Commit Graph

522 Commits

Author SHA1 Message Date
TimWhite
9336b4d599
Update VSIISExeLauncher.yml 2021-09-24 15:28:39 +08:00
TimWhite
559d9bc3ff
Create VSIISExeLauncher.yml 2021-09-24 15:28:01 +08:00
John Lambert
ecbc2f817f
Add lolbin for fltMC.exe
Used by redteams for defense evasion to disable drivers used by agents like sysmon

https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
https://github.com/oddcod3/Phantom-Evasion/blob/master/Modules/post-exploitation/Postex_CMD_UnloadSysmonDriver_windows.py
2021-09-18 17:43:59 -07:00
Ruben
bb73c013fb
Update Finger.yml
Fixed header and footer
2021-08-30 13:30:52 +02:00
Rubén
670a5f1870 Create Finger.exe 2021-08-30 13:16:08 +02:00
Elliot Killick
6e047908a4
Create OneDriveStandaloneUpdater.yml 2021-08-28 05:16:35 -04:00
Elliot Killick
02207882f6
Create cmdl32.yml 2021-08-28 00:55:50 -04:00
Elliot Killick
3b1fd0ea8e
Create SettingSyncHost.yml 2021-08-26 13:35:15 -04:00
Elliot Killick
692a3bf4c2
Remove .exe from command and increase specificity 2021-08-26 12:49:43 -04:00
Elliot Killick
34af96f564
Remove .exe from command 2021-08-26 12:21:34 -04:00
Elliot Killick
084fb83984
Remove .exe from command and increase specificity 2021-08-26 12:07:04 -04:00
bohops
f51a70c03e
Merge pull request #143 from Efraim-Kaplan/patch-1
Fixed Typo
2021-08-26 09:08:40 -04:00
bohops
788d16289a
Merge pull request #132 from pgmcgee/patch-1
Fix a typo in Findstr.yml
2021-08-26 09:06:49 -04:00
Elliot Killick
26a15f55cf
Create OfflineScannerShell.yml 2021-08-16 19:46:47 -04:00
Elliot Killick
95baee85fd
Create WorkFolders.yml 2021-08-16 19:42:32 -04:00
Elliot Killick
63af8cca3b
Add resources section and improve formatting 2021-07-10 11:54:35 -04:00
Josh Brower
87c3319ad4
Fix ART link 2021-07-06 13:56:24 -04:00
Efraim-Kaplan
ebf494ae4d
FIxed typo
Replaced "handeling" with "handling".
2021-07-02 17:33:53 -04:00
Elliot Killick
8f705bb7a4
Create PrintBrm.yml
New lolbin for zipping & unzipping to and from UNC paths and ADS. The zip file could also serve as a useful form of obfuscation for evading detection.
2021-06-22 02:11:27 +00:00
Parker McGee
bbf14cf4b9
Fix a typo in Findstr.yml
`finstr.exe` should be `findstr.exe`
2021-03-20 16:40:37 -04:00
Filipe Spencer Lopes
79cf7bfb88 Adding pull_requests to the action list 2021-03-09 16:46:38 +01:00
Filipe Spencer Lopes
3993c5f053 removing newline 2021-03-09 16:46:24 +01:00
Filipe Spencer Lopes
8a31d0d1b4 Removing second yamllint action 2021-03-09 16:40:24 +01:00
Filipe Spencer Lopes
05a6dc1ccb Removing second document start. 2021-03-09 16:21:25 +01:00
Filipe Spencer Lopes
0da2e5e687 also run on push 2021-03-09 15:25:35 +01:00
Filipe Spencer Lopes
911004a924 Testing other yamllint action 2021-03-09 15:23:15 +01:00
Filipe Spencer Lopes
26eeb8eb1e Setting yamllinting to config file 2021-03-09 15:06:22 +01:00
Filipe Spencer Lopes
67bfb8cbfe changing yammlint to set indentations to warning 2021-03-09 15:05:21 +01:00
Filipe Spencer Lopes
29acd82968 putting quotes around strings with special chars 2021-03-09 15:04:09 +01:00
Filipe Spencer Lopes
ff9f5cff3d Removing blank lines 2021-03-09 15:00:55 +01:00
Filipe Spencer Lopes
b0a321e4c4 Too many whitespaces 2021-03-09 14:58:44 +01:00
Filipe Spencer Lopes
a232cfa007 Too many empty lines 2021-03-09 14:57:47 +01:00
Filipe Spencer Lopes
13901ea496 Too many whitespaces 2021-03-09 14:57:01 +01:00
Filipe Spencer Lopes
56035a7d10 Too many whitespaces 2021-03-09 14:56:47 +01:00
Filipe Spencer Lopes
85f25672a8 Adding rules 2021-03-09 14:56:22 +01:00
Filipe Spencer Lopes
75fa0cd6e3 test for pattern 2021-03-09 14:36:19 +01:00
Filipe Spencer Lopes
487af0347d no more pattern. 2021-03-09 14:34:40 +01:00
Filipe Spencer Lopes
a2bfd8a28d ugh, patterns. 2021-03-09 14:32:54 +01:00
Filipe Spencer Lopes
fda371bec0 Another pattern change 2021-03-09 14:28:09 +01:00
Filipe Spencer Lopes
4fa217f9c3 Changing matching pattern 2021-03-09 14:23:27 +01:00
Filipe Spencer Lopes
a4d37e4c60 Extension used is yml, not yaml. 2021-03-09 14:22:06 +01:00
Filipe Spencer Lopes
aa6e8be528 Adding yamllint conf with warnings for whitespaces 2021-03-09 14:19:51 +01:00
Filipe Spencer Lopes
c1765618c6 Adding GitHub action for linting 2021-03-09 14:16:42 +01:00
Filipe Spencer Lopes
65b0c24ed0 syntax: encapsulating strings with special char 2021-03-09 14:13:52 +01:00
whickey-r7
782bc68c7c
Create IMEWDBLD.yml 2021-03-05 11:35:06 -05:00
SpookySec
d539a7dacd edited cdb.yml 2021-02-12 22:26:16 +03:00
SpookySec
84de927a83 edited cdb.yml 2021-02-08 16:28:25 +03:00
ahmad
3ca7bdc542 Fixed the url 2021-01-22 06:33:58 -05:00
Oddvar Moe
7c1a4a7959
Merge pull request #125 from wokis/master
Added detection by Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen
2021-01-21 22:58:24 +01:00
Oddvar Moe
9ce6984dd7
Merge pull request #121 from ahmadalsabagh/adplus.exe
Create Adplus.yml
2021-01-21 22:56:34 +01:00