LOLBAS/yml/OtherMSBinaries
Onat Uzunyayla 7aba6fb550
Create vstest.console.exe (#322)
* vstest.console.exe awl bypass

* Create testwindowremoteagent.yaml

Data Exfiltration with TestWindowRemoteAgent.exe is added

* Create vstest.yaml

In order to utilize this, you have to create a Unit Test project for c++ preferrably (because it builds into a single DLL easily) and write your malicious code inside the test method then build it. the main function will not run any code at all but when you call vstest.console to run your unit tests it also performs the other code inside the test method so you can run your code without directly running exe or dll

* Delete testwindowremoteagent.yaml

* Update vstest.yaml

A new description added
2023-10-18 11:28:04 -04:00
..
AccCheckConsole.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Adplus.yml Several LOLBINs additions & modifications (#192) 2023-03-31 13:46:21 +01:00
Agentexecutor.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Appvlp.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Bginfo.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Cdb.yml Several LOLBINs additions & modifications (#192) 2023-03-31 13:46:21 +01:00
Coregen.yml Add Sigma ref 2023-06-10 08:12:12 +02:00
Createdump.yml Several LOLBINs additions & modifications (#192) 2023-03-31 13:46:21 +01:00
Csi.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
DefaultPack.yml Add Sigma ref 2023-06-10 08:12:12 +02:00
Devinit.yml Add Sigma ref 2023-06-10 08:12:12 +02:00
Devtoolslauncher.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
devtunnels.yml DevTunnels - Other MS Binary for Data Exfiltration (#327) 2023-10-15 00:05:54 +02:00
Dnx.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Dotnet.yml Added fsi to dotnet.exe (#281) 2023-02-25 20:10:45 +00:00
Dsdbutil.yml Add files via upload 2023-08-23 02:50:03 -04:00
Dump64.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
DumpMinitool.yml Add Sigma ref 2023-06-10 08:12:12 +02:00
Dxcap.yml Update Dxcap.yml (#296) 2023-06-27 13:42:47 +01:00
Excel.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Fsi.yml Add missing document starts and add yamllint rule (#305) 2023-06-23 20:55:39 +01:00
FsiAnyCpu.yml Update FsiAnyCpu.yml with Sigma (#225) 2022-12-28 23:50:51 -05:00
Mftrace.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Microsoft.NodejsTools.PressAnyKey.yml Add Sigma ref 2023-06-10 08:12:12 +02:00
Msdeploy.yml Correcting 'AWL bypass' to 'AWL Bypass' 2022-09-10 22:55:32 -04:00
MsoHtmEd.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Mspub.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Msxsl.yml Updated msxsl.yml to include a download and ADS category (#276) 2023-08-05 18:04:09 +01:00
Ntdsutil.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
OpenConsole.yml Adding and updating various LOLBINS (#229) 2022-11-11 16:42:44 +00:00
Powerpnt.yml Update Powerpnt.yml with Sigma (#222) 2022-10-04 12:36:49 +01:00
Procdump.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
ProtocolHandler.yml Update ProtocolHandler.yml (#267) 2023-06-17 22:18:06 +01:00
Rcsi.yml Adding no defualt paths to pass schema validations 2022-09-11 00:16:59 -04:00
Remote.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Sqldumper.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Sqlps.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Sqltoolsps.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
Squirrel.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
Te.yml Adding no defualt paths to pass schema validations 2022-09-11 00:16:59 -04:00
Teams.yml removing blank line 2023-09-03 14:49:16 -04:00
Testwindowremoteagent.yml Renaming vshadow file 2023-10-03 17:38:41 +01:00
Tracker.yml Adding no defualt paths to pass schema validations 2022-09-11 00:16:59 -04:00
Update.yml Update SigmaHQ ref (#301) 2023-06-19 22:40:24 +01:00
VisualUiaVerifyNative.yml Add missing document starts and add yamllint rule (#305) 2023-06-23 20:55:39 +01:00
VSDiagnostics.yml VSDiagnostics Execute lolbin (#309) 2023-08-05 17:18:48 +01:00
Vshadow.yml Fixing command attribute on Vshadow 2023-10-03 17:41:18 +01:00
VSIISExeLauncher.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Vsjitdebugger.yml Removing extra --- from each yaml file 2022-09-10 22:16:47 -04:00
vsls-agent.yml Fix sigmaHQ ref (#300) 2023-06-17 20:29:07 +01:00
vstest.yaml Create vstest.console.exe (#322) 2023-10-18 11:28:04 -04:00
Wfc.yml Update Wfc.yml with Sigma (#223) 2022-12-29 00:22:39 -05:00
Winword.yml Add sigma ref Detection (#272) 2022-12-29 09:51:15 -05:00
Wsl.yml Adding and updating various LOLBINS (#229) 2022-11-11 16:42:44 +00:00