Commit Graph

166 Commits

Author SHA1 Message Date
Oddvar Moe
d9e31e2291 Rename fltMC.yml to FltMC.yml 2021-10-22 16:04:27 +02:00
Oddvar Moe
6bda2344eb Rename certoc.yml to Certoc.yml 2021-10-22 16:04:12 +02:00
Oddvar Moe
e32f944030 Merge pull request #162 from esebese/master
Create certoc.yml
2021-10-22 16:02:20 +02:00
Oddvar Moe
985bda094e Merge pull request #164 from eral4m/master
Create Stordiag.yml
2021-10-22 15:58:35 +02:00
Oddvar Moe
30a9f90f5f Update Stordiag.yml 2021-10-22 15:56:52 +02:00
Oddvar Moe
a55e2249c1 Merge branch 'master' into fixing-yaml-issues 2021-10-22 14:53:09 +02:00
eral4m
8b49ca2054 Update Stordiag.yml 2021-10-21 10:30:54 +01:00
eral4m
b723258dbf Update Stordiag.yml 2021-10-21 10:30:31 +01:00
eral4m
6da5480936 Update Stordiag.yml 2021-10-21 10:14:04 +01:00
eral4m
fd2a31b43b Create Stordiag.yml 2021-10-21 10:00:47 +01:00
Ensar Şamil
6b6fd3fd62 Create certoc.yml 2021-10-07 13:31:45 +03:00
root
b5357cdec0 Adding app-ctrl bypass bins and a few lolscripts 2021-09-26 23:31:30 -04:00
bohops
3475ce1213 Merge pull request #158 from JohnLaTwC/patch-1
Add lolbin for fltMC.exe
2021-09-25 22:47:30 -04:00
bohops
6c20e750e8 Merge pull request #144 from defensivedepth/patch-1
Fix ART link
2021-09-25 22:22:42 -04:00
bohops
198b421d15 Merge pull request #130 from whickey-r7/patch-3
Create IMEWDBLD.yml
2021-09-25 22:07:23 -04:00
John Lambert
ecbc2f817f Add lolbin for fltMC.exe
Used by redteams for defense evasion to disable drivers used by agents like sysmon

https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py
2021-09-18 17:43:59 -07:00
bohops
f51a70c03e Merge pull request #143 from Efraim-Kaplan/patch-1
Fixed Typo
2021-08-26 09:08:40 -04:00
Josh Brower
87c3319ad4 Fix ART link 2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d FIxed typo
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Parker McGee
bbf14cf4b9 Fix a typo in Findstr.yml
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
whickey-r7
782bc68c7c Create IMEWDBLD.yml 2021-03-05 11:35:06 -05:00
Oddvar Moe
7c1a4a7959 Merge pull request #125 from wokis/master
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
b79a48f082 Fixed Category on pnputil 2021-01-21 22:54:58 +01:00
Oddvar Moe
2406d99f33 Rename pnputil.yml to Pnputil.yml
Casing
2021-01-21 22:49:19 +01:00
Oddvar Moe
64914b641c Adjusted error on pnputil yml file 2021-01-21 22:48:05 +01:00
Oddvar Moe
5b9c4f63dc Merge pull request #118 from LuxNoBulIshit/master
Pnputil.exe
2021-01-21 22:42:40 +01:00
Oddvar Moe
394d3c66f9 Merge pull request #112 from zeroSteiner/patch-1
Update the affected operating systems for SyncAppvPublishingServer
2021-01-21 22:35:50 +01:00
Oddvar Moe
97176a0a07 Merge pull request #110 from whickey-r7/patch-2
Create AppInstaller.yml
2021-01-21 22:29:35 +01:00
Oddvar Moe
6774d228a5 Merge pull request #109 from unexpectedBy/patch-2
Create DataSvcUtil.yml
2021-01-21 22:24:02 +01:00
wokis
00935f154e Update Wsreset.yml
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-20 14:47:23 +01:00
Wietze
5012f95152 Fix Code_Sample field 2021-01-10 15:49:30 +00:00
Wietze
14dca38278 Standardise date formats (see https://yaml.org/type/timestamp.html) 2021-01-10 15:04:52 +00:00
LuxNoBu!!shit
0d819439c5 Create pnputil.exe 2020-12-25 12:14:15 -08:00
Spencer McIntyre
deb249042b Update the affected operating systems for SyncAppvPublishingServer 2020-12-08 15:32:35 -05:00
whickey-r7
b381d04faf Create AppInstaller.yml
New lolbin for downloading files in Windows 10.
2020-12-02 11:35:49 -05:00
unload
bfe248b07e Create DataSvcUtil.yml
Another data exfil way with lolbins
2020-12-01 22:57:09 -03:00
Nasreddine Bencherchali
15d5ff302d Create Dllhost.yml 2020-11-07 14:22:24 +01:00
Conor Richard
d15172284a Merge pull request #101 from leo1-1/master
added command to certutil
2020-10-26 19:44:53 -04:00
Conor Richard
5806d33e70 Update Certutil.yml 2020-10-26 19:43:55 -04:00
leo1-1
64d5dffc4b Delete certutil.yml 2020-10-26 08:59:00 +02:00
leo1-1
76d79ea479 Update Certutil 2020-10-26 08:57:42 +02:00
leo1-1
2166960d4e changed path 2020-10-26 08:22:58 +02:00
Conor Richard
9a83179ddd Merge pull request #99 from dtmsecurity/master
Create Wuauclt.yml
2020-10-24 22:29:34 -04:00
Conor Richard
04c0e7ee38 Update Explorer.yml
Fixing alignment in Acknowledgement section
2020-10-22 22:00:05 -04:00
Conor Richard
4f19dbba19 Merge pull request #93 from C3dr1cMFE/add_MpCmdRun_Bypass
Update MpCmdRun.yml
2020-10-22 21:05:37 -04:00
Conor Richard
d281faccd3 Merge pull request #92 from whickey-r7/patch-1
Update Xwizard.yml
2020-10-22 20:57:55 -04:00
Conor Richard
9a6309d8de Update ConfigSecurityPolicy.yml
Added link to Tweet from author containing an example usage.
2020-10-22 20:38:50 -04:00
@dtmsecurity
651e156583 Create Wuauclt.yml 2020-10-12 19:24:45 +01:00
Cochin, Cedric
13026a481b Update MpCmdRun.yml
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker
2020-09-24 14:09:58 -07:00
whickey-r7
11aa1e503b Update Xwizard.yml
This lolbin has functionality which allows downloading of files from the internet as well as previously outlined execution functionality.
2020-09-16 16:34:47 +00:00