frack113
|
f85eeb748a
|
Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219)
|
2022-05-23 12:35:58 +01:00 |
|
Chris "Lopi" Spehn
|
36945392ca
|
Merge pull request #201 from wietze/new/Conhost
Adding Conhost.exe LOLBAS
|
2022-05-19 10:27:10 -06:00 |
|
Chris "Lopi" Spehn
|
e872ce028b
|
Merge pull request #214 from jstnk9/master
Added new sigma rule and references to desk.cpl
|
2022-05-19 10:21:21 -06:00 |
|
Chris "Lopi" Spehn
|
82f19b22e7
|
Merge pull request #217 from ManuelBerrueta/master
Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign sh…
|
2022-05-19 10:19:22 -06:00 |
|
ManuelBerrueta
|
68b772a567
|
Updated yml/OtherMSBinaries/Sqlps.yml, used recently in a campaign shared my Microsoft Security Intelligence. Would be useful reference for Red Teamers/Offensive Security Engineers as well as Blue Teamers/Defenders who reference this open source project/library.
|
2022-05-19 07:12:37 -07:00 |
|
Chris "Lopi" Spehn
|
3ce3ec6656
|
Merge pull request #216 from TactiKoolSec/master
Added entry for rdrleakdiag.exe process dumping lolbas
|
2022-05-19 07:32:58 -06:00 |
|
John Dwyer
|
90b6082f1d
|
Update Rdrleakdiag.yml
|
2022-05-19 13:30:11 +00:00 |
|
John Dwyer
|
e2493d8ccf
|
Detection Resources and Other Updates (LOLBAS-Project#84)
https://github.com/LOLBAS-Project/LOLBAS/issues/84
|
2022-05-18 19:00:26 +00:00 |
|
John Dwyer
|
d935f096fd
|
Added rdrleakdiag dump
Added yaml for rdrleakdiag process dumping capability
|
2022-05-18 18:58:04 +00:00 |
|
frack113
|
d1738b946b
|
Adding various Sigma references (#213)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-05-17 09:18:45 +01:00 |
|
bohops
|
3571a7ad88
|
Create AccCheckConsole.yml (#187)
|
2022-05-15 21:55:16 +01:00 |
|
mrd0x
|
7c2f3231d3
|
Adding Dump64.exe (#182)
Co-authored-by: mrd0x <mrd0x@example.com>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-05-15 21:21:45 +01:00 |
|
Wietze
|
b333db4f91
|
Fixing typo (ieaframe -> ieframe)
|
2022-05-15 21:06:33 +01:00 |
|
akshat pradhan
|
79f4cbdb7f
|
Changed tid to T1105 for downloads (#195)
|
2022-05-15 20:38:24 +01:00 |
|
jstnk9
|
00bc9177bd
|
Added new sigma rule and references
Added new sigma rule and references
|
2022-05-15 16:42:44 +02:00 |
|
bohops
|
d93539bf9b
|
Quick fix for syntax and removed IOC
|
2022-04-29 23:06:41 -04:00 |
|
cr1sp4
|
666e6e8645
|
Update Desk.yml (#210)
Added Sigma rules.
|
2022-04-29 22:52:57 -04:00 |
|
Wietze
|
619aafbfa2
|
Adding extra contributor to Desk.cpl entry
|
2022-04-28 13:01:35 +01:00 |
|
Wietze
|
4a8bdf4844
|
Fix casing on Desk.cpl entry
|
2022-04-27 11:20:13 +01:00 |
|
LuxNoBu!!shit
|
6ed0fb9326
|
Create Desk.cpl (#207)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-04-27 11:15:15 +01:00 |
|
Wietze
|
e4261b1f02
|
Fixing typo
|
2022-04-26 16:59:14 +01:00 |
|
Wietze
|
5c46dd63f5
|
Giving Hexacorn the proper credit
|
2022-04-07 15:50:39 +01:00 |
|
Wietze
|
4df2e43c82
|
Adding Conhost.exe LOLBAS
|
2022-04-05 18:46:58 +01:00 |
|
Wietze
|
55a7ea9a81
|
Fixing wlrmdr entry
|
2022-02-16 21:02:24 +00:00 |
|
Moshe Kaplan
|
12c85eb8f0
|
Create wlrmdr.yml (#194)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2022-02-16 20:41:14 +00:00 |
|
akshat pradhan
|
a7f7ec2cc2
|
Changing ATT&CK TID of wuauclt.exe entry (#193)
|
2022-01-23 22:24:59 +00:00 |
|
bohops
|
7b208e8021
|
Change notice.txt to notice.md
|
2021-12-12 14:47:44 -05:00 |
|
whickey-r7
|
18bceb7639
|
Create Unregmp2.yml
Added a new lolbin, unregmp2.exe, used for proxying execution.
