Mr. 0range
2b7fdcac03
Adding WebDav techniques to cmd.exe entry ( #273 )
...
Added the documentation for the type command file transfer, ADS, and copy functionality
---------
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-03-08 14:39:32 +00:00
YamAlon
8283b4b7e3
Added fsi to dotnet.exe ( #281 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-02-25 20:10:45 +00:00
Wietze
74d010a893
Removing pre-Windows 10 OSs from CertReq entry, fixes #247
2023-02-25 19:19:22 +00:00
bohops
cd16f0aff3
Add vsls-agent lolbin and committing a few other changes ( #263 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2023-02-25 18:47:44 +00:00
febou92
ded90467a8
Create Ssh.yml ( #211 )
...
* Create Ssh.yml
* newline ymlint
Co-authored-by: bohops <bohops>
2022-12-29 19:45:09 -05:00
frack113
1072d3dc34
Add sigma ref Detection ( #272 )
...
* Add sigma ref
* Add missing sigma ref
* Fix sigma link
* Remove by Defender
* Remove by Defender
2022-12-29 09:51:15 -05:00
securepeacock
8ff159abb7
Update Wfc.yml with Sigma ( #223 )
...
* Update Wfc.yml
* Update acknowledgement
* Update Wfc.yml
* fix line feed issue after conflict
Co-authored-by: bohops <bohops>
2022-12-29 00:22:39 -05:00
securepeacock
41f5d6f33b
Update VisualUiaVerifyNative.yml with Sigma ( #224 )
...
* Update VisualUiaVerifyNative.yml
* Update acknowledgement
* Update VisualUiaVerifyNative.yml
* fix line feed issue after conflict
* fix line feed issue after conflict
* fix line feed issue after conflict
* fix line feed issue after conflict
Co-authored-by: bohops <bohops>
2022-12-29 00:15:31 -05:00
securepeacock
1833ddd391
Update FsiAnyCpu.yml with Sigma ( #225 )
...
* Update FsiAnyCpu.yml
* Update acknowledgement
* Update FsiAnyCpu.yml
* fix line feed issue after conflict
Co-authored-by: bohops <jimmy@jbtech.us>
2022-12-28 23:50:51 -05:00
securepeacock
8d35738a1f
Update Fsi.yml with Sigma ( #226 )
...
* Update Fsi.yml
* Update acknowledgement
* Remove newline
* resolving unix lf issue with fsi
* resolving unix lf issue with fsi
* resolving fsi issue
Co-authored-by: bohops <jimmy@jbtech.us>
2022-12-28 23:41:27 -05:00
securepeacock
c19a2e3cf8
Update Remote.yml with Sigma ( #227 )
...
* Update Remote.yml
* Update acknowledgement
Co-authored-by: bohops <jimmy@jbtech.us>
2022-12-28 21:24:57 -05:00
Grzegorz Tworek
ec676cbd93
Create Runexehelper.yml ( #269 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-12-17 17:30:30 +00:00
Michał Kucharski
8452c1ca96
Update eventvwr.yml with Execute part ( #252 )
...
* Update eventvwr.yml with Execute part
All things added based on https://twitter.com/orange_8361/status/1518970259868626944 and my re-tests.
* Update Eventvwr.yml
As asked by @bohops
* Update Eventvwr.yml
2022-11-13 14:56:32 -05:00
Nasreddine Bencherchali
0d7efb8ead
Adding and updating various LOLBINS ( #229 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-11-11 16:42:44 +00:00
Grzegorz Tworek
1587eeaf6c
Create Setres.yml ( #262 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-26 11:15:13 +01:00
Wietze
c20f388444
Fixing minor error in description of Explorer, closes #257
2022-10-26 09:14:27 +01:00
frack113
01d7580886
Add Sigma rule references to various LOLBAS ( #260 )
2022-10-26 09:10:39 +01:00
Wietze
a0556744d1
Merge branch 'master' into windows_11_sprint
2022-10-04 15:45:57 +01:00
Wietze
6f2135e173
Updating category of fltMC to tamper
2022-10-04 15:37:56 +01:00
Daniel Santos
4217d0f8ca
Adding .NET Core binary createdump.exe ( #240 )
...
Co-authored-by: Daniel Santos <vovohelo@gmail.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 13:23:10 +01:00
securepeacock
461fbaf787
Update Powerpnt.yml with Sigma ( #222 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 12:36:49 +01:00
Wietze
76acca6f2b
Merge branch 'master' into windows_11_sprint
2022-10-04 12:31:31 +01:00
C-h4ck-0
f29471dde9
Adding download functionality entries to existing binaries ( #239 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 12:27:31 +01:00
C-h4ck-0
ea68ad824d
Adding 3 Microsoft Office-based downloaders ( #238 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 12:13:56 +01:00
saulpanders
83ca9aa197
Adding Windows Package Manager tool winget.exe ( #188 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-10-04 11:27:47 +01:00
Wietze
67e1040172
Merge remote-tracking branch 'upstream/master' into windows_11_sprint
2022-10-03 16:18:57 +01:00
Conor Richard
da38f3d8ed
Merge pull request #185 from whickey-r7/patch-1
...
