LOLBAS/yml/OSBinaries
2024-12-02 23:56:02 +11:00
..
Addinutil.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
AppInstaller.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Aspnet_Compiler.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
At.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Atbroker.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Bash.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Bitsadmin.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Certoc.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Certreq.yml Moved text to correct line (#349) 2024-02-17 17:14:08 +00:00
Certutil.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
Cmd.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdkey.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdl32.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmstp.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Colorcpl.yml Added colorcpl.exe (#315) 2023-07-27 18:18:49 +01:00
ComputerDefaults.yml Add ComputerDefaults.yml (#400) 2024-09-25 23:47:41 +01:00
ConfigSecurityPolicy.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Conhost.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Control.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Csc.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Cscript.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
CustomShellHost.yml
DataSvcUtil.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Desktopimgdownldr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
DeviceCredentialDeployment.yml
Dfsvc.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Diantz.yml Add Diantz directives/DDF entry to diantz.exe (#390) 2024-08-17 22:02:55 +01:00
Diskshadow.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Dnscmd.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Esentutl.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Eventvwr.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Expand.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Explorer.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Extexport.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Extrac32.yml Adding more operating systems to extrac32.exe (#387) 2024-08-17 22:10:48 +01:00
Findstr.yml Update MITRE T1185 to T1105 (#345) 2024-02-17 17:30:52 +00:00
Finger.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
FltMC.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Forfiles.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Fsutil.yml Adding GitHub Actions workflow test for duplicate filenames (#340) 2023-11-07 20:55:24 -05:00
Ftp.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Gpscript.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Hh.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Ie4uinit.yml
Iediagcmd.yml Added lolbas iediagcmd.exe as discovered by Adam @hexacorn (#199) 2023-10-04 09:47:18 -04:00
Ieexec.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Ilasm.yml
IMEWDBLD.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Infdefaultinstall.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Installutil.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Jsc.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ldifde.yml
Makecab.yml Makecab - LOLBAS command, more information about Windows compatibility (#389) 2024-08-17 22:16:07 +01:00
Mavinject.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Microsoft.Workflow.Compiler.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Mmc.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
MpCmdRun.yml
Msbuild.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Msconfig.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Msdt.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
msedge_proxy.yml Adding Windows file path validation for values of File_Path (#403) 2024-10-01 23:14:19 +01:00
Msedge.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
msedgewebview2.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
Mshta.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Msiexec.yml Update Msiexec.yml (#369) 2024-05-22 18:59:51 +01:00
Netsh.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ngen.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Odbcconf.yml Odbcconf.yml - Corrected incorrect privileges (#396) 2024-09-07 15:01:46 +01:00
OfflineScannerShell.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
OneDriveStandaloneUpdater.yml Adding Windows file path validation for values of File_Path (#403) 2024-10-01 23:14:19 +01:00
Pcalua.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Pcwrun.yml
Pktmon.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Pnputil.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Presentationhost.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Print.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
PrintBrm.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Provlaunch.yml Add SigmaHQ ref 2023-09-03 15:06:34 +02:00
Psr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rasautou.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Rdrleakdiag.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Reg.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regasm.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Regedit.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regini.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Register-cimprovider.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Regsvcs.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Regsvr32.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Replace.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rpcping.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rundll32.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Runexehelper.yml
Runonce.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Runscripthelper.yml Update Runscripthelper.yml (#407) 2024-11-10 17:31:41 +00:00
Sc.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Schtasks.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Scriptrunner.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Setres.yml
SettingSyncHost.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Ssh.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Stordiag.yml Updates in Stordiag.exe (#394) 2024-09-10 13:31:38 +01:00
Syncappvpublishingserver.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Tar.yml Add Detection Sigma ref (#368) 2024-04-19 18:53:37 +01:00
Ttdinject.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Tttracer.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Unregmp2.yml
Vbc.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Verclsid.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wab.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wbadmin.yml Create wbadmin (#364) 2024-04-05 19:38:21 +01:00
Wevtutil.yml added more reference and contribution 2024-12-02 23:56:02 +11:00
Winget.yml Update Winget.yml (#384) 2024-08-17 23:52:52 +01:00
Wlrmdr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wmic.yml Update Wmic.yml (#355) 2024-09-15 17:31:17 +01:00
WorkFolders.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wscript.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Wsreset.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
wt.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wuauclt.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Xwizard.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00