|
2022-04-29 23:06:41 -04:00 |
|
cr1sp4
|
666e6e8645
|
Update Desk.yml (#210)
Added Sigma rules.
|
2022-04-29 22:52:57 -04:00 |
|
Wietze
|
619aafbfa2
|
Adding extra contributor to Desk.cpl entry
|
2022-04-28 13:01:35 +01:00 |
|
Wietze
|
4a8bdf4844
|
Fix casing on Desk.cpl entry
|
2022-04-27 11:20:13 +01:00 |
|
LuxNoBu!!shit
|
6ed0fb9326
|
Create Desk.cpl (#207)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-04-27 11:15:15 +01:00 |
|
Wietze
|
e4261b1f02
|
Fixing typo
|
2022-04-26 16:59:14 +01:00 |
|
Wietze
|
5c46dd63f5
|
Giving Hexacorn the proper credit
|
2022-04-07 15:50:39 +01:00 |
|
Wietze
|
4df2e43c82
|
Adding Conhost.exe LOLBAS
|
2022-04-05 18:46:58 +01:00 |
|
Wietze
|
55a7ea9a81
|
Fixing wlrmdr entry
|
2022-02-16 21:02:24 +00:00 |
|
Moshe Kaplan
|
12c85eb8f0
|
Create wlrmdr.yml (#194)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-02-16 20:41:14 +00:00 |
|
akshat pradhan
|
a7f7ec2cc2
|
Changing ATT&CK TID of wuauclt.exe entry (#193)
|
2022-01-23 22:24:59 +00:00 |
|
Andrew Kisliakov
|
e40a6432a0
|
Merge branch 'LOLBAS-Project:master' into master
|
2022-01-17 08:16:16 +00:00 |
|
Andrew Kisliakov
|
ada7f7f6c3
|
Microsoft Teams as a LOLbin
|
2022-01-17 08:11:47 +00:00 |
|
Wietze
|
085aaa37b1
|
Adding more missed-out entries
|
2021-12-15 11:50:18 +00:00 |
|
Wietze
|
52302853c9
|
Merge branch 'master' into windows_11_sprint
|
2021-12-14 17:39:36 +00:00 |
|
Wietze
|
e51caad3dd
|
Adding Windows 11 reference to missed-out executables
|
2021-12-14 16:57:56 +00:00 |
|
Wietze
|
6793a7d238
|
Fixing various issues identified
|
2021-12-14 16:50:22 +00:00 |
|
Wietze
|
adf171d089
|
Applying minor format changes (incorrectly formatted dates, typos, etc.)
|
2021-12-14 15:53:03 +00:00 |
|
Wietze
|
754a451e76
|
Updating entries that have been confirmed to be working on Windows 11 (21H2)
|
2021-12-14 15:51:43 +00:00 |
|
Wietze
|
39d4e815af
|
Minor formatting changes (redudant backslashes, incorrect dates, typos, etc.)
|
2021-12-14 14:57:32 +00:00 |
|
whickey-r7
|
18bceb7639
|
Create Unregmp2.yml
Added a new lolbin, unregmp2.exe, used for proxying execution.
|
2021-12-06 12:13:24 -05:00 |
|
frack113
|
17899acbb0
|
Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184)
|
2021-12-06 11:19:01 +00:00 |
|
frack113
|
2d28767c04
|
Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183)
|
2021-11-25 09:42:26 +00:00 |
|
Wietze
|
f7b30775a4
|
Odbcconf realign to T1218.008, hh.exe to T1218.001
|
2021-11-16 14:09:37 +00:00 |
|
bohops
|
23dd0236ae
|
Detection Resources and Other Updates (#179)
* Add detection links for scripts
* Add detection links for OtherMSBins. Fixed and updated as needed.
* Add detection links for MSBins. Fixed and updated as needed.
