Chris "Lopi" Spehn
							
						 
					 | 
					
						
						
							
						
						e872ce028b
					 | 
					
						
						
							
							Merge pull request #214 from jstnk9/master
						
						
						
						
						
						
						
						Added new sigma rule and references to desk.cpl 
						
						
					 | 
					
						2022-05-19 10:21:21 -06:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Chris "Lopi" Spehn
							
						 
					 | 
					
						
						
							
						
						82f19b22e7
					 | 
					
						
						
							
							Merge pull request #217 from ManuelBerrueta/master
						
						
						
						
						
						
						
						Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign sh… 
						
						
					 | 
					
						2022-05-19 10:19:22 -06:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								ManuelBerrueta
							
						 
					 | 
					
						
						
							
						
						68b772a567
					 | 
					
						
						
							
							Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign shared my Microsoft Security Intelligence. Would be useful reference for Red Teamers/Offensive Security Engineers as well as Blue Teamers/Defenders who reference this open source project/library.
						
						
						
						
						
						
					 | 
					
						2022-05-19 07:12:37 -07:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Chris "Lopi" Spehn
							
						 
					 | 
					
						
						
							
						
						3ce3ec6656
					 | 
					
						
						
							
							Merge pull request #216 from TactiKoolSec/master
						
						
						
						
						
						
						
						Added entry for rdrleakdiag.exe process dumping lolbas 
						
						
					 | 
					
						2022-05-19 07:32:58 -06:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						90b6082f1d
					 | 
					
						
						
							
							Update Rdrleakdiag.yml
						
						
						
						
						
						
					 | 
					
						2022-05-19 13:30:11 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						e2493d8ccf
					 | 
					
						
						
							
							Detection Resources and Other Updates (LOLBAS-Project#84)
						
						
						
						
						
						
						
						https://github.com/LOLBAS-Project/LOLBAS/issues/84 
						
						
					 | 
					
						2022-05-18 19:00:26 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						d935f096fd
					 | 
					
						
						
							
							Added rdrleakdiag dump
						
						
						
						
						
						
						
						Added yaml for rdrleakdiag process dumping capability 
						
						
					 | 
					
						2022-05-18 18:58:04 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						d1738b946b
					 | 
					
						
						
							
							Adding various Sigma references (#213)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-05-17 09:18:45 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						3571a7ad88
					 | 
					
						
						
							
							Create AccCheckConsole.yml (#187)
						
						
						
						
						
						
					 | 
					
						2022-05-15 21:55:16 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								mrd0x
							
						 
					 | 
					
						
						
							
						
						7c2f3231d3
					 | 
					
						
						
							
							Adding Dump64.exe (#182)
						
						
						
						
						
						
						
						Co-authored-by: mrd0x <mrd0x@example.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-05-15 21:21:45 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						b333db4f91
					 | 
					
						
						
							
							Fixing typo (ieaframe -> ieframe)
						
						
						
						
						
						
					 | 
					
						2022-05-15 21:06:33 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						79f4cbdb7f
					 | 
					
						
						
							
							Changed tid to T1105 for downloads (#195)
						
						
						
						
						
						
					 | 
					
						2022-05-15 20:38:24 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								jstnk9
							
						 
					 | 
					
						
						
							
						
						00bc9177bd
					 | 
					
						
						
							
							Added new sigma rule and references
						
						
						
						
						
						
						
						Added new sigma rule and references 
						
						
					 | 
					
						2022-05-15 16:42:44 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						d93539bf9b
					 | 
					
						
						
							
							Quick fix for syntax and removed IOC
						
						
						
						
						
						
					 | 
					
						2022-04-29 23:06:41 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								cr1sp4
							
						 
					 | 
					
						
						
							
						
						666e6e8645
					 | 
					
						
						
							
							Update Desk.yml (#210)
						
						
						
						
						
						
						
						Added Sigma rules. 
						
						
					 | 
					
						2022-04-29 22:52:57 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						619aafbfa2
					 | 
					
						
						
							
							Adding extra contributor to Desk.cpl entry
						
						
						
						
						
						
					 | 
					
						2022-04-28 13:01:35 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						4a8bdf4844
					 | 
					
						
						
							
							Fix casing on Desk.cpl entry
						
						
						
						
						
						
					 | 
					
						2022-04-27 11:20:13 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								LuxNoBu!!shit
							
						 
					 | 
					
						
						
							
						
						6ed0fb9326
					 | 
					
						
						
							
							Create Desk.cpl (#207)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-04-27 11:15:15 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						e4261b1f02
					 | 
					
						
						
							
							Fixing typo
						
						
						
						
						
						
					 | 
					
						2022-04-26 16:59:14 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						55a7ea9a81
					 | 
					
						
						
							
							Fixing wlrmdr entry
						
						
						
						
						
						
					 | 
					
						2022-02-16 21:02:24 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Moshe Kaplan
							
						 
					 | 
					
						
						
							
						
						12c85eb8f0
					 | 
					
						
						
							
							Create wlrmdr.yml (#194)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-02-16 20:41:14 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						a7f7ec2cc2
					 | 
					
						
						
							
							Changing ATT&CK TID of wuauclt.exe entry (#193)
						
						
						
						
						
						
					 | 
					
						2022-01-23 22:24:59 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						7b208e8021
					 | 
					
						
						
							
							Change notice.txt to notice.md
						
						
						
						
						
						
					 | 
					
						2021-12-12 14:47:44 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						17899acbb0
					 | 
					