|
2021-12-06 12:13:24 -05:00 |
|
frack113
|
17899acbb0
|
Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184)
|
2021-12-06 11:19:01 +00:00 |
|
frack113
|
2d28767c04
|
Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183)
|
2021-11-25 09:42:26 +00:00 |
|
Wietze
|
f7b30775a4
|
Odbcconf realign to T1218.008, hh.exe to T1218.001
|
2021-11-16 14:09:37 +00:00 |
|
bohops
|
23dd0236ae
|
Detection Resources and Other Updates (#179)
* Add detection links for scripts
* Add detection links for OtherMSBins. Fixed and updated as needed.
* Add detection links for MSBins. Fixed and updated as needed.
* Add detection links for oslibraries
* Updating template for Detections
* Removing empty Detection:Sigma entries
* Remove redundant blank line
* Replacing commit URL with file URL
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-11-15 08:19:03 -05:00 |
|
Wietze
|
4860585fb7
|
Adding CustomShellHost.exe LOLBAS
|
2021-11-14 23:26:39 +00:00 |
|
akshat pradhan
|
2031916b1a
|
ATT&CK realignment, typo fixes (#178)
* Corrected Mitre TID for pnputil
* Fixed Command misspells
|
2021-11-14 17:27:17 +00:00 |
|
bohops
|
f73ce77004
|
Project License and Notice (#175)
* Adding GPL3 License
* Adding Notice for licensing and disclaimer
* Updated Notice. Changed to md
* Cleaned up notes
* Minor visual changes
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-11-13 09:29:14 -05:00 |
|
akshat pradhan
|
53a4070205
|
Fixed formating
|
2021-11-09 08:16:34 +05:30 |
|
akshat pradhan
|
33a8da933c
|
Added AWL Bypass to Ssh.yml
|
2021-11-09 08:14:43 +05:30 |
|
akshat pradhan
|
dfc7d40b1f
|
Create Ssh
|
2021-11-08 22:21:37 +05:30 |
|
bohops
|
11a62e618e
|
Added notice.txt reference
|
2021-11-07 15:46:44 -05:00 |
|
bohops
|
cdf3bd7591
|
Addint notice.txt for license information
|
2021-11-07 15:43:06 -05:00 |
|
bohops
|
03362b8640
|
Merge pull request #170 from wietze/fixes/mitre_attack_realignment
MITRE ATT&CK realignment sprint
|
2021-11-05 20:17:10 -04:00 |
|
Wietze
|
2380c506d4
|
LSASS realign to T1003.001
|
2021-11-05 20:35:58 +00:00 |
|
Wietze
|
df8c88f4ca
|
Remaping NTDS entries to T1003.003
|
2021-11-05 20:32:44 +00:00 |
|
Wietze
|
8257d60aad
|
Realigning .ps1 scripts to T1216
|
2021-11-05 20:29:07 +00:00 |
|
Wietze
|
bc51cb4e03
|
More changes (mainly changing some T1218 instances to T1202)
|
2021-11-05 20:19:39 +00:00 |
|
Wietze
|
2577066af9
|
More changes (mainly changing generic T1218 to dev-specific T1127)
|
2021-11-05 20:06:57 +00:00 |
|
Wietze
|
8286677dac
|
Applying more specific subtechniques to Verclsid
|
2021-11-05 19:38:21 +00:00 |
|
Wietze
|
80e3f67e44
|
Applying more specific subtechniques to At/Schtasks, closes LOLBAS-Project/LOLBAS#113
|
2021-11-05 19:33:59 +00:00 |
|
Wietze
|
4f7ec8d2af
|
MITRE ATT&CK realignment sprint
|
2021-11-05 18:58:26 +00:00 |
|
Ensar Şamil
|
97f5042a58
|
Update Certoc.yml (#168)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
|
2021-10-27 10:02:52 +01:00 |
|