* Add detection links for oslibraries
* Updating template for Detections
* Removing empty Detection:Sigma entries
* Remove redundant blank line
* Replacing commit URL with file URL
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-11-15 08:19:03 -05:00 |
|
Wietze
|
4860585fb7
|
Adding CustomShellHost.exe LOLBAS
|
2021-11-14 23:26:39 +00:00 |
|
akshat pradhan
|
2031916b1a
|
ATT&CK realignment, typo fixes (#178)
* Corrected Mitre TID for pnputil
* Fixed Command misspells
|
2021-11-14 17:27:17 +00:00 |
|
akshat pradhan
|
53a4070205
|
Fixed formating
|
2021-11-09 08:16:34 +05:30 |
|
akshat pradhan
|
33a8da933c
|
Added AWL Bypass to Ssh.yml
|
2021-11-09 08:14:43 +05:30 |
|
akshat pradhan
|
dfc7d40b1f
|
Create Ssh
|
2021-11-08 22:21:37 +05:30 |
|
Wietze
|
2380c506d4
|
LSASS realign to T1003.001
|
2021-11-05 20:35:58 +00:00 |
|
Wietze
|
df8c88f4ca
|
Remaping NTDS entries to T1003.003
|
2021-11-05 20:32:44 +00:00 |
|
Wietze
|
8257d60aad
|
Realigning .ps1 scripts to T1216
|
2021-11-05 20:29:07 +00:00 |
|
Wietze
|
bc51cb4e03
|
More changes (mainly changing some T1218 instances to T1202)
|
2021-11-05 20:19:39 +00:00 |
|
Wietze
|
2577066af9
|
More changes (mainly changing generic T1218 to dev-specific T1127)
|
2021-11-05 20:06:57 +00:00 |
|
Wietze
|
8286677dac
|
Applying more specific subtechniques to Verclsid
|
2021-11-05 19:38:21 +00:00 |
|
Wietze
|
80e3f67e44
|
Applying more specific subtechniques to At/Schtasks, closes LOLBAS-Project/LOLBAS#113
|
2021-11-05 19:33:59 +00:00 |
|
Wietze
|
4f7ec8d2af
|
MITRE ATT&CK realignment sprint
|
2021-11-05 18:58:26 +00:00 |
|
Ensar Şamil
|
97f5042a58
|
Update Certoc.yml (#168)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-10-27 10:02:52 +01:00 |
|
Oddvar Moe
|
5db35bb397
|
Updated msbuild with logger technique
|
2021-10-26 00:27:35 +02:00 |
|
Oddvar Moe
|
7aeed60864
|
Updated msbuild with logger technique
|
2021-10-26 00:19:57 +02:00 |
|
Oddvar Moe
|
b91c7ddab5
|
Updated msbuild with logger technique
|
2021-10-26 00:17:08 +02:00 |
|
Wietze
|
ca11578655
|
Archiving off legacy LOLUtilz
|
2021-10-25 21:32:59 +01:00 |
|
Wietze
|
fa3ff39cac
|
Update Nvudisp.yml
|
2021-10-25 12:33:19 +01:00 |
|
Wietze
|
d411d9572b
|
Create Finger.exe (#154)
Closes #24, #123
|
2021-10-25 12:30:32 +01:00 |
|
Wietze
|
eafc1982f0
|
Website update
|
2021-10-25 12:28:09 +01:00 |
|
Wietze
|
234eb99a7d
|
Formatting
|
2021-10-25 12:27:00 +01:00 |
|
Wietze
|
afe93672a4
|
Minor updates
|
2021-10-25 12:25:13 +01:00 |
|
Oddvar Moe
|
7a34f57a31
|
Update Procdump.yml
|
2021-10-22 16:49:59 +02:00 |
|
Oddvar Moe
|
e70295bc7c
|
Merge pull request #163 from ajpc500/master
added procdump dll load
|
2021-10-22 16:48:46 +02:00 |
|
Oddvar Moe
|
1b15eccf07
|
Merge branch 'master' into master
|
2021-10-22 16:46:18 +02:00 |
|
Oddvar Moe
|
58b5eb7513
|
Update OneDriveStandaloneUpdater.yml
|
2021-10-22 16:43:28 +02:00 |
|
Oddvar Moe
|
a509625acc
|
Update OneDriveStandaloneUpdater.yml
|
2021-10-22 16:41:56 +02:00 |
|
Oddvar Moe
|
70a061d301
|
Merge pull request #153 from elliotkillick/OneDriveStandaloneUpdater
Create OneDriveStandaloneUpdater.yml
|
2021-10-22 16:39:14 +02:00 |
|
Oddvar Moe
|
486b5fc1ef
|
Merge pull request #152 from elliotkillick/SettingSyncHost
Create SettingSyncHost.yml
|
2021-10-22 16:36:13 +02:00 |
|
Oddvar Moe
|
44f88df089
|
Update Cmdl32.yml
|
2021-10-22 16:34:41 +02:00 |
|
Oddvar Moe
|
ccb20e560c
|
Rename cmdl32.yml to Cmdl32.yml
|
2021-10-22 16:33:24 +02:00 |
|
Oddvar Moe
|
5a62424a79
|
Merge pull request #151 from elliotkillick/cmdl32
Create cmdl32.yml
|
2021-10-22 16:32:42 +02:00 |
|
Oddvar Moe
|
fb9b6d65d5
|
Update cmdl32.yml
|
2021-10-22 16:31:54 +02:00 |
|
Oddvar Moe
|
adcb7e0c57
|
Merge pull request #150 from elliotkillick/OfflineScannerShell
Create OfflineScannerShell.yml
|
2021-10-22 16:28:33 +02:00 |
|
Oddvar Moe
|
c04d90c533
|
Merge pull request #149 from elliotkillick/WorkFolders
Create WorkFolders.yml
|
2021-10-22 16:26:50 +02:00 |
|