						
						
							
							Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184)
						
						
						
						
						
						
					 | 
					
						2021-12-06 11:19:01 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						2d28767c04
					 | 
					
						
						
							
							Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183)
						
						
						
						
						
						
					 | 
					
						2021-11-25 09:42:26 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						f7b30775a4
					 | 
					
						
						
							
							Odbcconf realign to T1218.008, hh.exe to T1218.001
						
						
						
						
						
						
					 | 
					
						2021-11-16 14:09:37 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						23dd0236ae
					 | 
					
						
						
							
							Detection Resources and Other Updates (#179)
						
						
						
						
						
						
						
						* Add detection links for scripts
* Add detection links for OtherMSBins. Fixed and updated as needed.
* Add detection links for MSBins. Fixed and updated as needed.
* Add detection links for oslibraries
* Updating template for Detections
* Removing empty Detection:Sigma entries
* Remove redundant blank line
* Replacing commit URL with file URL
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2021-11-15 08:19:03 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						2031916b1a
					 | 
					
						
						
							
							ATT&CK realignment, typo fixes (#178)
						
						
						
						
						
						
						
						* Corrected Mitre TID for pnputil
* Fixed Command misspells 
						
						
					 | 
					
						2021-11-14 17:27:17 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						f73ce77004
					 | 
					
						
						
							
							Project License and Notice (#175)
						
						
						
						
						
						
						
						* Adding GPL3 License
* Adding Notice for licensing and disclaimer
* Updated Notice. Changed to md
* Cleaned up notes
* Minor visual changes
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2021-11-13 09:29:14 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						11a62e618e
					 | 
					
						
						
							
							Added notice.txt reference
						
						
						
						
						
						
					 | 
					
						2021-11-07 15:46:44 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						cdf3bd7591
					 | 
					
						
						
							
							Addint notice.txt for license information
						
						
						
						
						
						
					 | 
					
						2021-11-07 15:43:06 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						03362b8640
					 | 
					
						
						
							
							Merge pull request #170 from wietze/fixes/mitre_attack_realignment
						
						
						
						
						
						
						
						MITRE ATT&CK realignment sprint 
						
						
					 | 
					
						2021-11-05 20:17:10 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						2380c506d4
					 | 
					
						
						
							
							LSASS realign to T1003.001
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:35:58 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						df8c88f4ca
					 | 
					
						
						
							
							Remaping NTDS entries to T1003.003
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:32:44 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						8257d60aad
					 | 
					
						
						
							
							Realigning .ps1 scripts to T1216
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:29:07 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						bc51cb4e03
					 | 
					
						
						
							
							More changes (mainly changing some T1218 instances to T1202)
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:19:39 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						2577066af9
					 | 
					
						
						
							
							More changes (mainly changing generic T1218 to dev-specific T1127)
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:06:57 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						8286677dac
					 | 
					
						
						
							
							Applying more specific subtechniques to Verclsid
						
						
						
						
						
						
					 | 
					
						2021-11-05 19:38:21 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						80e3f67e44
					 | 
					
						
						
							
							Applying more specific subtechniques to At/Schtasks, closes LOLBAS-Project/LOLBAS#113
						
						
						
						
						
						
					 | 
					
						2021-11-05 19:33:59 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						4f7ec8d2af
					 | 
					
						
						
							
							MITRE ATT&CK realignment sprint
						
						
						
						
						
						
					 | 
					
						2021-11-05 18:58:26 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Ensar Şamil
							
						 
					 | 
					
						
						
							
						
						97f5042a58
					 | 
					
						
						
							
							Update Certoc.yml (#168)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2021-10-27 10:02:52 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						5db35bb397
					 | 
					
						
						
							
							Updated msbuild with logger technique
						
						
						
						
						
						
					 | 
					
						2021-10-26 00:27:35 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						7aeed60864
					 | 
					
						
						
							
							Updated msbuild with logger technique
						
						
						
						
						
						
					 | 
					
						2021-10-26 00:19:57 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						b91c7ddab5
					 | 
					
						
						
							
							Updated msbuild with logger technique
						
						
						
						
						
						
					 | 
					
						2021-10-26 00:17:08 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						57b66da28e
					 | 
					
						
						
							
							Merge pull request #167 from LOLBAS-Project/features/github-action-improvements
						
						
						
						
						
						
						
						Sync with LOLBAS-Project.github.io via GitHub Actions 
						
						
					 | 
					
						2021-10-26 00:03:32 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						0063238c23
					 | 
					
						
						
							
							Only perform Action on the main branch - will prevent test from failing on forks
						
						
						
						
						
						
					 | 
					
						2021-10-25 22:48:38 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						7759811ae5
					 | 
					
						
						
							
							Adding GitHub action for automatically updating LOLBAS-Project.github.io
						
						
						
						
						
						
					 | 
					
						2021-10-25 22:02:15 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						ca11578655
					 | 
					
						
						
							
							Archiving off legacy LOLUtilz
						
						
						
						
						
						
					 | 
					
						2021-10-25 21:32:59 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						6df5ef310a
					 | 
					
						
						
							
							Update Nvudisp.yml, fixes GitHub Actions issue
						
						
						
						
						
						
					 | 
					
						2021-10-25 12:36:07 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						fa3ff39cac
					 | 
					
						
						
							
							Update Nvudisp.yml
						
						
						
						
						
						
					 | 
					
						2021-10-25 12:33:19 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
						
					 |