LOLBAS/yml/OSBinaries
hegusung eb06fb5266
Update Ftp.yml Tags
Added Tags:
- Execute CMD
- Input Custom Format
2024-10-13 13:13:21 +02:00
..
Addinutil.yml Update Addinutil.yml 2024-10-13 11:50:14 +02:00
AppInstaller.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Aspnet_Compiler.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
At.yml Update At.yml 2024-10-13 11:55:20 +02:00
Atbroker.yml Update Atbroker.yml 2024-10-13 11:59:14 +02:00
Bash.yml Update Bash.yml 2024-10-13 12:02:27 +02:00
Bitsadmin.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Certoc.yml Update Certoc.yml 2024-10-13 12:06:18 +02:00
Certreq.yml Moved text to correct line (#349) 2024-02-17 17:14:08 +00:00
Certutil.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
Cmd.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdkey.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmdl32.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Cmstp.yml Update Cmstp.yml 2024-10-13 12:16:28 +02:00
Colorcpl.yml
ComputerDefaults.yml Add ComputerDefaults.yml (#400) 2024-09-25 23:47:41 +01:00
ConfigSecurityPolicy.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Conhost.yml Update Conhost.yml 2024-10-13 12:19:14 +02:00
Control.yml Update Control.yml 2024-10-13 12:26:15 +02:00
Csc.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Cscript.yml Update Cscript.yml Tags 2024-10-13 12:33:41 +02:00
CustomShellHost.yml Update CustomShellHost.yml Tags 2024-10-13 12:35:23 +02:00
DataSvcUtil.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Desktopimgdownldr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
DeviceCredentialDeployment.yml
Dfsvc.yml Update Dfsvc.yml Tags 2024-10-13 12:37:51 +02:00
Diantz.yml Add Diantz directives/DDF entry to diantz.exe (#390) 2024-08-17 22:02:55 +01:00
Diskshadow.yml Update Diskshadow.yml Tags 2024-10-13 13:03:33 +02:00
Dnscmd.yml Update Dnscmd.yml Tags 2024-10-13 13:05:06 +02:00
Esentutl.yml
Eventvwr.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Expand.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Explorer.yml Update Explorer.yml Tags 2024-10-13 13:07:06 +02:00
Extexport.yml Update Extexport.yml Tags 2024-10-13 13:08:11 +02:00
Extrac32.yml Adding more operating systems to extrac32.exe (#387) 2024-08-17 22:10:48 +01:00
Findstr.yml Update MITRE T1185 to T1105 (#345) 2024-02-17 17:30:52 +00:00
Finger.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
FltMC.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Forfiles.yml Update Forfiles.yml Tags 2024-10-13 13:11:05 +02:00
Fsutil.yml Update Fsutil.yml Tags 2024-10-13 13:12:20 +02:00
Ftp.yml Update Ftp.yml Tags 2024-10-13 13:13:21 +02:00
Gpscript.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Hh.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Ie4uinit.yml
Iediagcmd.yml Added lolbas iediagcmd.exe as discovered by Adam @hexacorn (#199) 2023-10-04 09:47:18 -04:00
Ieexec.yml
Ilasm.yml
IMEWDBLD.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Infdefaultinstall.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Installutil.yml Update Installutil.yml 2024-10-13 11:11:44 +02:00
Jsc.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ldifde.yml
Makecab.yml Makecab - LOLBAS command, more information about Windows compatibility (#389) 2024-08-17 22:16:07 +01:00
Mavinject.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Microsoft.Workflow.Compiler.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Mmc.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
MpCmdRun.yml
Msbuild.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Msconfig.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Msdt.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
msedge_proxy.yml Adding Windows file path validation for values of File_Path (#403) 2024-10-01 23:14:19 +01:00
Msedge.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
msedgewebview2.yml Applying MITRE ATT&CK v15 changes (#370) 2024-04-24 15:10:59 +01:00
Mshta.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Msiexec.yml Update Msiexec.yml (#369) 2024-05-22 18:59:51 +01:00
Netsh.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Ngen.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Odbcconf.yml Odbcconf.yml - Corrected incorrect privileges (#396) 2024-09-07 15:01:46 +01:00
OfflineScannerShell.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
OneDriveStandaloneUpdater.yml Adding Windows file path validation for values of File_Path (#403) 2024-10-01 23:14:19 +01:00
Pcalua.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Pcwrun.yml
Pktmon.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Pnputil.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Presentationhost.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Print.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
PrintBrm.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Provlaunch.yml Add SigmaHQ ref 2023-09-03 15:06:34 +02:00
Psr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rasautou.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Rdrleakdiag.yml
Reg.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regasm.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Regedit.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Regini.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Register-cimprovider.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Regsvcs.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Regsvr32.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Replace.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rpcping.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Rundll32.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Runexehelper.yml
Runonce.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Runscripthelper.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Sc.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Schtasks.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Scriptrunner.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Setres.yml
SettingSyncHost.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Ssh.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Stordiag.yml Updates in Stordiag.exe (#394) 2024-09-10 13:31:38 +01:00
Syncappvpublishingserver.yml
Tar.yml Add Detection Sigma ref (#368) 2024-04-19 18:53:37 +01:00
Ttdinject.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Tttracer.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Unregmp2.yml
Vbc.yml Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392) 2024-09-07 15:07:46 +01:00
Verclsid.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wab.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wbadmin.yml Create wbadmin (#364) 2024-04-05 19:38:21 +01:00
Winget.yml Update Winget.yml (#384) 2024-08-17 23:52:52 +01:00
Wlrmdr.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wmic.yml Update Wmic.yml (#355) 2024-09-15 17:31:17 +01:00
WorkFolders.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wscript.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Wsreset.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
wt.yml Update old sigma link (#303) 2023-10-18 11:30:34 -04:00
Wuauclt.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00
Xwizard.yml Adding tags (closes #9, #318) (#362) 2024-04-03 11:53:36 -04:00