Commit Graph

388 Commits

Author SHA1 Message Date
Onat Uzunyayla
7aba6fb550
Create vstest.console.exe (#322)
* vstest.console.exe awl bypass

* Create testwindowremoteagent.yaml

Data Exfiltration with TestWindowRemoteAgent.exe is added

* Create vstest.yaml

In order to utilize this, you have to create a Unit Test project for c++ preferrably (because it builds into a single DLL easily) and write your malicious code inside the test method then build it. the main function will not run any code at all but when you call vstest.console to run your unit tests it also performs the other code inside the test method so you can run your code without directly running exe or dll

* Delete testwindowremoteagent.yaml

* Update vstest.yaml

A new description added
2023-10-18 11:28:04 -04:00
SILJAEUROPA
fa3b5ed33c
added addinutil lolbas binary (#335)
* added addinutil lolbas binary

* updated format for lint

* EOF LF
2023-10-09 09:05:57 +02:00
Manas Bellani
d6e4fb07d5
Added lolbas iediagcmd.exe as discovered by Adam @hexacorn (#199)
Everything looks good, confirmed working on Windows 10 & 11, merging changes:

* Added 'Execute' lolbas for iediagcmd.exe

* Added missing fields from the template

* Update Iediagcmd.yml

Made corrections

* Update Iediagcmd.yml

Removing trailing spaces

* Update Iediagcmd.yml

removing empty fields

* Minor changes

* Update Iediagcmd.yml

Removing space before first "&". When setting the Environment variable, it's picking up the space so the path seemed to be "c:\test \", which is why tests are failing.

* Adding Windows 11 support

---------

Co-authored-by: Conor Richard <xenos@xenos-1.net>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-10-04 09:47:18 -04:00
securepeacock
fd9fae8321
Added Sigma to Teams.exe (#329) 2023-10-03 12:04:39 +01:00
Jose Enrique Hernandez
a493c20989
Merge pull request #320 from mertdas/master
Create msedge_proxy.yml
2023-09-05 13:26:30 -04:00
Mert Daş
e75e99f1cf
Update msedge_proxy.yml 2023-09-05 18:47:05 +03:00
Mert Daş
e585183dcd
Update msedge_proxy.yml 2023-09-05 18:45:00 +03:00
Mert Daş
69976b4880
Update msedge_proxy.yml 2023-09-05 18:41:36 +03:00
Mert Daş
fee20a0813
Update msedge_proxy.yml 2023-09-05 18:39:16 +03:00
Mert Daş
7da6f3216d
Update msedge_proxy.yml 2023-09-05 18:37:14 +03:00
Mert Daş
e2c58fcf31
Update msedge_proxy.yml 2023-09-03 22:28:00 +03:00
Mert Daş
d5f153b84b
Update msedge_proxy.yml 2023-09-03 22:23:40 +03:00
Mert Daş
f8743a4109
Update msedge_proxy.yml 2023-09-03 22:17:14 +03:00
Mert Daş
994aa792f0
Update msedge_proxy.yml 2023-09-03 22:11:01 +03:00
Mert Daş
247511bca8
Update msedge_proxy.yml 2023-09-03 21:51:32 +03:00
Mert Daş
a0874f2bb7
Update msedge_proxy.yml 2023-09-03 21:48:05 +03:00
Mert Daş
53f8fbe19b
Update msedge_proxy.yml 2023-09-03 21:44:41 +03:00
frack113
50c481795b Add SigmaHQ ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-09-03 15:06:34 +02:00
Mert Daş
9d79fab230
Update msedge_proxy.yml 2023-08-25 21:24:58 +03:00
Mert Daş
0f3b483ae1
Update msedge_proxy.yml 2023-08-25 21:23:41 +03:00
Mert Daş
f4acc01906
Update msedge_proxy.yml 2023-08-18 17:47:17 +03:00
Mert Daş
68629128a3
Update msedge_proxy.yml 2023-08-18 17:44:23 +03:00
Mert Daş
b14ad21ff9
Create msedge_proxy.yml 2023-08-18 17:17:49 +03:00
Elliot Killick
65007296a6
Update Cmdl32.exe resource links (#317) 2023-08-04 11:21:36 +01:00
Wietze
b50df49ac2
Added colorcpl.exe (#315)
Co-authored-by: Arjan Onwezen <arjan.onwezen@gmail.com>
2023-07-27 18:18:49 +01:00
Grzegorz Tworek
7241a8b7fd
Create Provlaunch.yml (#307)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-07-25 16:16:39 +01:00
Ryan Plas
62ed936a39
Add missing document starts and add yamllint rule (#305) 2023-06-23 20:55:39 +01:00
frack113
e8ea28d4e9
Update SigmaHQ ref (#301)
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-06-19 22:40:24 +01:00
CyberSorcery
c3f2690633
Tar.exe lateral movement (#277)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-06-17 22:25:34 +01:00
Black Shade
d71415de77
Create msedgewebview2.exe (#299)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-06-17 21:56:16 +01:00
frack113
b52200eb89
Add sigma and remove ampty string (#297)
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-06-17 20:30:00 +01:00
Jose Enrique Hernandez
f5a3812c91
Merge pull request #295 from frack113/sigma_20230610
Add missing Sigma ref
2023-06-11 22:10:04 -04:00
frack113
55b7556b64 Add Sigma ref
Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com>
2023-06-10 08:12:12 +02:00
mr.d0x
ef8048344d Update msedge.exe & add teams.exe 2023-05-27 12:11:05 -04:00
biscoito
1f7e8a3e57
Remove unnecessary "at" on command (#286) 2023-05-01 23:36:38 +01:00
mrd0x
787c87470e
Several LOLBINs additions & modifications (#192)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-03-31 13:46:21 +01:00
Wietze
a9046ecb85
Fixing newline in odbcconf entry 2023-03-25 16:21:34 +00:00
Wietze
06f33c91ae
Updating odbcconf, fixes #282 - thanks @hexacorn (#283) 2023-03-25 16:14:04 +00:00
Mr. 0range
2b7fdcac03
Adding WebDav techniques to cmd.exe entry (#273)
Added the documentation for the type command file transfer, ADS, and copy functionality
---------

Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-03-08 14:39:32 +00:00
Wietze
74d010a893
Removing pre-Windows 10 OSs from CertReq entry, fixes #247 2023-02-25 19:19:22 +00:00
bohops
cd16f0aff3
Add vsls-agent lolbin and committing a few other changes (#263)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-02-25 18:47:44 +00:00
febou92
ded90467a8
Create Ssh.yml (#211)
* Create Ssh.yml

* newline ymlint

Co-authored-by: bohops <bohops>
2022-12-29 19:45:09 -05:00
frack113
1072d3dc34
Add sigma ref Detection (#272)
* Add sigma ref

* Add missing sigma ref

* Fix sigma link

* Remove by Defender

* Remove by Defender
2022-12-29 09:51:15 -05:00
Grzegorz Tworek
ec676cbd93
Create Runexehelper.yml (#269)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-12-17 17:30:30 +00:00
Michał Kucharski
8452c1ca96
Update eventvwr.yml with Execute part (#252)
* Update eventvwr.yml with Execute part

All things added based on https://twitter.com/orange_8361/status/1518970259868626944 and my re-tests.

* Update Eventvwr.yml

As asked by @bohops

* Update Eventvwr.yml
2022-11-13 14:56:32 -05:00
Nasreddine Bencherchali
0d7efb8ead
Adding and updating various LOLBINS (#229)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-11-11 16:42:44 +00:00
Grzegorz Tworek
1587eeaf6c
Create Setres.yml (#262)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-26 11:15:13 +01:00
Wietze
c20f388444
Fixing minor error in description of Explorer, closes #257 2022-10-26 09:14:27 +01:00
frack113
01d7580886
Add Sigma rule references to various LOLBAS (#260) 2022-10-26 09:10:39 +01:00
Wietze
a0556744d1
Merge branch 'master' into windows_11_sprint 2022-10-04 15:45:57 +01:00
Wietze
6f2135e173
Updating category of fltMC to tamper 2022-10-04 15:37:56 +01:00
Wietze
76acca6f2b
Merge branch 'master' into windows_11_sprint 2022-10-04 12:31:31 +01:00
C-h4ck-0
f29471dde9
Adding download functionality entries to existing binaries (#239)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 12:27:31 +01:00
saulpanders
83ca9aa197
Adding Windows Package Manager tool winget.exe (#188)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 11:27:47 +01:00
Wietze
67e1040172
Merge remote-tracking branch 'upstream/master' into windows_11_sprint 2022-10-03 16:18:57 +01:00
Conor Richard
da38f3d8ed
Merge pull request #185 from whickey-r7/patch-1
Create Unregmp2.yml
2022-09-17 21:38:59 -04:00
Conor Richard
a9e5707f74
Removing extra YAML record start "---" 2022-09-17 21:37:30 -04:00
Conor Richard
59808608e7
Merge pull request #180 from wietze/new/CustomShellHost
Adding CustomShellHost.exe LOLBAS
2022-09-17 21:34:04 -04:00
Conor Richard
05faad73b2
Removing extra YAML record start "---" 2022-09-17 21:32:13 -04:00
Conor Richard
c22d17a116
Merge pull request #176 from akat12/Ssh
Create Ssh
2022-09-17 21:25:49 -04:00
Conor Richard
14896a1436
Removed trailing space on line 3 2022-09-17 21:24:04 -04:00
Conor Richard
730359aa0d
Changed AWL MitreID and removed extra YAML record start "---" 2022-09-17 21:21:13 -04:00
Conor Richard
aa698337ff
Merge pull request #148 from elliotkillick/fsutil
Create fsutil.yml
2022-09-17 08:10:53 -04:00
Conor Richard
181672267b
Adding quotes since the ":" falls at the end to fix linting error 2022-09-17 08:09:27 -04:00
Conor Richard
4615fbc582
fixing indentation in line 14 2022-09-17 08:04:58 -04:00
Conor Richard
2759dd0565
Adding USN deletion that @bohops mentioned in #148 notes 2022-09-17 08:01:53 -04:00