Create Unregmp2.yml
2022-09-17 21:38:59 -04:00
Conor Richard
a9e5707f74
Removing extra YAML record start "---"
2022-09-17 21:37:30 -04:00
Conor Richard
59808608e7
Merge pull request #180 from wietze/new/CustomShellHost
...
Adding CustomShellHost.exe LOLBAS
2022-09-17 21:34:04 -04:00
Conor Richard
05faad73b2
Removing extra YAML record start "---"
2022-09-17 21:32:13 -04:00
Conor Richard
c22d17a116
Merge pull request #176 from akat12/Ssh
...
Create Ssh
2022-09-17 21:25:49 -04:00
Conor Richard
14896a1436
Removed trailing space on line 3
2022-09-17 21:24:04 -04:00
Conor Richard
730359aa0d
Changed AWL MitreID and removed extra YAML record start "---"
2022-09-17 21:21:13 -04:00
Conor Richard
aa698337ff
Merge pull request #148 from elliotkillick/fsutil
...
Create fsutil.yml
2022-09-17 08:10:53 -04:00
Conor Richard
181672267b
Adding quotes since the ":" falls at the end to fix linting error
2022-09-17 08:09:27 -04:00
Conor Richard
4615fbc582
fixing indentation in line 14
2022-09-17 08:04:58 -04:00
Conor Richard
2759dd0565
Adding USN deletion that @bohops mentioned in #148 notes
2022-09-17 08:01:53 -04:00
Conor Richard
e878c66e6f
Cleaning YAML, updated new category Tamper
2022-09-17 07:55:16 -04:00
Conor Richard
f5c797a888
Merge pull request #147 from elliotkillick/DeviceCredentialDeployment
...
Create DeviceCredentialDeployment.yml
2022-09-17 07:52:29 -04:00
Conor Richard
7dd6ca24aa
Removing invalid MiterLink key.
2022-09-17 07:50:44 -04:00
Conor Richard
1e6d6d23cc
Removing extra document start "---" and updating category to Conceal.
2022-09-17 07:47:06 -04:00
Conor Richard
61043ccf0b
Merge pull request #245 from gtworek/patch-1
...
Create Ldifde.yml
2022-09-17 00:09:22 -04:00
Conor Richard
2689786b59
Update Ldifde.yml
...
Removed trailing spaces.
2022-09-17 00:06:25 -04:00
Conor Richard
9875eb2ed2
Update Ldifde.yml
...
Removed final "---". It does not match the current template and schema checks.
2022-09-17 00:03:20 -04:00
Conor Richard
2c9a7a97ce
Merge pull request #244 from 721574n/tristan_add
...
Added external reference about Rundll32
2022-09-16 23:46:43 -04:00
Filipe Spencer
d780de4ece
Prep for new yamllint
2022-09-16 11:29:26 +00:00
Conor Richard
3347e43b3f
Merge branch 'master' into alias_introduction
2022-09-15 13:54:50 -04:00
xenoscr
dfb30f194f
Tweaked the Link regex to allow anchor tags and the handle regex to permit blank entries.
2022-09-13 23:37:10 -04:00
xenoscr
ee68df7f26
Put schema back to previous state and fixed non-compliant Link in At.yml
2022-09-13 23:06:42 -04:00
xenoscr
92424a40de
Implimenting requested changes from PR #251 review from @wietze.
2022-09-13 22:51:52 -04:00
xenoscr
2c3653f0c4
Fixing more file formatting issues.
2022-09-11 01:36:14 -04:00
xenoscr
654cdd2d61
Fixing file formating.
2022-09-11 01:33:36 -04:00
xenoscr
3d6a4be2a5
Fixing more formatting errors.
2022-09-11 01:23:21 -04:00
xenoscr
98813fe01b
Fixing errors found in yaml lint action.
2022-09-11 01:07:18 -04:00
xenoscr
6e253a7a38
Adding missing OperatingSystem values.
2022-09-11 00:22:36 -04:00
xenoscr
68e5795aec
Fixing Acknowledgement values.
2022-09-11 00:20:05 -04:00
xenoscr
aa1e1ea2be
Adding no defualt paths to pass schema validations
2022-09-11 00:16:59 -04:00
xenoscr
c933426c1a
Adding missing Path value.
2022-09-11 00:03:30 -04:00
xenoscr
1bd305e3a3
Adding missing Usecase values.
2022-09-10 23:53:21 -04:00
xenoscr
c24cad7868
Adding missing OperatingSystem values.
2022-09-10 23:48:38 -04:00
xenoscr
371d1cf2cc
Correcting case in Usecase key names.
2022-09-10 23:45:28 -04:00
xenoscr
a040ca3e40
Adding missing OperatingSystem values to Ieadvpack.yml
2022-09-10 23:41:38 -04:00
xenoscr
f5baac1c45
Adding missing authors
2022-09-10 23:37:10 -04:00
xenoscr
700d181c7e
Adding missing OperatingSystem key in Ilasm.yml
2022-09-10 23:30:36 -04:00
xenoscr
d585695b08
Adding missing Descriptions.
