LOLBAS/yml/OSBinaries
hegusung c34810b29b
Update Mshta.yml Tags
Changed Execute: WSH to HTA
2024-10-13 18:08:27 +02:00
..
Addinutil.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
AppInstaller.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Aspnet_Compiler.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
At.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Atbroker.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Bash.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Bitsadmin.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Certoc.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Certreq.yml Moved text to correct line (#349) 2024-02-17 17:14:08 +00:00
Certutil.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
Cmd.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdkey.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdl32.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmstp.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Colorcpl.yml Added colorcpl.exe (#315) 2023-07-27 18:18:49 +01:00
ComputerDefaults.yml Add ComputerDefaults.yml (#400) 2024-09-25 23:47:41 +01:00
ConfigSecurityPolicy.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Conhost.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Control.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Csc.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Cscript.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
CustomShellHost.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
DataSvcUtil.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Desktopimgdownldr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
DeviceCredentialDeployment.yml
Dfsvc.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Diantz.yml Add Diantz directives/DDF entry to diantz.exe (#390) 2024-08-17 22:02:55 +01:00
Diskshadow.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Dnscmd.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Esentutl.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Eventvwr.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Expand.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Explorer.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Extexport.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Extrac32.yml Adding more operating systems to extrac32.exe (#387) 2024-08-17 22:10:48 +01:00
Findstr.yml Update MITRE T1185 to T1105 (#345) 2024-02-17 17:30:52 +00:00
Finger.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
FltMC.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Forfiles.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Fsutil.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Ftp.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Gpscript.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Hh.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Ie4uinit.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Iediagcmd.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Ieexec.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Ilasm.yml
IMEWDBLD.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Infdefaultinstall.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Installutil.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Jsc.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ldifde.yml
Makecab.yml Makecab - LOLBAS command, more information about Windows compatibility (#389) 2024-08-17 22:16:07 +01:00
Mavinject.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Microsoft.Workflow.Compiler.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Mmc.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
MpCmdRun.yml
Msbuild.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Msconfig.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Msdt.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
msedge_proxy.yml Correct identation 2024-10-13 17:57:36 +02:00
Msedge.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
msedgewebview2.yml Correct identation 2024-10-13 17:57:36 +02:00
Mshta.yml Update Mshta.yml Tags 2024-10-13 18:08:27 +02:00
Msiexec.yml Removed Fixed and Custom Format tags 2024-10-13 18:01:58 +02:00
Netsh.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ngen.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Odbcconf.yml Odbcconf.yml - Corrected incorrect privileges (#396) 2024-09-07 15:01:46 +01:00
OfflineScannerShell.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
OneDriveStandaloneUpdater.yml Adding Windows file path validation for values of File_Path (#403) 2024-10-01 23:14:19 +01:00
Pcalua.yml Update Pcalua.yml Tags 2024-10-13 16:24:52 +02:00
Pcwrun.yml Update Pcwrun.yml Tags 2024-10-13 16:26:26 +02:00
Pktmon.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Pnputil.yml Update Pnputil.yml Tags 2024-10-13 16:29:07 +02:00
Presentationhost.yml Correct identation 2024-10-13 17:57:36 +02:00
Print.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
PrintBrm.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Provlaunch.yml Correct identation 2024-10-13 17:57:36 +02:00
Psr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rasautou.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Rdrleakdiag.yml
Reg.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regasm.yml Update Regasm.yml Tags 2024-10-13 16:41:32 +02:00
Regedit.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regini.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Register-cimprovider.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Regsvcs.yml Update Regsvcs.yml Tags 2024-10-13 16:45:00 +02:00
Regsvr32.yml Correct identation 2024-10-13 17:57:36 +02:00
Replace.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rpcping.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rundll32.yml Correct identation 2024-10-13 17:57:36 +02:00
Runexehelper.yml Correct identation 2024-10-13 17:57:36 +02:00
Runonce.yml Correct identation 2024-10-13 17:57:36 +02:00
Runscripthelper.yml Correct identation 2024-10-13 17:57:36 +02:00
Sc.yml Correct identation 2024-10-13 17:57:36 +02:00
Schtasks.yml Correct identation 2024-10-13 17:57:36 +02:00
Scriptrunner.yml Correct identation 2024-10-13 17:57:36 +02:00
Setres.yml Correct identation 2024-10-13 17:57:36 +02:00
SettingSyncHost.yml Correct identation 2024-10-13 17:57:36 +02:00
Ssh.yml Correct identation 2024-10-13 17:57:36 +02:00
Stordiag.yml Correct identation 2024-10-13 17:57:36 +02:00
Syncappvpublishingserver.yml Correct identation 2024-10-13 17:57:36 +02:00
Tar.yml Add Detection Sigma ref (#368) 2024-04-19 18:53:37 +01:00
Ttdinject.yml Correct identation 2024-10-13 17:57:36 +02:00
Tttracer.yml Correct identation 2024-10-13 17:57:36 +02:00
Unregmp2.yml Correct identation 2024-10-13 17:57:36 +02:00
Vbc.yml Update Vbc.yml Tags 2024-10-13 17:22:53 +02:00
Verclsid.yml Correct identation 2024-10-13 17:57:36 +02:00
Wab.yml Correct identation 2024-10-13 17:57:36 +02:00
Wbadmin.yml Create wbadmin (#364) 2024-04-05 19:38:21 +01:00
Winget.yml Correct identation 2024-10-13 17:57:36 +02:00
Wlrmdr.yml Correct identation 2024-10-13 17:57:36 +02:00
Wmic.yml Correct identation 2024-10-13 17:57:36 +02:00
WorkFolders.yml Correct identation 2024-10-13 17:57:36 +02:00
Wscript.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Wsreset.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
wt.yml Correct identation 2024-10-13 17:57:36 +02:00
Wuauclt.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Xwizard.yml Correct identation 2024-10-13 17:57:36 +02:00