Conor Richard
e878c66e6f
Cleaning YAML, updated new category Tamper 2022-09-17 07:55:16 -04:00
Conor Richard
f5c797a888
Merge pull request #147 from elliotkillick/DeviceCredentialDeployment
Create DeviceCredentialDeployment.yml
2022-09-17 07:52:29 -04:00
Conor Richard
7dd6ca24aa
Removing invalid MiterLink key. 2022-09-17 07:50:44 -04:00
Conor Richard
1e6d6d23cc
Removing extra document start "---" and updating category to Conceal. 2022-09-17 07:47:06 -04:00
Conor Richard
61043ccf0b
Merge pull request #245 from gtworek/patch-1
Create Ldifde.yml
2022-09-17 00:09:22 -04:00
Conor Richard
2689786b59
Update Ldifde.yml
Removed trailing spaces.
2022-09-17 00:06:25 -04:00
Conor Richard
9875eb2ed2
Update Ldifde.yml
Removed final "---". It does not match the current template and schema checks.
2022-09-17 00:03:20 -04:00
Conor Richard
2c9a7a97ce
Merge pull request #244 from 721574n/tristan_add
Added external reference about Rundll32
2022-09-16 23:46:43 -04:00
xenoscr
dfb30f194f
Tweaked the Link regex to allow anchor tags and the handle regex to permit blank entries. 2022-09-13 23:37:10 -04:00
xenoscr
ee68df7f26
Put schema back to previous state and fixed non-compliant Link in At.yml 2022-09-13 23:06:42 -04:00
xenoscr
92424a40de
Implimenting requested changes from PR #251 review from @wietze. 2022-09-13 22:51:52 -04:00
xenoscr
654cdd2d61
Fixing file formating. 2022-09-11 01:33:36 -04:00
xenoscr
3d6a4be2a5
Fixing more formatting errors. 2022-09-11 01:23:21 -04:00
xenoscr
98813fe01b
Fixing errors found in yaml lint action. 2022-09-11 01:07:18 -04:00
xenoscr
700d181c7e
Adding missing OperatingSystem key in Ilasm.yml 2022-09-10 23:30:36 -04:00
xenoscr
d585695b08
Adding missing Descriptions. 2022-09-10 23:26:10 -04:00
xenoscr
abb1034b00
Added missing description to Extexport.yml 2022-09-10 23:08:46 -04:00
xenoscr
dd58662ee9
Correcting 'UAC bypass' to 'UAC Bypass' 2022-09-10 22:58:06 -04:00
xenoscr
0ed1694bf1
Correcting 'AWL bypass' to 'AWL Bypass' 2022-09-10 22:55:32 -04:00
xenoscr
09e81d0bd1
Correcting Cmstp.yml Category value, case. 2022-09-10 22:48:08 -04:00
xenoscr
5e0ae9c976
Correcting Cmstp.yml Category value. 2022-09-10 22:46:13 -04:00
xenoscr
ce36f924fc
Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Ryan Stamp
8810e30f0a
Fix incorrect decodehex command syntax (#230) 2022-09-02 18:44:23 +01:00
Wietze
e1df4e9f83
Merge remote-tracking branch 'upstream/master' into windows_11_sprint 2022-09-02 17:23:45 +01:00
Grzegorz Tworek
9b70f38986
Create Ldifde.yml 2022-08-31 17:58:30 +02:00
721574n
4b564464fd Added external reference for Rundll32 2022-08-24 12:11:31 +02:00
Oddvar Moe
8283d8d915
Delete Dllhost.yml
https://twitter.com/0gtweet/status/1533804788038647808
2022-06-09 10:51:40 +02:00
Wietze
539c1da0fa
Merge branch 'master' into windows_11_sprint 2022-05-25 09:25:42 +01:00
Kostas
314f585da9
Update Hh.yml
Added SysWoW64 Path
2022-05-24 15:29:03 -07:00
Kostas
aae794c59c
Update Hh.yml
Fixing the full path of the hh.exe binary to C:\Windows\hh.exe
2022-05-24 14:23:18 -07:00
Wietze
7797a1967c
Merge branch 'master' into windows_11_sprint 2022-05-24 08:38:50 +01:00
frack113
f85eeb748a
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219) 2022-05-23 12:35:58 +01:00
Chris "Lopi" Spehn
36945392ca
Merge pull request #201 from wietze/new/Conhost
Adding Conhost.exe LOLBAS
2022-05-19 10:27:10 -06:00
John Dwyer
90b6082f1d Update Rdrleakdiag.yml 2022-05-19 13:30:11 +00:00