2022-09-10 23:26:10 -04:00
xenoscr
abb1034b00
Added missing description to Extexport.yml
2022-09-10 23:08:46 -04:00
xenoscr
dd58662ee9
Correcting 'UAC bypass' to 'UAC Bypass'
2022-09-10 22:58:06 -04:00
xenoscr
0ed1694bf1
Correcting 'AWL bypass' to 'AWL Bypass'
2022-09-10 22:55:32 -04:00
xenoscr
09e81d0bd1
Correcting Cmstp.yml Category value, case.
2022-09-10 22:48:08 -04:00
xenoscr
5e0ae9c976
Correcting Cmstp.yml Category value.
2022-09-10 22:46:13 -04:00
xenoscr
ce36f924fc
Removing extra --- from each yaml file
2022-09-10 22:16:47 -04:00
Ryan Stamp
8810e30f0a
Fix incorrect decodehex command syntax ( #230 )
2022-09-02 18:44:23 +01:00
securepeacock
68c14b894c
Update UtilityFunctions.yml ( #228 )
2022-09-02 18:42:59 +01:00
Wietze
e1df4e9f83
Merge remote-tracking branch 'upstream/master' into windows_11_sprint
2022-09-02 17:23:45 +01:00
Oddvar Moe
c5c227a7ba
added sigma detection for pester
2022-09-02 17:18:24 +01:00
Oddvar Moe
5a38aa722f
Adjusted comment in command
2022-09-02 17:18:24 +01:00
Oddvar Moe
4b99cadd85
Update pester.bat with an additional example
2022-09-02 17:18:23 +01:00
Wietze
400158f2df
Add sigma references to CL_LoadAssembly, CLMutexVerifiers entries ( #221 )
2022-09-02 17:16:58 +01:00
Grzegorz Tworek
9b70f38986
Create Ldifde.yml
2022-08-31 17:58:30 +02:00
Oddvar Moe
68a6f0a35f
added sigma detection for pester
2022-08-24 12:32:48 +02:00
721574n
4b564464fd
Added external reference for Rundll32
2022-08-24 12:11:31 +02:00
Oddvar Moe
c53a8ea06e
Adjusted comment in command
2022-08-23 15:47:17 +02:00
Oddvar Moe
fdc1b2c827
Update pester.bat with an additional example
2022-08-23 15:44:57 +02:00
fslds
3162825fdc
Split procdump name pattern into two actual names.
2022-08-08 20:27:04 +00:00
Oddvar Moe
8283d8d915
Delete Dllhost.yml
...
https://twitter.com/0gtweet/status/1533804788038647808
2022-06-09 10:51:40 +02:00
frack113
91350057ce
Add sigma references to CL_LoadAssembly, CLMutexVerifiers entries ( #221 )
2022-06-04 11:50:35 +01:00
Wietze
539c1da0fa
Merge branch 'master' into windows_11_sprint
2022-05-25 09:25:42 +01:00
Kostas
314f585da9
Update Hh.yml
...
Added SysWoW64 Path
2022-05-24 15:29:03 -07:00
Kostas
aae794c59c
Update Hh.yml
...
Fixing the full path of the hh.exe binary to C:\Windows\hh.exe
2022-05-24 14:23:18 -07:00
Wietze
7797a1967c
Merge branch 'master' into windows_11_sprint
2022-05-24 08:38:50 +01:00
frack113
f85eeb748a
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace ( #219 )
2022-05-23 12:35:58 +01:00
Chris "Lopi" Spehn
36945392ca
Merge pull request #201 from wietze/new/Conhost
...
Adding Conhost.exe LOLBAS
2022-05-19 10:27:10 -06:00
Chris "Lopi" Spehn
e872ce028b
Merge pull request #214 from jstnk9/master
...
Added new sigma rule and references to desk.cpl
2022-05-19 10:21:21 -06:00
ManuelBerrueta
68b772a567
Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign shared my Microsoft Security Intelligence. Would be useful reference for Red Teamers/Offensive Security Engineers as well as Blue Teamers/Defenders who reference this open source project/library.
2022-05-19 07:12:37 -07:00
John Dwyer
90b6082f1d
Update Rdrleakdiag.yml
2022-05-19 13:30:11 +00:00
John Dwyer
e2493d8ccf
Detection Resources and Other Updates (LOLBAS-Project#84)
...
https://github.com/LOLBAS-Project/LOLBAS/issues/84
2022-05-18 19:00:26 +00:00
John Dwyer
d935f096fd
Added rdrleakdiag dump
...
Added yaml for rdrleakdiag process dumping capability
2022-05-18 18:58:04 +00:00
frack113
d1738b946b
Adding various Sigma references ( #213 )
...
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-05-17 09:18:45 +01:00
bohops
3571a7ad88
Create AccCheckConsole.yml ( #187 )
2022-05-15 21:55:16 +01:00
mrd0x
7c2f3231d3
Adding Dump64.exe ( #182 )
...
Co-authored-by: mrd0x <mrd0x@example.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
2022-05-15 21:21:45 +01:00